๐ฉ๐ช
klaus_ph
2026-09-27 00:09:26
(1 week ago)
2026-09-25 22:45:16,916 fail2ban.actions [594716]: NOTICE [ipblocklist] Ban 34.140.217.206
. ...
show more
2026-09-25 22:45:16,916 fail2ban.actions [594716]: NOTICE [ipblocklist] Ban 34.140.217.206
...
show less
Bad Web Bot
๐ฉ๐ช
klaus_ph
2026-09-23 13:08:19
(2 weeks ago)
2026-09-23 00:30:36,074 fail2ban.actions [535885]: NOTICE [ipblocklist] Ban 34.140.217.206
. ...
show more
2026-09-23 00:30:36,074 fail2ban.actions [535885]: NOTICE [ipblocklist] Ban 34.140.217.206
...
show less
Bad Web Bot
๐ฎ๐ช
RoboSOC
2026-09-22 03:03:42
(2 weeks ago)
Spring Cloud SPEL Remote Code Execution Vulnerability, PTR: 206.217.140.34.bc.googleusercontent.com.
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-22 01:38:32
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.140.217.206 (206.217.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.217.206 (206.217.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:38:25.280720 2026] [security2:error] [pid 15974:tid 15974] [client 34.140.217.206:42416] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.gogitzit.com"] [uri "/.git/config"] [unique_id "arHcESVli37HHiUJq9cXGAAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-22 00:59:19
(2 weeks ago)
This address declares itself a crawler and keeps requesting pages after being refused (HTTP 403/429) ...
show more
This address declares itself a crawler and keeps requesting pages after being refused (HTTP 403/429) and told to stop by robots.txt. A crawler that ignores refusals costs our servers capacity for nothing and is treated as abusive; blocked. Please make it honour robots.txt and the refusals it is given. | ua: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot) (+2 more) | path: /host.key (+12 more) | 2026-09-22 00:59 UTC
show less
Bad Web Bot
๐ง๐ช
cmbplf
2026-09-22 00:44:47
(2 weeks ago)
168 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
๐ฉ๐ช
ghostwarriors
2026-09-22 00:20:07
(2 weeks ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-22 00:05:42
(2 weeks ago)
34.140.217.206 - - [22/Sep/2026:02:05:38 +0200] "GET /assets/.env HTTP/2.0" 404 300 "-" "Mozilla/5.0 ...
show more
34.140.217.206 - - [22/Sep/2026:02:05:38 +0200] "GET /assets/.env HTTP/2.0" 404 300 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
34.140.217.206 - - [22/Sep/2026:02:05:38 +0200] "GET /.env_sample HTTP/2.0" 404 300 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
34.140.217.206 - - [22/Sep/2026:02:05:38 +0200] "GET /.env.old HTTP/2.0" 403 304 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
34.140.217.206 - - [22/Sep/2026:02:05:38 +0200] "GET /api/.env HTTP/2.0" 404 300 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
34.140.217.206 - - [22/Sep/2026:02:05:38 +0200] "GET /api/v1/env HTTP/2.0" 404 300 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
34.140.217.206 - - [22/Sep/2026:02:05:38 +0200] "GET /private/.env HTTP/2.0" 4
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-21 23:41:09
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.140.217.206 (206.217.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.217.206 (206.217.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:41:06.787305 2026] [security2:error] [pid 12708:tid 12708] [client 34.140.217.206:46974] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.goldenanniversarynapkins.com"] [uri "/wp-config.php.old"] [unique_id "arHAkvH6BGTqJz27QMITQwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-21 23:40:56
(2 weeks ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-21 22:38:33
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.140.217.206 (206.217.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.217.206 (206.217.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:38:30.138651 2026] [security2:error] [pid 12351:tid 12351] [client 34.140.217.206:49526] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.goglobex.com"] [uri "/agents/.env"] [unique_id "arGx5trUACJTHo9mAAnh3AAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 21:45:07
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.140.217.206 (206.217.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.217.206 (206.217.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:45:00.503712 2026] [security2:error] [pid 13867:tid 13867] [client 34.140.217.206:55958] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.ggisoft.com"] [uri "/backend/.env"] [unique_id "arGlXElRYwD6J6HosLfreQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-09-21 21:27:41
(2 weeks ago)
Aggressive web search of vulnerable pages: /.env /static../.env /media../.env /files../.env /static/ ...
show more
Aggressive web search of vulnerable pages: /.env /static../.env /media../.env /files../.env /static/.env ...
show less
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-21 20:54:32
(2 weeks ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:22:53
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.140.217.206 (206.217.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.217.206 (206.217.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:22:45.117317 2026] [security2:error] [pid 14668:tid 14668] [client 34.140.217.206:46114] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gatheringsattheschool.com"] [uri "/.env.js"] [unique_id "arGSFZwSqwDE-iydlvQWDAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack