This IP address has been reported a total of
9
times from
7 distinct
sources.
34.61.13.105 was first reported on
September 21st 2026 , and the most recent report was
2 weeks ago .
In the last 60 days, the top reporter locations were:
United States of America
with 3
reports;
Czechia
with 2
reports;
Germany
with 2
reports.
The most common categories in these recent reports were:
Web App Attack
8
times;
Bad Web Bot
5
times;
Brute-Force
5
times;
Port Scan
1
time;
Exploited Host
1
time;
Other
2
times.
Old Reports
The most recent abuse report for this IP address is from
2 weeks ago . It is possible that this IP is no
longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐ซ๐ท
SpaceHost-Server
2026-09-22 22:24:35
(2 weeks ago)
Brute-Force
Web App Attack
๐ฉ๐ช
ใใใจใใใใ
2026-09-22 05:14:33
(2 weeks ago)
Automated web attack source per OWASP CRS classification against a self-hosted nginx web service. . ...
show more
Automated web attack source per OWASP CRS classification against a self-hosted nginx web service. . Self-hosted service; no site identifiers included.
show less
Port Scan
Web App Attack
๐ฉ๐ช
loveprod
2026-09-22 00:15:28
(2 weeks ago)
34.61.13.105 - - [22/Sep/2026:03:15:27 +0300] "GET /.git/HEAD HTTP/2.0" 403 359 "-" "Mozilla/5.0 (co ...
show more
34.61.13.105 - - [22/Sep/2026:03:15:27 +0300] "GET /.git/HEAD HTTP/2.0" 403 359 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
34.61.13.105 - - [22/Sep/2026:03:15:27 +0300] "GET /.env HTTP/2.0" 403 359 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
...
show less
Bad Web Bot
๐ท๐บ
DZBOT
2026-09-21 23:07:34
(2 weeks ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
Anonymous
2026-09-21 21:01:52
(2 weeks ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 12:56:37
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 34.61.13.105 (105.13.61.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.61.13.105 (105.13.61.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 08:56:33.142633 2026] [security2:error] [pid 148199:tid 148199] [client 34.61.13.105:39190] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||21-0322.dynamic-therapy-mn.com|F|2"] [data ".dynamic-therapy-mn.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "21-0322.dynamic-therapy-mn.com"] [uri "/z9x8c7v6b5-debug-trigger-21-0322.dynamic-therapy-mn.com"] [unique_id "arEpgbmwHHFQ93KrruhtMgAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 12:40:08
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.61.13.105 (105.13.61.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.61.13.105 (105.13.61.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 08:40:04.994822 2026] [security2:error] [pid 24423:tid 24423] [client 34.61.13.105:33720] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.20dekopas.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "arElpAZxscXYJkLOy6DRzgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 11:36:50
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 34.61.13.105 (105.13.61.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.61.13.105 (105.13.61.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 07:36:45.683608 2026] [security2:error] [pid 7331:tid 7331] [client 34.61.13.105:49194] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||21north.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "21north.com"] [uri "/z9x8c7v6b5-debug-trigger-21north.com"] [unique_id "arEWzQTxzuXG7z6ErPgyeQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 10:50:06
(2 weeks ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
Showing 1 to
9
of 9 reports