This IP address has been reported a total of
17
times from
13 distinct
sources.
34.146.122.166 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
United States of America
with 5
reports;
Czechia
with 2
reports;
Netherlands
with 2
reports.
The most common categories in these recent reports were:
Web App Attack
15
times;
Brute-Force
8
times;
Bad Web Bot
8
times;
Hacking
4
times;
Port Scan
2
times;
Other
1
time.
Old Reports
The most recent abuse report for this IP address is from
. It is possible that this IP is no
longer involved in abusive activities.
[ThuSep2410:46:05.8222212026][security2:error][pid2002698:tid2002818][client34.146.122.166:0]ModSecu ...
show more[ThuSep2410:46:05.8222212026][security2:error][pid2002698:tid2002818][client34.146.122.166:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Stringmatchwithin\".asa/.asax/.ascx/.backup/.bak/.bat/.cdx/.cer/.cfg/.cmd/.com/.config/.conf/.cs/.csproj/.csr/.dat/.db/.dbf/.dll/.dos/.htr/.htw/.ida/.idc/.idq/.inc/.ini/.key/.licx/.lnk/.log/.mdb/.old/.pass/.pdb/.pol/.printer/.pwd/.rdb/.resources/.resx/.sql/.swp/.sys/.vb/.vbs/.vbproj/.vsdisco/.webinfo/.xsx/\"atTX:extension.[file\"/etc/apache2/conf.d/modsec_rules/00_asl_zz_strict.conf\"][line\"91\"][id\"390716\"][rev\"2\"][msg\"Atomicorp.comWAFRules:URLfileextensionisrestrictedbypolicy\"][data\".bak\"][severity\"ERROR\"][hostname\"cadvending.ch.81-17-25-250.cpanel.site\"][uri\"/.codex/auth.json.bak\"][unique_id\"arTjTS7mqfCh04Xn4KifWgAAAAo\"]
show less
Automated Wazuh observation. Wazuh rule 31151 lvl=10 detected repeated HTTP web application probing ...
show moreAutomated Wazuh observation. Wazuh rule 31151 lvl=10 detected repeated HTTP web application probing from this source IP. Observed 3 matching Wazuh alert(s) between 2026-09-24T06:09:41+02:00 and 2026-09-24T06:09:41+02:00.
show less
Ran a ~50-source-port TCP SYN sweep of the public web edge on TCP/80, then harvested AI-agent secret ...
show moreRan a ~50-source-port TCP SYN sweep of the public web edge on TCP/80, then harvested AI-agent secret files (/.claude/...) with the 'crusader-worker/1.0' bot; all requests returned 444.
Target: HTTP / โ enumerating AI-agent secret/config files using user-agent crusader-worker/1.0, preceded by a ~50-source-port TCP SYN sweep of TCP/80
Seen: 2026-09-23 23:23 EDT
- 23:23:22 User-Agent 'crusader-worker/1.0' GET /.claude/a host.json, /data/.claude.json, /www/.claude/credentials.json -> 444
- 23:23:22 ~50 single TCP SYN packets from source ports 35276-35688 against TCP/80 (SYN sweep)
show less
open() "/var/www/html/data/.claude.json" failed (2: No such file or directory), client: 34.146.122.1 ...
show moreopen() "/var/www/html/data/.claude.json" failed (2: No such file or directory), client: 34.146.122.166, server: api.services.org.pl, request: "GET /data/.claude.json HTTP/1.1", host: "api.services.org.pl"
show less
1.206 requests with url.path */auth.json
403 requests with url.path *credentials.json
175 request ...
show more1.206 requests with url.path */auth.json
403 requests with url.path *credentials.json
175 requests with url.path *.config/*
show less
[WedSep2302:51:15.5399012026][security2:error][pid1499771:tid1499872][client34.146.122.166:0]ModSecu ...
show more[WedSep2302:51:15.5399012026][security2:error][pid1499771:tid1499872][client34.146.122.166:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"aati.ch.136-243-54-122.cpanel.site\"][uri\"/.codex/auth.json.old\"][unique_id\"arMig9orl474EaGm0mPojQAAAM8\"]
show less