This IP address has been reported a total of
112
times from
51 distinct
sources.
34.168.235.167 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Germany
with 45
reports;
United States of America
with 21
reports;
Netherlands
with 10
reports.
The most common categories in these recent reports were:
Web App Attack
88
times;
Brute-Force
43
times;
Bad Web Bot
32
times;
Hacking
12
times;
Port Scan
8
times;
Other
23
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
This address is looking for secret files on our sites: .git directories, .env files, credential and ...
show moreThis address is looking for secret files on our sites: .git directories, .env files, credential and configuration files, database dumps, backups. This is a targeted search for credentials to break into the sites, blocked at the first request. Please check the machine behind it for an attack tool or malware. | method: GET | path: /.git/config (+5 more) | 2026-09-22 02:40 UTC
show less
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: Word ...
show moreBlocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
[MonSep2123:28:38.4202962026][security2:error][pid4029219:tid4029284][client34.168.235.167:0]ModSecu ...
show more[MonSep2123:28:38.4202962026][security2:error][pid4029219:tid4029284][client34.168.235.167:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\\$\(\?:\\\\\\\\\(\(\?:\\\\\\\\\(.\*\\\\\\\\\)\|.\*\)\\\\\\\\\)\|\\\\\\\\{.\*\\\\\\\\}\)\|[\<\>]\\\\\\\\\(.\*\\\\\\\\\)\)\"atARGS:0.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"396\"][id\"393655\"][rev\"17\"][msg\"Atomicorp.comWAFRules:PossibleRemoteCommandExecution:UnixShellExpressionFound\"][data\"MatchedData:\$\(\(41\*271\)\)foundwithinARGS:0:{then:\$1:__proto__:thenstatus:resolved_modelreason:-1value:{then:\$b1337}_response:{_prefix:varres=process.mainmodule.require\(child_process\).execsync\(echo\$\(\(41\*271\)\)\|base64-w0\).tostring\(\).trim\(\)throwobject.assign\(newerror\(next_redirect\){digest:\`next_redirectpush/login\?a=\${res}307\`}\)_chunks:\$q2_formdata:{get:\$1:constructor:constructor}}}\"][tag\"attack-rce\"][hostname\"dsfiduciaria.ch\"][uri\"/\"][unique_id\"arGhhv3YGk4Ke90AAf5dQwAAAIQ\"]
show less
Malicious web probe detected on bearstool.com: 34.168.235.167 - - [21/Sep/2026:15:17:21 -0400] "GET ...
show moreMalicious web probe detected on bearstool.com: 34.168.235.167 - - [21/Sep/2026:15:17:21 -0400] "GET /.git/config HTTP/2.0" 404 935 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show moreAuto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-18.
show less
Triggered Cloudflare WAF (linkMaze) from US.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/1.1 (GE ...
show moreTriggered Cloudflare WAF (linkMaze) from US.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
time="2026-09-19T06:23:23Z" level=info msg="Access to https://dash.sw0ok.dev/dashboard/ (method POST ...
show moretime="2026-09-19T06:23:23Z" level=info msg="Access to https://dash.sw0ok.dev/dashboard/ (method POST) is not authorized to user <anonymous>, responding with status code 303 with location redirect to https://auth.sw0ok.dev/?rd=https%3A%2F%2Fdash.sw0ok.dev%2Fdashboard%2F&rm=POST" method=GET path=/api/authz/forward-auth remote_ip=34.168.235.167
time="2026-09-19T06:23:23Z" level=info msg="Access to https://dash.sw0ok.dev/dashboard/ (method POST) is not authorized to user <anonymous>, responding with status code 303 with location redirect to https://auth.sw0ok.dev/?rd=https%3A%2F%2Fdash.sw0ok.dev%2Fdashboard%2F&rm=POST" method=GET path=/api/authz/forward-auth remote_ip=34.168.235.167
time="2026-09-19T06:23:24Z" level=info msg="Access to https://dash.sw0ok.dev/dashboard/ (method POST) is not authorized to user <anonymous>, responding with status code 303 with location redirect to https://auth.sw0ok.dev/?rd=https%3A%2F%2Fdash.sw0ok.dev%2Fdashboard%2F&rm=POST" method=GET path=/api/authz/forwar
...
show less