This IP address has been reported a total of
52
times from
41 distinct
sources.
34.138.52.125 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show moreAuto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-28.
show less
(mod_security) mod_security (id:949110) triggered by 34.138.52.125 (US/United States/125.52.138.34.b ...
show more(mod_security) mod_security (id:949110) triggered by 34.138.52.125 (US/United States/125.52.138.34.bc.googleusercontent.com): 5 in the last 3600 secs [SIGMA]
show less
[FriAug2816:14:32.0016012026][security2:error][pid2743786:tid2743916][client34.138.52.125:0]ModSecur ...
show more[FriAug2816:14:32.0016012026][security2:error][pid2743786:tid2743916][client34.138.52.125:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"domoticaswiss.ch.136-243-54-122.cpanel.site\"][uri\"/.env.old\"][unique_id\"apGXyGou6fcUojgyUf1e_QAAANg\"]
show less
ModSecurity OWASP CRS (Anomaly Score: 10): Attempt to access a backup or working file;Restricted Fil ...
show moreModSecurity OWASP CRS (Anomaly Score: 10): Attempt to access a backup or working file;Restricted File Access Attempt;URL file extension is restricted by policy;
show less