This IP address has been reported a total of
23
times from
18 distinct
sources.
34.85.134.164 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show moreAuto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-15.
show less
Aggressive web search of vulnerable pages: /production/.env /api/.env /api/.env.local /v2/.env /app/ ...
show moreAggressive web search of vulnerable pages: /production/.env /api/.env /api/.env.local /v2/.env /app/.env ...
show less
{"level":"info","ts":1781478606.0232918,"logger":"http.log.access.log1","msg":"handled request","req ...
show more{"level":"info","ts":1781478606.0232918,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.85.134.164","remote_port":"41696","client_ip":"34.85.134.164","proto":"HTTP/1.1","method":"GET","host":"status.hollywoodsoundstage.com","uri":"/.env.bak","headers":{"Accept-Encoding":["gzip"],"Connection":["close"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.131 Safari/537.36"],"Accept-Charset":["utf-8"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"","server_name":"status.hollywoodsoundstage.com","ech":false}},"bytes_read":0,"user_id":"","duration":0.000997071,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1781478606.0273807,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.85.134.164","remote_port":"41708","client_ip":"34.85.134.164","proto":"HTTP/1.1","meth
...
show less
Automated Apache detection on Windows host. 5 suspicious HTTP requests within 300 seconds. Examples: ...
show moreAutomated Apache detection on Windows host. 5 suspicious HTTP requests within 300 seconds. Examples: GET /.env.backup -> 404 UA=""; GET /.env -> 404 UA=""; GET /.env.backup.txt -> 404 UA=""; GET /.env.prod -> 404 UA=""; GET /.env.production -> 404 UA=""
show less