This IP address has been reported a total of
50
times from
30 distinct
sources.
34.165.94.122 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[SatSep1917:40:45.8772762026][security2:error][pid944853:tid944920][client34.165.94.122:0]ModSecurit ...
show more[SatSep1917:40:45.8772762026][security2:error][pid944853:tid944920][client34.165.94.122:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"cpanel.vulcanoricambi.ch\"][uri\"/.env.bak\"][unique_id\"aq6s_a9ADXrHhKw7YnfTrwAAAIY\"]
show less
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show moreAuto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-17.
show less
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
Anonymous
Honeypot: hit a non-existent, robots.txt-disallowed trap path / fake admin console on a WordPress st ...
show moreHoneypot: hit a non-existent, robots.txt-disallowed trap path / fake admin console on a WordPress store, then probed fake "database export" endpoints. Automated scanner attempting data theft / exfiltration.
show less
Hacking
Bad Web Bot
Web App Attack
Anonymous
Blocked by web application firewall: automated malicious HTTP requests (WordPress xmlrpc.php / wp-lo ...
show moreBlocked by web application firewall: automated malicious HTTP requests (WordPress xmlrpc.php / wp-login brute-force and admin-panel scanning). Distributed botnet / automated tooling. No legitimate use.
show less
[FriSep1808:23:51.8832092026][security2:error][pid3236906:tid3236965][client34.165.94.122:0]ModSecur ...
show more[FriSep1808:23:51.8832092026][security2:error][pid3236906:tid3236965][client34.165.94.122:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"cpanel.tpgs.ch\"][uri\"/.env.bak\"][unique_id\"aqzY9x72rjVNJ8_IWBh8JQAAAFU\"]
show less
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b ...
show moreRemote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b (932235-195)
show less