🇦🇺
2000cn.com.au
2026-09-08 20:22:16
(19 minutes ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-path-traversal-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-08 20:09:48
(32 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.80.71.31 (31.71.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.71.31 (31.71.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 16:09:43.715355 2026] [security2:error] [pid 20303:tid 20303] [client 34.80.71.31:33494] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stonestreetnh.com.somehand.com"] [uri "/@fs/../../.env"] [unique_id "aqBrh_rPPlKfIl_nntQ_OAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
debestelapp
2026-09-08 19:50:12
(51 minutes ago)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 19:19:33
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.80.71.31 (31.71.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.71.31 (31.71.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:19:26.685644 2026] [security2:error] [pid 16209:tid 16209] [client 34.80.71.31:6142] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mtprogressions.com"] [uri "/@fs/root/.env"] [unique_id "aqBfvuNrpExZkDxmyCTLMAAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
backslash
2026-09-08 19:06:01
(1 hour ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 18:48:38
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.80.71.31 (31.71.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.71.31 (31.71.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:48:32.928161 2026] [security2:error] [pid 13460:tid 13460] [client 34.80.71.31:48958] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.couturebikini.com"] [uri "/@fs/root/.env"] [unique_id "aqBYgFv_0znyxpCtP1PZDwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-08 18:30:27
(2 hours ago)
739 requests with url.path *.aws/*
377 requests with url.path *.ssh/*
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 18:18:43
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.71.31 (31.71.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.71.31 (31.71.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:18:37.095567 2026] [security2:error] [pid 2748:tid 2748] [client 34.80.71.31:61178] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.specialtywebsiteservice.com"] [uri "/@fs/.env"] [unique_id "aqBRfQFuiEShQv4fyPnkQQAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
AWW-Admin
2026-09-08 18:18:04
(2 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.80.71.31 (TW/Taiwan/31.71.80.34.bc.g ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.80.71.31 (TW/Taiwan/31.71.80.34.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
IndigoRidge
2026-09-08 18:12:21
(2 hours ago)
34.80.71.31 - - [08/Sep/2026:14:12:21 -0400] "GET /@fs/root/.aws/credentials?raw?? HTTP/1.1" 404 573 ...
show more
34.80.71.31 - - [08/Sep/2026:14:12:21 -0400] "GET /@fs/root/.aws/credentials?raw?? HTTP/1.1" 404 5739 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.3; +https://openai.com/searchbot)"
34.80.71.31 - - [08/Sep/2026:14:12:21 -0400] "GET /@fs/root/.env?raw?? HTTP/1.1" 403 4955 "-" "Mozilla/5.0 (compatible; meta-externalagent/1.1; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
34.80.71.31 - - [08/Sep/2026:14:12:21 -0400] "GET /@fs/..%252f..%252f..%252f..%252f..%252fapp/.env?raw?? HTTP/1.1" 403 5738 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko; compatible; GrokBot/1.0; +https://x.ai/grokbot) Version/16.2 Mobile/15E148 Safari/604.1"
...
show less
Web App Attack
🇩🇪
LRob
2026-09-08 17:56:31
(2 hours ago)
Enumerating paths that do not exist (scanning) | method: GET | path: /@fs/.env.development (+7 more) ...
show more
Enumerating paths that do not exist (scanning) | method: GET | path: /@fs/.env.development (+7 more) | 2026-09-08 17:56 UTC
show less
Port Scan
Web App Attack
Anonymous
2026-09-08 17:37:19
(3 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-08 17:16:11
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.71.31 (31.71.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.71.31 (31.71.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:16:05.033724 2026] [security2:error] [pid 16472:tid 16472] [client 34.80.71.31:9236] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.brasscadillac.com"] [uri "/@fs/root/.env"] [unique_id "aqBC1aRghDUu4rzcqf9fXAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:16:49
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.71.31 (31.71.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.71.31 (31.71.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:16:45.786714 2026] [security2:error] [pid 21993:tid 21993] [client 34.80.71.31:57838] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.superlambauto.superlamb.com"] [uri "/@fs/src/.env"] [unique_id "aqA07bH2AA4L8m8g0q2ISwAAAG4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:00:27
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.71.31 (31.71.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.71.31 (31.71.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:00:21.588361 2026] [security2:error] [pid 3827435:tid 3827435] [client 34.80.71.31:14194] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.mindchill.net"] [uri "/@fs/app/.env"] [unique_id "aqAxFbX23JHiM97_IiMScAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack