This IP address has been reported a total of
45
times from
34 distinct
sources.
34.21.218.36 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
(mod_security) mod_security triggered on hostname [redacted] 34.21.218.36 (SG/Singapore/36.218.21.34 ...
show more(mod_security) mod_security triggered on hostname [redacted] 34.21.218.36 (SG/Singapore/36.218.21.34.bc.googleusercontent.com)
show less
2026-08-28 12:38:05 GET /@fs/app/.env?raw?? [301] && 2026-08-28 12:38:05 GET /@fs/src/.env?raw?? [30 ...
show more2026-08-28 12:38:05 GET /@fs/app/.env?raw?? [301] && 2026-08-28 12:38:05 GET /@fs/src/.env?raw?? [301] && 2026-08-28 12:38:05 GET /@fs/proc/self/environ?raw?? [301] && 124 more within 20 minutes
show less
[Fri Aug 28 10:54:43.358470 2026] [php7:error] [pid 3470291:tid 3470291] [client 34.21.218.36:13256] ...
show more[Fri Aug 28 10:54:43.358470 2026] [php7:error] [pid 3470291:tid 3470291] [client 34.21.218.36:13256] script '/var/www/html/blog.solution.it/config.php' not found or unable to stat
show less
{"level":"info","ts":1787903882.1739593,"logger":"http.log.access.log0","msg":"handled request","req ...
show more{"level":"info","ts":1787903882.1739593,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"34.21.218.36","remote_port":"56024","client_ip":"34.21.218.36","proto":"HTTP/1.1","method":"GET","host":"jncp.status.updown.io","uri":"/","headers":{"Accept":["*/*"],"Accept-Encoding":["gzip"],"User-Agent":["Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"]}},"bytes_read":0,"user_id":"","duration":0.000061778,"size":0,"status":308,"resp_headers":{"Connection":["close"],"Location":["https://jncp.status.updown.io/"],"Content-Type":[],"Server":["Caddy"]}}
{"level":"info","ts":1787903889.891479,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"34.21.218.36","remote_port":"39284","client_ip":"34.21.218.36","proto":"HTTP/1.1","method":"GET","host":"jncp.status.updown.io","uri":"/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env?raw??","headers":{"User-Agent":["Mozilla/5.0 (X11;
...
show less
(mod_security) mod_security (id:210492) triggered by 34.21.218.36 (36.218.21.34.bc.googleusercontent ...
show more(mod_security) mod_security (id:210492) triggered by 34.21.218.36 (36.218.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 03:27:06.868559 2026] [security2:error] [pid 22515:tid 22515] [client 34.21.218.36:26056] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "robertanders.com"] [uri "/@fs/.env.production"] [unique_id "apE4Slkt3DRI1PDRpITXkQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
Bot / scanning and/or hacking attempts: GET /.azure/credentials HTTP/1.1, GET /public/.env HTTP/1.1, ...
show moreBot / scanning and/or hacking attempts: GET /.azure/credentials HTTP/1.1, GET /public/.env HTTP/1.1, GET /aws.json HTTP/1.1, GET /aws_credentials HTTP/1.1, GET /.aws/credentials HTTP/1.1, GET /root/.aws/credentials HTTP/1.1, GET /.gcloud/credentials HTTP/1.1, GET /.github/.env HTTP/1.1, GET /.git-credentials HTTP/1.1, GET /root/.aws/config HTTP/1.1, GET /.aws/config HTTP/1.1, GET /.gcloud/credentials.json HTTP/1.1, GET /aws-credentials HTTP/1.1, GET /admin/.env HTTP/1.1, GET /api/.env HTTP/1.1, GET /env.js HTTP/1.1
show less
Hacking
Web App Attack
Anonymous
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail