Log in to view charts and search reports for this IP.
Log In
Top Reporter Countries (Last 60 Days)
Example preview
Report Categories (Last 60 Days)
Example preview
Reports Activity
Example preview
Account required for the enhanced features
Log inSign up
IP Abuse Reports for 34.81.36.30:
This IP address has been reported a total of
28
times from
25 distinct
sources.
34.81.36.30 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Netherlands
with 6
reports;
United States of America
with 6
reports;
Germany
with 4
reports.
The most common categories in these recent reports were:
Web App Attack
19
times;
Bad Web Bot
9
times;
Brute-Force
8
times;
SQL Injection
4
times;
Hacking
4
times;
Other
6
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
Anonymous
Portscan: TCP/8443 (6x), TCP/8080 (6x)
Port Scan
Anonymous
Web probing (201 hits in 24h) on crm.1valkenburg.nl,default-vhost: sensitive-path scans and/or 404 b ...
show moreWeb probing (201 hits in 24h) on crm.1valkenburg.nl,default-vhost: sensitive-path scans and/or 404 bursts. Reported by CRMON.
show less
Scanning for .env files [GET /api/fs/read?path=/app/.env&allowOutsideWorkspace=true] [Mozilla/5.0 (X ...
show moreScanning for .env files [GET /api/fs/read?path=/app/.env&allowOutsideWorkspace=true] [Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36]
show less
ET EXPLOIT Apache HTTP Server 2.4.49 - Path Traversal Attempt (CVE-2021-41773) M2
ET EXPLOIT Grafa ...
show moreET EXPLOIT Apache HTTP Server 2.4.49 - Path Traversal Attempt (CVE-2021-41773) M2
ET EXPLOIT Grafana 8.x Path Traversal (CVE-2021-43798)
ET EXPLOIT Local File Inclusion with Shell Execution via proc/self/environ
ET EXPLOIT VMware Spring Cloud Directory Traversal (CVE-2020-5410)
ET INFO Request to Hidden Environment File - Inbound
ET WEB_SERVER Likely Malicious Request for /proc/self/environ
ET WEB_SERVER Next.js Middleware Authorization Bypass (CVE-2025-29927)
ET WEB_SPECIFIC_APPS Vite Arbitrary File Read Via raw parameter (CVE-2025-30208)
ET WEB_SPECIFIC_APPS Vite Unauthenticated Arbitrary File Read (CVE-2025-31486)
GPL WEB_SERVER 403 Forbidden
show less
34.81.36.30 - - [06/Sep/2026:09:18:10 +0000] "GET /rclone.conf HTTP/1.1" 404 3431 "-" "Mozilla/5.0 ( ...
show more34.81.36.30 - - [06/Sep/2026:09:18:10 +0000] "GET /rclone.conf HTTP/1.1" 404 3431 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36" "-"
34.81.36.30 - - [06/Sep/2026:09:18:11 +0000] "GET /.git/config HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36" "-"
34.81.36.30 - - [06/Sep/2026:09:18:11 +0000] "GET /z9x8c7v6b5-debug-trigger-www.solentyachtcharter.com HTTP/1.1" 404 3431 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36" "-"
34.81.36.30 - - [06/Sep/2026:09:18:11 +0000] "GET /.aws/config HTTP/1.1" 404 3431 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36" "-"
34.81.36.30 - - [06/Sep/2026:09:18:11 +0000] "GET /.aws/credentials HTTP/1.1" 404 3431 "-" "Mozilla/5.0 (Macintosh; Intel
...
show less
Web App Attack
Anonymous
(mod_security) mod_security triggered on hostname [redacted] 34.81.36.30 (TW/Taiwan/30.36.81.34.bc.g ...
show more(mod_security) mod_security triggered on hostname [redacted] 34.81.36.30 (TW/Taiwan/30.36.81.34.bc.googleusercontent.com)
show less
Aggressive web search of vulnerable pages: /.env /.env.example /.env.production /.env.bak /.env.back ...
show moreAggressive web search of vulnerable pages: /.env /.env.example /.env.production /.env.bak /.env.backup /api/.env /.env.local /.env.old /backend ...
show less
HTTP application-layer DoS / botnet traffic from 34.81.36.30: repeated high-cost dynamic page and fe ...
show moreHTTP application-layer DoS / botnet traffic from 34.81.36.30: repeated high-cost dynamic page and feed requests (profile/tag views, forums, tracker, RSS) at abusive rates via completed TCP/HTTPS. Likely compromised end-user host.
show less