This IP address has been reported a total of
9
times from
7 distinct
sources.
34.18.236.108 was first reported on
September 15th 2026 , and the most recent report was
2 weeks ago .
In the last 60 days, the top reporter locations were:
United States of America
with 3
reports;
Canada
with 1
report;
Czechia
with 1
report.
The most common categories in these recent reports were:
Web App Attack
9
times;
Brute-Force
5
times;
Bad Web Bot
3
times;
Hacking
3
times;
SSH
1
time.
Old Reports
The most recent abuse report for this IP address is from
2 weeks ago . It is possible that this IP is no
longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐ณ๐ฑ
homeshowdomain.nl
2026-09-17 22:03:09
(2 weeks ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-16.
show less
Web App Attack
SSH
Hacking
๐จ๐ฆ
lakered
2026-09-16 04:45:34
(2 weeks ago)
Detectors: [NGINX] | Reasons: Nginx Honeypot: Sensitive configuration file search | Evidence: High-C ...
show more
Detectors: [NGINX] | Reasons: Nginx Honeypot: Sensitive configuration file search | Evidence: High-Criminality-Signature (ja4:t13d4312h1 - Ratio:0.99), High-Criminality-Signature (ja4h:33f56baf5bd7a8c6c1fc8c4c9a1d4829 - Ratio:0.95) | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | TCP Fingerprint: Linux (Legacy/Embedded) (Link:generic tunnel or VPN, Uptime:70636m)
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 02:57:57
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.18.236.108 (108.236.18.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.236.108 (108.236.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 22:57:53.118177 2026] [security2:error] [pid 22546:tid 22546] [client 34.18.236.108:45800] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "researchdesk.jmnr.net"] [uri "/.git/config"] [unique_id "aqoFsSvN1rMtf847x3hCrwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 02:39:46
(2 weeks ago)
Web application attack detected.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 01:42:24
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.18.236.108 (108.236.18.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.236.108 (108.236.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 21:42:20.545192 2026] [security2:error] [pid 30291:tid 30291] [client 34.18.236.108:56940] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rescuedpekes.com"] [uri "/.git/config"] [unique_id "aqnz_LC0ONqmgjwgR89pOQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-15 12:35:03
(2 weeks ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 10:38:35
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.18.236.108 (108.236.18.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.236.108 (108.236.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 06:38:27.777204 2026] [security2:error] [pid 24410:tid 24410] [client 34.18.236.108:59456] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "doctorspainmanagement.com"] [uri "/.git/config"] [unique_id "aqkgI7Sooi4hCI_UOmeRkAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 09:26:19
(3 weeks ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ฌ๐ง
gws-hostmaster
2026-09-15 04:03:04
(3 weeks ago)
ModSecurity OWASP CRS (Anomaly Score: 50): JavaScript Prototype Pollution;JSON-Based SQL Injection;N ...
show more
ModSecurity OWASP CRS (Anomaly Score: 50): JavaScript Prototype Pollution;JSON-Based SQL Injection;Node.js Injection Attack 1/2;PHP Injection Attack: Variable Access Found;Remote Command Execution: Direct Unix Command Execution;Remote Command Execution: Unix Shell Expression Found;Restricted File Access Attempt;SQL Injection Attack: SQL function name detected;URL file extension is restricted by policy;
show less
Web App Attack
Showing 1 to
9
of 9 reports