This IP address has been reported a total of
25
times from
19 distinct
sources.
34.12.245.140 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Netherlands
with 5
reports;
United States of America
with 5
reports;
Germany
with 3
reports.
The most common categories in these recent reports were:
Web App Attack
18
times;
Brute-Force
8
times;
Hacking
6
times;
Bad Web Bot
5
times;
Port Scan
5
times;
Other
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Automated ban via infra-monitor: suspicious-probe, crowdsecurity/http-cve-2021-41773, wp-sensitive-p ...
show moreAutomated ban via infra-monitor: suspicious-probe, crowdsecurity/http-cve-2021-41773, wp-sensitive-paths, +6 more
show less
(mod_security) mod_security (id:949110) triggered by 34.12.245.140 (140.245.12.34.bc.googleuserconte ...
show more(mod_security) mod_security (id:949110) triggered by 34.12.245.140 (140.245.12.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
Anonymous
Bot / scanning and/or hacking attempts: POST /api/templates/preview HTTP/2.0, POST /read-document HT ...
show moreBot / scanning and/or hacking attempts: POST /api/templates/preview HTTP/2.0, POST /read-document HTTP/2.0, POST /feast/read-document HTTP/2.0, POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e, POST /api/designer/v1/file-content HTTP/2.0, POST /cgi-bin/php-cgi?-d+allow_url_include%3don+-d+auto_prepend, POST /flowise/api/v1/node-load-method/customMCP HTTP/2.0, POST /api/v1/node-load-method/customMCP HTTP/2.0, POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%, POST /exec-py HTTP/2.0, POST /cgi-bin/php?-d+allow_url_include%3don+-d+auto_prepend_fil, POST /api/fs/exec HTTP/2.0, POST /cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_, GET /_security/_authenticate HTTP/2.0
show less
[ThuOct0111:06:55.9325912026][security2:error][pid3525305:tid3525315][client34.12.245.140:0]ModSecur ...
show more[ThuOct0111:06:55.9325912026][security2:error][pid3525305:tid3525315][client34.12.245.140:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:queryintrospectionquery\?\|__schema\\\\\\\\\?{\?\(\?:querytype\|types\?\)\)\?\\\\\\\\{\"atREQUEST_BODY.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"234\"][id\"344378\"][rev\"2\"][msg\"Atomicorp.comWAFRules:GraphQLInjectionAttackattempt\"][data\"MatchedData:__schema{types{foundwithinREQUEST_BODY:{\\\\x22query\\\\x22:\\\\x22{__schema{types{namefields{nameargs{namedefaultvalue}}}}}\\\\x22}\"][severity\"CRITICAL\"][tag\"SQLi\"][hostname\"www.aidconsultancy.ch\"][uri\"/graphql\"][unique_id\"ar4ir7qGgMP4FXkQPUoh3wAAAUg\"]\,referer:https://www.aidconsultancy.ch
show less