This IP address has been reported a total of
21
times from
19 distinct
sources.
34.89.152.29 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Germany
with 5
reports;
United States of America
with 3
reports;
United Kingdom of Great Britain and Northern Ireland
with 2
reports.
The most common categories in these recent reports were:
Web App Attack
18
times;
Bad Web Bot
6
times;
Brute-Force
6
times;
Hacking
3
times;
Port Scan
3
times;
Other
6
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
(mod_security) mod_security triggered on hostname [redacted] 34.89.152.29 (DE/Germany/29.152.89.34.b ...
show more(mod_security) mod_security triggered on hostname [redacted] 34.89.152.29 (DE/Germany/29.152.89.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
Anonymous
(wordpress) Failed login wp-login.php or xmlrpc.php
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show moreAuto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-30.
show less
01-10-2026:15:17:36UTC [Nginx Web Server] Suspicious web request: path:/.env path:/.git (14 request( ...
show more01-10-2026:15:17:36UTC [Nginx Web Server] Suspicious web request: path:/.env path:/.git (14 request(s)).
show less
Bad Web Bot
Web App Attack
Anonymous
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.89.152.29 (29.152.89.34.bc.googleusercont ...
show more(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.89.152.29 (29.152.89.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.89.152.29 - - [01/Oct/2026:14:24:28 +0200] "GET /pathscan-f181f154a94b-nope.env HTTP/1.1" 406 463 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
34.89.152.29 - - [01/Oct/2026:14:24:29 +0200] "GET /.env.dev HTTP/1.1" 406 4816 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
34.89.152.29 - - [01/Oct/2026:14:24:29 +0200] "GET /.env.bak HTTP/1.1" 406 4816 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
show less
[ThuOct0107:32:10.0743092026][security2:error][pid3309654:tid3309710][client34.89.152.29:0]ModSecuri ...
show more[ThuOct0107:32:10.0743092026][security2:error][pid3309654:tid3309710][client34.89.152.29:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"710\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"piffarerio.ch\"][uri\"/pathscan-7484b43b5c62-nope.env\"][unique_id\"ar3wWuAMfAAEg4_kk8_NzQAAAE0\"]
show less