Log in to view charts and search reports for this IP.
Log In
Reports Activity
Example preview
Report Categories (Last 60 Days)
Example preview
Top Reporter Countries (Last 60 Days)
Example preview
Account required for the enhanced features
Log inSign up
IP Abuse Reports for 34.20.164.251
This IP address has been reported a total of
17
times from
15 distinct
sources.
34.20.164.251 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
United States of America
with 5
reports;
Germany
with 4
reports;
Netherlands
with 3
reports.
The most common categories in these recent reports were:
Web App Attack
15
times;
Hacking
6
times;
Brute-Force
5
times;
Bad Web Bot
4
times;
Exploited Host
1
time;
Other
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
(modsecurity) srv103 ModSecurity 34.20.164.251 (US/United States/251.164.20.34.bc.googleusercontent. ...
show more(modsecurity) srv103 ModSecurity 34.20.164.251 (US/United States/251.164.20.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
{"level":"info","ts":1790015370.8854303,"logger":"http.log.access.log1","msg":"handled request","req ...
show more{"level":"info","ts":1790015370.8854303,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.20.164.251","remote_port":"43856","client_ip":"34.20.164.251","proto":"HTTP/1.1","method":"GET","host":"ponmlojqponmlkjihgc7402a95-6fc9-4756-b4e6-fa6c7eeb29c6.random.159.89.98.98.nip.io","uri":"/.codex/config.json","headers":{"Accept":["*/*"],"User-Agent":["crusader-worker/1.0"]}},"bytes_read":0,"user_id":"","duration":0.000071927,"size":0,"status":308,"resp_headers":{"Server":["Caddy"],"Connection":["close"],"Location":["https://ponmlojqponmlkjihgc7402a95-6fc9-4756-b4e6-fa6c7eeb29c6.random.159.89.98.98.nip.io/.codex/config.json"],"Content-Type":[]}}
{"level":"info","ts":1790015370.8861804,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.20.164.251","remote_port":"43882","client_ip":"34.20.164.251","proto":"HTTP/1.1","method":"GET","host":"ponmlojqponmlkjihgc7402a95-6fc9-4756-b4e6-fa6c7eeb29c6.random.159.89.98.98.nip.io","uri":"/.c
...
show less
(secretscan) Secret-Scanner (env/git/ssh/credentials) from 34.20.164.251 (US/United States/251.164.2 ...
show more(secretscan) Secret-Scanner (env/git/ssh/credentials) from 34.20.164.251 (US/United States/251.164.20.34.bc.googleusercontent.com)
show less
Hacking
Anonymous
IP matched detection query 20 more in short time bad rqs.
Automated HTTP scanner ('crusader-worker/1.0') hit a public web service with 80+ connections across ...
show moreAutomated HTTP scanner ('crusader-worker/1.0') hit a public web service with 80+ connections across TCP 80 and 443 and rapidly requested AI-agent credential/token files โ /a host, /credentials.json, /claude.json and /config paths, plus many directory-prefixed variants (/root, /home, /var/www, /ap...
Target: HTTP 80 and HTTPS 443, enumeration of AI-agent credential files across directory prefixes (/root, /home, /var/www, /app, /data, /tmp, /www, /srv, /opt, /htdocs, /files, /uploads, /web, /config, /si...
Seen: 2026-09-21 02:42-02:43 EDT
- 2026-09-21 02:42:52 EDT: 10+ sequential GET requests returned 444 - /.codex/a host, /.claude/credentials.json, /.claude.json, /.config/claude/credentials.json, /backup/.claude/credentials.json, /backup/.codex/a host - User-Agent 'crusader-worker/1.0'
- 2026-09-21 02:42:52-02:42:53 EDT: rapid burst of SYN connections from source ports 50428-50774 to TCP/80 and 41140-41478 to TCP/443 from a single source - 80+ connection attempts within ~1 second, consistent with an automat...
show less