This IP address has been reported a total of
183
times from
127 distinct
sources.
34.73.230.219 was first reported on
, and the most recent report was
.
Old Reports:
The most recent abuse report for this IP address is from
. It is possible that this IP is no longer involved in abusive activities.
Vulnerability scanning (requests for admin panels, shells, backup files etc.) against a production s ...
show moreVulnerability scanning (requests for admin panels, shells, backup files etc.) against a production server. Observed on 6 day(s) between 2026-08-14 and 2026-08-18 (UTC).
show less
BAD BOT - Detected and Blocked.. Matched phrase "GPTBot" at REQUEST_HEADERS:user-agent. (1100000-122 ...
show moreBAD BOT - Detected and Blocked.. Matched phrase "GPTBot" at REQUEST_HEADERS:user-agent. (1100000-122)
show less
[SatAug1507:53:30.7704332026][security2:error][pid2797643:tid2797659][client34.73.230.219:0]ModSecur ...
show more[SatAug1507:53:30.7704332026][security2:error][pid2797643:tid2797659][client34.73.230.219:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:queryintrospectionquery\?\|__schema\\\\\\\\\?{\?\(\?:querytype\|types\?\)\)\?\\\\\\\\{\"atREQUEST_BODY.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"234\"][id\"344378\"][rev\"2\"][msg\"Atomicorp.comWAFRules:GraphQLInjectionAttackattempt\"][data\"MatchedData:__schema{types{foundwithinREQUEST_BODY:{\\\\x22query\\\\x22:\\\\x22{__schema{types{namefields{nameargs{namedefaultvalue}}}}}\\\\x22}\"][severity\"CRITICAL\"][tag\"SQLi\"][hostname\"www.gpwealth.ch\"][uri\"/graphql\"][unique_id\"an_-2vhVfxeZOQDQz0KzcwAAAA0\"]\,referer:https://www.gpwealth.ch
show less
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ ...
show moreURL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .compositefont/ .config/ .conf/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .scr/ .sct/ .shs/ .sql/ .swp/ .sys/ .tlb/ .tmp/ .url/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-196)
show less
Hacking
Anonymous
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: Word ...
show moreBlocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Bot / scanning and/or hacking attempts: GET /config/.env.php HTTP/2.0, GET /.zshrc HTTP/2.0, GET /.e ...
show moreBot / scanning and/or hacking attempts: GET /config/.env.php HTTP/2.0, GET /.zshrc HTTP/2.0, GET /.env.php.bak HTTP/2.0, GET /laravel/.env HTTP/2.0, GET /wp-config.php.old HTTP/2.0, GET /storage/logs/laravel.log HTTP/2.0, GET /auth.json HTTP/2.0, GET /.codex/config.toml HTTP/2.0, GET /core/.env HTTP/2.0, GET /.claude/settings.json HTTP/2.0, GET /.hermes/auth.json HTTP/2.0, GET /.bashrc HTTP/2.0, GET /.profile HTTP/2.0, GET /wp-config.php.bak HTTP/2.0, GET /.config/anthropic/credentials/default.json HTTP/2.0, GET /.env.dev HTTP/2.0, GET /configuration.php.bak HTTP/2.0, GET /.bash_profile HTTP/2.0, GET /config.php.bak HTTP/2.0
show less
Hacking
Web App Attack
Showing 1 to
15
of 183 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ