๐ฉ๐ช
klaus_ph
2026-09-26 23:25:04
(1 week ago)
2026-09-25 22:13:50,205 fail2ban.actions [594716]: NOTICE [ipblocklist] Ban 34.131.72.109
.. ...
show more
2026-09-25 22:13:50,205 fail2ban.actions [594716]: NOTICE [ipblocklist] Ban 34.131.72.109
...
show less
Bad Web Bot
๐ฉ๐ช
klaus_ph
2026-09-23 12:48:29
(2 weeks ago)
2026-09-23 00:21:58,108 fail2ban.actions [535885]: NOTICE [ipblocklist] Ban 34.131.72.109
.. ...
show more
2026-09-23 00:21:58,108 fail2ban.actions [535885]: NOTICE [ipblocklist] Ban 34.131.72.109
...
show less
Bad Web Bot
๐ฎ๐ณ
evicky2002
2026-09-23 06:00:01
(2 weeks ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฌ๐ง
andypiper
2026-09-23 01:01:03
(2 weeks ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
Anonymous
2026-09-23 00:15:22
(2 weeks ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: IN, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: IN, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 08:57:05
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.131.72.109 (109.72.131.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.131.72.109 (109.72.131.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 04:56:58.407716 2026] [security2:error] [pid 26295:tid 26295] [client 34.131.72.109:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ac.cloudex.click"] [uri "/.git/config"] [unique_id "arJC2ixQ-qTwUZnPM0IvqwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-22 07:00:03
(2 weeks ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
abuse-opdc
2026-09-22 05:05:42
(2 weeks ago)
Malicious HTTP requests matching injection/exploit signatures.
Web App Attack
Brute-Force
๐ช๐ธ
robotstxt
2026-09-22 05:03:24
(2 weeks ago)
34.131.72.109 - - [22/Sep/2026:05:02:56 +0000] "GET /.env HTTP/1.1" 403 205 "-" "Mozilla/5.0 (X11; L ...
show more
34.131.72.109 - - [22/Sep/2026:05:02:56 +0000] "GET /.env HTTP/1.1" 403 205 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
34.131.72.109 - - [22/Sep/2026:05:02:56 +0000] "GET /.env.local HTTP/1.1" 403 205 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
34.131.72.109 - - [22/Sep/2026:05:02:56 +0000] "GET /.env.production HTTP/1.1" 403 205 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
34.131.72.109 - - [22/Sep/2026:05:02:57 +0000] "GET /.env.staging HTTP/1.1" 403 205 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
34.131.72.109 - - [22/Sep/2026:05:02:57 +0000] "GET /.env.development HTTP/1.1" 403 205 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 04:42:03
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.131.72.109 (109.72.131.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.131.72.109 (109.72.131.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 00:41:59.636194 2026] [security2:error] [pid 13551:tid 13559] [client 34.131.72.109:43794] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abusaimeh.com"] [uri "/.git/config"] [unique_id "arIHFzfwFWVCBYYrJWBYmQAAAQU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 02:37:47
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.131.72.109 (109.72.131.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.131.72.109 (109.72.131.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 22:37:39.721397 2026] [security2:error] [pid 10600:tid 10600] [client 34.131.72.109:48478] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abu-dhabi-boat-registration.com"] [uri "/.git/config"] [unique_id "arHp8_GfjqeGzzZMTO7kegAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-22 02:21:10
(2 weeks ago)
6.845 requests with url.path *.env
1.298 requests with url.path *phpinfo.php
205 requests with ur ...
show more
6.845 requests with url.path *.env
1.298 requests with url.path *phpinfo.php
205 requests with url.path *credentials.json
112 requests with url.path *.php.bak
show less
Brute-Force
Bad Web Bot
๐ณ๐ฑ
Site.eu
2026-09-22 01:35:43
(2 weeks ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-22 01:29:45
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.131.72.109 (109.72.131.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.131.72.109 (109.72.131.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:29:38.069567 2026] [security2:error] [pid 30633:tid 30762] [client 34.131.72.109:41694] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "absurdotron.com"] [uri "/.git/config"] [unique_id "arHaAsbHdU-pqdnv8ZJMDQAAAQ8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 01:00:33
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.131.72.109 (109.72.131.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.131.72.109 (109.72.131.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:00:25.341261 2026] [security2:error] [pid 25511:tid 25511] [client 34.131.72.109:46078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abstractorangemusic.com"] [uri "/.git/config"] [unique_id "arHTKUlTvISrPxzUgGsq_QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack