๐บ๐ธ
TPI-Abuse
2026-09-22 01:28:53
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.140.185.179 (179.185.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.185.179 (179.185.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:28:47.514682 2026] [security2:error] [pid 9884:tid 9884] [client 34.140.185.179:57684] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.fynyx.com"] [uri "/.env.development"] [unique_id "arHZz2ZlXqn1BFMXwZvKbAAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-22 01:25:02
(2 days ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 00:10:09
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.140.185.179 (179.185.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.185.179 (179.185.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:10:02.594250 2026] [security2:error] [pid 4687:tid 4687] [client 34.140.185.179:47750] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.galengetting.com"] [uri "/.git/config"] [unique_id "arHHWgTe-o0aIrGAldZDagAAADU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 23:30:44
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.140.185.179 (179.185.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.185.179 (179.185.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:30:37.586687 2026] [security2:error] [pid 4893:tid 4893] [client 34.140.185.179:37268] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.gamepart.com"] [uri "/shop/.env"] [unique_id "arG-HY5IO_1CG_A1ftFxcwAAAD8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-21 22:42:21
(2 days ago)
34.140.185.179 - - [22/Sep/2026:00:42:18 +0200] "GET /api%2F.env HTTP/2.0" 404 294 "-" "Mozilla/5.0 ...
show more
34.140.185.179 - - [22/Sep/2026:00:42:18 +0200] "GET /api%2F.env HTTP/2.0" 404 294 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
34.140.185.179 - - [22/Sep/2026:00:42:18 +0200] "GET /api/sysConfig/getAll HTTP/2.0" 404 294 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
34.140.185.179 - - [22/Sep/2026:00:42:18 +0200] "GET /privatekey.key HTTP/2.0" 404 294 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
34.140.185.179 - - [22/Sep/2026:00:42:18 +0200] "GET /key.pem HTTP/2.0" 403 297 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
34.140.185.179 - - [22/Sep/2026:00:42:18 +0200] "GET /settings%2F.env HTTP/2.0" 404 294 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
34.140.185.179 - - [22/Sep/2026:00:42:18 +0200] "GET /localhost.key HTTP/2.0" 403 297 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
34.140.185.179 - - [22/Sep/2026:00:42:18 +0200] "GET /id_ecdsa HTTP
show less
Bad Web Bot
๐ฉ๐ช
crypto i trust, hold i must
2026-09-21 22:06:23
(2 days ago)
Web scanner path: /private/.env
Web App Attack
๐ฌ๐ง
consul.to
2026-09-21 21:51:41
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-09-21 20:04:49
(2 days ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-21 19:15:01
(2 days ago)
Excessive 404/403 errors
Brute-Force
Anonymous
2026-09-21 18:51:30
(2 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
xmission.com
2026-09-21 12:03:40
(2 days ago)
Blocked by UFW (TCP on 8080)
Source port: 58520
TTL: 60
Packet length: 60
TOS: 0x00
This report (fo ...
show more
Blocked by UFW (TCP on 8080)
Source port: 58520
TTL: 60
Packet length: 60
TOS: 0x00
This report (for 34.140.185.179) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Web App Attack
๐ฉ๐ช
itsolon
2026-09-21 11:14:17
(3 days ago)
[21/Sep/2026:13:14:16 +0200] 178998925651.802295 34.140.185.179 45792 217.154.7.177 443
[21/Sep/2026 ...
show more
[21/Sep/2026:13:14:16 +0200] 178998925651.802295 34.140.185.179 45792 217.154.7.177 443
[21/Sep/2026:13:14:16 +0200] 178998925670.900534 34.140.185.179 45792 217.154.7.177 443
[21/Sep/2026:13:14:16 +0200] 178998925656.259508 34.140.185.179 45792 217.154.7.177 443
[21/Sep/2026:13:14:16 +0200] 178998925658.466556 34.140.185.179 45792 217.154.7.177 443
[21/Sep/2026:13:14:16 +0200] 178998925648.849365 34.140.185.179 45792 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 11:09:05
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.140.185.179 (179.185.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.185.179 (179.185.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 07:08:56.089393 2026] [security2:error] [pid 12353:tid 12353] [client 34.140.185.179:36460] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "1healthplace.com.darkcodedesign.net"] [uri "/wp-config.php.bak"] [unique_id "arEQSDGZsmtf92c8kcgh_AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 10:40:15
(3 days ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐ซ๐ท
dynamix
2026-09-21 10:36:47
(3 days ago)
Multiple WAF Violations
Web App Attack