This IP address has been reported a total of
29
times from
22 distinct
sources.
34.97.213.190 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[TueSep0105:34:31.7054112026][security2:error][pid3600976:tid3601036][client34.97.213.190:0]ModSecur ...
show more[TueSep0105:34:31.7054112026][security2:error][pid3600976:tid3601036][client34.97.213.190:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"www.autoeuro.lv.136-243-54-122.cpanel.site\"][uri\"/.env.bak\"][unique_id\"apZHx7OgiAcBuLT9DX-2mQAAAFc\"]
show less
34.97.213.190 - - [31/Aug/2026:19:00:07 +0200] "POST / HTTP/1.1" 200 634 "-" "Mozilla/5.0 (X11; Linu ...
show more34.97.213.190 - - [31/Aug/2026:19:00:07 +0200] "POST / HTTP/1.1" 200 634 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.97.213.190 - - [31/Aug/2026:19:00:07 +0200] "GET /.env HTTP/1.1" 404 631 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.97.213.190 - - [31/Aug/2026:19:00:07 +0200] "GET /.env.local HTTP/1.1" 404 631 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.97.213.190 - - [31/Aug/2026:19:00:07 +0200] "GET /.env.production HTTP/1.1" 404 631 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.97.213.190 - - [31/Aug/2026:19:00:08 +0200] "GET /.env.staging HTTP/1.1" 404 631 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.97.213.190 - - [31/Aug/2026:19:00:08 +0200] "GET /.env.
show less
Web App Attack
Hacking
Anonymous
Bot / scanning and/or hacking attempts: GET /app/.env HTTP/1.1, GET /api/.env HTTP/1.1, GET /.env.ya ...
show moreBot / scanning and/or hacking attempts: GET /app/.env HTTP/1.1, GET /api/.env HTTP/1.1, GET /.env.yaml HTTP/1.1, GET /web/.env HTTP/1.1, GET /.env.uat HTTP/1.1, GET /.env.yml HTTP/1.1, GET /.env.json HTTP/1.1, GET /.env1 HTTP/1.1, GET /.env2 HTTP/1.1, GET /apps/.env HTTP/1.1
show less
[Mon Aug 31 17:04:05.682625 2026] [php:error] [pid 2240282] [client 34.97.213.190:54122] script '/ho ...
show more[Mon Aug 31 17:04:05.682625 2026] [php:error] [pid 2240282] [client 34.97.213.190:54122] script '/home/pawel/biuro/phpinfo.php' not found or unable to stat
[Mon Aug 31 17:04:05.931804 2026] [php:error] [pid 2240282] [client 34.97.213.190:54122] script '/home/pawel/biuro/info.php' not found or unable to stat
[Mon Aug 31 17:04:06.180135 2026] [php:error] [pid 2240282] [client 34.97.213.190:54122] script '/home/pawel/biuro/php.php' not found or unable to stat
...
show less
(mod_security) mod_security triggered on hostname [redacted] 34.97.213.190 (JP/Japan/190.213.97.34.b ...
show more(mod_security) mod_security triggered on hostname [redacted] 34.97.213.190 (JP/Japan/190.213.97.34.bc.googleusercontent.com)
show less