This IP address has been reported a total of
24
times from
20 distinct
sources.
34.134.7.30 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Netherlands
with 9
reports;
United States of America
with 7
reports;
Germany
with 5
reports.
The most common categories in these recent reports were:
Web App Attack
21
times;
Brute-Force
10
times;
Bad Web Bot
8
times;
Hacking
6
times;
Port Scan
2
times;
Other
2
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show moreAuto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-10-08.
show less
Web App Attack
SSH
Hacking
Anonymous
34.134.7.30 - - [09/Oct/2026:01:11:22 +0200] "GET /%2e%2e/.env HTTP/1.1" 400 552 "-" "Mozilla/5.0 Ap ...
show more34.134.7.30 - - [09/Oct/2026:01:11:22 +0200] "GET /%2e%2e/.env HTTP/1.1" 400 552 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot" ...
show less
Bot / scanning and/or hacking attempts: POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/. ...
show moreBot / scanning and/or hacking attempts: POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e, POST /cgi-bin/php?-d+allow_url_include%3don+-d+auto_prepend_fil, POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%, POST /cgi-bin/php-cgi?-d+allow_url_include%3don+-d+auto_prepend, POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_
show less
Probing for admin interfaces: GET /admin%2F.env, GET /api/w/admins/jobs_u/get_log_file/../../../../p ...
show moreProbing for admin interfaces: GET /admin%2F.env, GET /api/w/admins/jobs_u/get_log_file/../../../../proc/self/env~, GET /public/admin.json | Exploit attempt for CVE-2021-41773: GET /%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env | Probing for sensitive files: GET /static../.env, GET /media../.env, GET /api/uploads/%2e%2e%2f%2e%2e%2f.env, GET /files../.env, GET /secrets.env | Path traversal attempts: GET /static../.env, GET /media../.env, GET /api/uploads/%2e%2e%2f%2e%2e%2f.env, GET /public/plugins/text/../../../../../../../../proc/self/envi~ | Exploit attempt for CVE-2021-43798: GET /public/plugins/text/../../../../../../../../proc/self/envi~ [14 events, 2026-10-08T21:55:04Z; auto-reported by CrowdSec]
show less
Automated report: Unauthorized vulnerability scanning detected on 2026-10-08. 1383 requests from thi ...
show moreAutomated report: Unauthorized vulnerability scanning detected on 2026-10-08. 1383 requests from this IP.
show less
Cluster member (Omitted) (FR/France/-) said, TEMPDENY 34.134.7.30, Reason:[(Suspicious404) Suspiciou ...
show moreCluster member (Omitted) (FR/France/-) said, TEMPDENY 34.134.7.30, Reason:[(Suspicious404) Suspicious activity detected 34.134.7.30 (US/United States/30.7.134.34.bc.googleusercontent.com): 10 in the last 3600 secs]
show less