This IP address has been reported a total of
61
times from
43 distinct
sources.
34.165.104.39 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Netherlands
with 12
reports;
Germany
with 10
reports;
France
with 9
reports.
The most common categories in these recent reports were:
Web App Attack
48
times;
Brute-Force
26
times;
Bad Web Bot
17
times;
Hacking
9
times;
Port Scan
6
times;
Other
4
times.
Old Reports
The most recent abuse report for this IP address is from
. It is possible that this IP is no
longer involved in abusive activities.
2026-09-26 00:24:26,650 fail2ban.actions [594716]: NOTICE [ipblocklist] Ban 34.165.104.39
.. ...
show more2026-09-26 00:24:26,650 fail2ban.actions [594716]: NOTICE [ipblocklist] Ban 34.165.104.39
...
show less
2026-09-23 01:13:34,807 fail2ban.actions [535885]: NOTICE [ipblocklist] Ban 34.165.104.39
.. ...
show more2026-09-23 01:13:34,807 fail2ban.actions [535885]: NOTICE [ipblocklist] Ban 34.165.104.39
...
show less
This address is looking for secret files on our sites: .git directories, .env files, credential and ...
show moreThis address is looking for secret files on our sites: .git directories, .env files, credential and configuration files, database dumps, backups. This is a targeted search for credentials to break into the sites, blocked at the first request. Please check the machine behind it for an attack tool or malware. | method: GET | path: /.git/config | 2026-09-22 20:17 UTC
show less
[TueSep2216:28:58.4014592026][security2:error][pid870099:tid870209][client34.165.104.39:0]ModSecurit ...
show more[TueSep2216:28:58.4014592026][security2:error][pid870099:tid870209][client34.165.104.39:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\\$\(\?:\\\\\\\\\(\(\?:\\\\\\\\\(.\*\\\\\\\\\)\|.\*\)\\\\\\\\\)\|\\\\\\\\{.\*\\\\\\\\}\)\|[\<\>]\\\\\\\\\(.\*\\\\\\\\\)\)\"atARGS:0.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"396\"][id\"393655\"][rev\"17\"][msg\"Atomicorp.comWAFRules:PossibleRemoteCommandExecution:UnixShellExpressionFound\"][data\"MatchedData:\$\(\(41\*271\)\)foundwithinARGS:0:{then:\$1:__proto__:thenstatus:resolved_modelreason:-1value:{then:\$b1337}_response:{_prefix:varres=process.mainmodule.require\(child_process\).execsync\(echo\$\(\(41\*271\)\)\|base64-w0\).tostring\(\).trim\(\)throwobject.assign\(newerror\(next_redirect\){digest:\`next_redirectpush/login\?a=\${res}307\`}\)_chunks:\$q2_formdata:{get:\$1:constructor:constructor}}}\"][tag\"attack-rce\"][hostname\"craniosacraltherapy.ch.136-243-54-122.cpanel.site\"][uri\"/\"][unique_id\"arKQqtgXRV_9y03C6w5aG
show less
Web probing (541 hits in 24h) on default-vhost: sensitive-path scans and/or 404 bursts. Reported by ...
show moreWeb probing (541 hits in 24h) on default-vhost: sensitive-path scans and/or 404 bursts. Reported by CRMON.
show less
[Tue Sep 22 06:49:14.951977 2026] [php7:error] [pid 2126037:tid 2126037] [client 34.165.104.39:38470 ...
show more[Tue Sep 22 06:49:14.951977 2026] [php7:error] [pid 2126037:tid 2126037] [client 34.165.104.39:38470] script '/var/www/html/www.craccaaltesoro.it/phpinfo.php' not found or unable to stat
show less
[MonSep2121:58:05.8464762026][security2:error][pid2310847:tid2310953][client34.165.104.39:0]ModSecur ...
show more[MonSep2121:58:05.8464762026][security2:error][pid2310847:tid2310953][client34.165.104.39:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\\$\(\?:\\\\\\\\\(\(\?:\\\\\\\\\(.\*\\\\\\\\\)\|.\*\)\\\\\\\\\)\|\\\\\\\\{.\*\\\\\\\\}\)\|[\<\>]\\\\\\\\\(.\*\\\\\\\\\)\)\"atARGS:0.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"396\"][id\"393655\"][rev\"17\"][msg\"Atomicorp.comWAFRules:PossibleRemoteCommandExecution:UnixShellExpressionFound\"][data\"MatchedData:\$\(\(41\*271\)\)foundwithinARGS:0:{then:\$1:__proto__:thenstatus:resolved_modelreason:-1value:{then:\$b1337}_response:{_prefix:varres=process.mainmodule.require\(child_process\).execsync\(echo\$\(\(41\*271\)\)\|base64-w0\).tostring\(\).trim\(\)throwobject.assign\(newerror\(next_redirect\){digest:\`next_redirectpush/login\?a=\${res}307\`}\)_chunks:\$q2_formdata:{get:\$1:constructor:constructor}}}\"][tag\"attack-rce\"][hostname\"cpu-services.ch\"][uri\"/\"][unique_id\"arGMTbepODey58UHs0OD3AAAAQg\"]
show less
[SunSep2023:10:05.6236122026][security2:error][pid2577414:tid2577481][client34.165.104.39:0]ModSecur ...
show more[SunSep2023:10:05.6236122026][security2:error][pid2577414:tid2577481][client34.165.104.39:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"cpanel.artisteer-italia.org\"][uri\"/.env.bak\"][unique_id\"arBLrflgejIWh3iCCa3JYgAAAIE\"]
show less