This IP address has been reported a total of
35
times from
31 distinct
sources.
34.102.52.168 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[TueSep0111:26:22.3407732026][security2:error][pid3975022:tid3975074][client34.102.52.168:0]ModSecur ...
show more[TueSep0111:26:22.3407732026][security2:error][pid3975022:tid3975074][client34.102.52.168:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Stringmatchwithin\".asa/.asax/.ascx/.backup/.bak/.bat/.cdx/.cer/.cfg/.cmd/.com/.config/.conf/.cs/.csproj/.csr/.dat/.db/.dbf/.dll/.dos/.htr/.htw/.ida/.idc/.idq/.inc/.ini/.key/.licx/.lnk/.log/.mdb/.old/.pass/.pdb/.pol/.printer/.pwd/.rdb/.resources/.resx/.sql/.swp/.sys/.vb/.vbs/.vbproj/.vsdisco/.webinfo/.xsx/\"atTX:extension.[file\"/etc/apache2/conf.d/modsec_rules/00_asl_zz_strict.conf\"][line\"91\"][id\"390716\"][rev\"2\"][msg\"Atomicorp.comWAFRules:URLfileextensionisrestrictedbypolicy\"][data\".backup\"][severity\"ERROR\"][hostname\"cmsolution.ch.136-243-54-122.cpanel.site\"][uri\"/.env.backup\"][unique_id\"apaaPijmenDWSqrSIgkXugAAAEw\"]
show less
[Tue Sep 01 03:26:28.310449 2026] [security2:error] [pid 825:tid 980] [client 34.102.52.168:33322] M ...
show more[Tue Sep 01 03:26:28.310449 2026] [security2:error] [pid 825:tid 980] [client 34.102.52.168:33322] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [ver "OWASP_CRS/4.15.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "yorknation.com"] [uri "/wp-config.php~"] [unique_id "apZ-JP-bTfvKvUzCbQGCHAAAAIs"]
...
show less
Web App Attack
Anonymous
Bot / scanning and/or hacking attempts: GET /.env.dev HTTP/1.1, GET /.env.bak HTTP/1.1, GET /.env.ex ...
show moreBot / scanning and/or hacking attempts: GET /.env.dev HTTP/1.1, GET /.env.bak HTTP/1.1, GET /.env.example HTTP/1.1, GET /env HTTP/1.1, GET /crusader-404-probe HTTP/1.1
show less