🇺🇦
Scientific Route
2026-09-06 12:29:14
(3 hours ago)
34.71.197.159 - - [06/Sep/2026:15:29:13 +0300] "GET /_nuxt/../.env HTTP/1.1" 404 219 "-" "Mozilla/5. ...
show more
34.71.197.159 - - [06/Sep/2026:15:29:13 +0300] "GET /_nuxt/../.env HTTP/1.1" 404 219 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
34.71.197.159 - - [06/Sep/2026:15:29:13 +0300] "GET /media../.env HTTP/1.1" 404 4163 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 10:50:49
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.71.197.159 (159.197.71.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.71.197.159 (159.197.71.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 06:50:42.051431 2026] [security2:error] [pid 10223:tid 10231] [client 34.71.197.159:59898] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||conceptsinammunition.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "conceptsinammunition.com"] [uri "/rclone.conf"] [unique_id "ap1FgnBS88ddYV0XpKSrvgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
maxpower
2026-09-06 10:22:51
(5 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.71.197.159 (US/United States/159.197. ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.71.197.159 (US/United States/159.197.71.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.71.197.159 - - [06/Sep/2026:12:22:47 +0200] "GET /.aws/credentials HTTP/2.0" 200 4722 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36" "34.71.197.159" host=www.masterlabvideoproduzioni.it
show less
Port Scan
🇳🇱
Savvii
2026-09-06 10:08:47
(6 hours ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 09:41:06
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.71.197.159 (159.197.71.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.71.197.159 (159.197.71.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 05:40:58.421840 2026] [security2:error] [pid 18935:tid 18935] [client 34.71.197.159:40298] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.ofertasdetrabajosyempleos.com|F|2"] [data ".ofertasdetrabajosyempleos.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.ofertasdetrabajosyempleos.com"] [uri "/z9x8c7v6b5-debug-trigger-www.ofertasdetrabajosyempleos.com"] [unique_id "ap01Ksmo_a07uGkUC7ZjPQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 09:39:37
(6 hours ago)
34.71.197.159 - - [06/Sep/2026:04:39:31 -0500] "GET /.env.production?import&raw HTTP/1.1" 403 10804 ...
show more
34.71.197.159 - - [06/Sep/2026:04:39:31 -0500] "GET /.env.production?import&raw HTTP/1.1" 403 10804 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Mobile Safari/537.36" 172.70.131.186
34.71.197.159 - - [06/Sep/2026:04:39:31 -0500] "GET /.env.development?import&raw HTTP/1.1" 403 10804 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Mobile Safari/537.36" 172.70.131.186
34.71.197.159 - - [06/Sep/2026:04:39:31 -0500] "GET /.env.production?raw HTTP/1.1" 403 10804 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Mobile Safari/537.36" 172.70.131.186
34.71.197.159 - - [06/Sep/2026:04:39:31 -0500] "GET /.env.local?import&raw HTTP/1.1" 403 10804 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Mobile Safari/537.36" 172.70.131.185
34.71.197.159 - - [06/Sep/2026:04:39:31 -0500] "GET /.env.local?raw HTTP/1.1" 4
...
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 09:38:05
(6 hours ago)
Detected by CrowdSec: crowdsecurity/http-path-traversal-probing
Web App Attack
🇫🇷
COMAITE
2026-09-06 09:34:00
(6 hours ago)
Common web attack from 34.71.197.159.
Web App Attack
🇳🇱
ConsulHosting
2026-09-06 09:29:57
(6 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
Anonymous
2026-09-06 09:06:56
(7 hours ago)
34.71.197.159 - - [06/Sep/2026:09:06:55 +0000] "GET /api/proc/self/environ HTTP/2.0" 404 64 "https: ...
show more
34.71.197.159 - - [06/Sep/2026:09:06:55 +0000] "GET /api/proc/self/environ HTTP/2.0" 404 64 "https://ivonne.ca/api/w/admins/jobs_u/get_log_file/../../../../proc/self/environ" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36" "34.71.197.159" "-"
...
show less
Web App Attack
🇨🇭
zynex
2026-09-06 09:00:16
(7 hours ago)
URL Probing: /@fs/proc/self/cwd/.env
Web App Attack
🇳🇿
Antinson
2026-09-06 08:55:42
(7 hours ago)
Scraping with a high error ratio and request rate
Bad Web Bot
🇫🇷
dynamix
2026-09-06 08:43:45
(7 hours ago)
Multiple WAF Violations
Web App Attack
🇩🇪
zumbo.net
2026-09-06 08:41:03
(7 hours ago)
[Sun Sep 06 11:41:02.207526 2026] [proxy_fcgi:error] [pid 28537:tid 28551] [client 34.71.197.159:0] ...
show more
[Sun Sep 06 11:41:02.207526 2026] [proxy_fcgi:error] [pid 28537:tid 28551] [client 34.71.197.159:0] AH01071: Got error 'Primary script unknown'
[Sun Sep 06 11:41:02.208737 2026] [proxy_fcgi:error] [pid 28537:tid 28544] [client 34.71.197.159:0] AH01071: Got error 'Primary script unknown'
[Sun Sep 06 11:41:02.209118 2026] [proxy_fcgi:error] [pid 28566:tid 28592] [client 34.71.197.159:0] AH01071: Got error 'Primary script unknown'
[Sun Sep 06 11:41:02.228292 2026] [proxy_fcgi:error] [pid 28537:tid 28562] [client 34.71.197.159:0] AH01071: Got error 'Primary script unknown'
[Sun Sep 06 11:41:02.572238 2026] [proxy_fcgi:error] [pid 28566:tid 28584] [client 34.71.197.159:0] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 08:32:51
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.71.197.159 (159.197.71.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.71.197.159 (159.197.71.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 04:32:43.747337 2026] [security2:error] [pid 25251:tid 25251] [client 34.71.197.159:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cloudex.click|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cloudex.click"] [uri "/rclone.conf"] [unique_id "ap0lK03sIEf7TSjsmv7-fwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack