This IP address has been reported a total of
25
times from
21 distinct
sources.
34.92.138.104 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Automated Wazuh local observation. Wazuh rule 31151 lvl=10 detected repeated HTTP web application pr ...
show moreAutomated Wazuh local observation. Wazuh rule 31151 lvl=10 detected repeated HTTP web application probing from this source IP. Observed 1 matching blocked event(s) between 2026-09-19T00:00:10+02:00 and 2026-09-19T00:00:10+02:00. Sample requested paths: /.env.dev.
show less
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show moreAuto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-17.
show less
โ [18/09/26] This IP has been detected performing multiple attacks on websites (638 attempts blocked ...
show moreโ [18/09/26] This IP has been detected performing multiple attacks on websites (638 attempts blocked). Potential malicious activity.
show less
{"ClientAddr":"34.92.138.104:59838","ClientHost":"34.92.138.104","ClientPort":"59838","ClientUsernam ...
show more{"ClientAddr":"34.92.138.104:59838","ClientHost":"34.92.138.104","ClientPort":"59838","ClientUsername":"-","DownstreamContentSize":2401,"DownstreamStatus":404,"Duration":52341587,"OriginContentSize":2401,"OriginDuration":52224726,"OriginStatus":404,"Overhead":116861,"RequestAddr":"umami.vdkln.com","RequestContentSize":0,"RequestCount":543169,"RequestHost":"umami.vdkln.com","RequestMethod":"GET","RequestPath":"/.git/config","RequestPort":"-","RequestProtocol":"HTTP/1.1","RequestScheme":"https","RetryAttempts":0,"RouterName":"umami@docker","ServiceAddr":"172.18.0.40:3000","ServiceName":"umami@docker","ServiceURL":"http://172.18.0.40:3000","StartLocal":"2026-09-18T19:44:16.11340282Z","StartUTC":"2026-09-18T19:44:16.11340282Z","TLSCipher":"TLS_AES_128_GCM_SHA256","TLSVersion":"1.3","entryPointName":"websecure","level":"info","msg":"","time":"2026-09-18T19:44:16Z"}
{"ClientAddr":"34.92.138.104:59838","ClientHost":"34.92.138.104","ClientPort":"59838","ClientUsername":"-","DownstreamContentSi
...
show less
(mod_security) mod_security triggered on hostname [redacted] 34.92.138.104 (HK/Hong Kong/104.138.92. ...
show more(mod_security) mod_security triggered on hostname [redacted] 34.92.138.104 (HK/Hong Kong/104.138.92.34.bc.googleusercontent.com)
show less
SQL Injection
Anonymous
Bot / scanning and/or hacking attempts: GET /.env.old HTTP/1.1, GET /.env.dist HTTP/1.1, GET /.env.p ...
show moreBot / scanning and/or hacking attempts: GET /.env.old HTTP/1.1, GET /.env.dist HTTP/1.1, GET /.env.preprod HTTP/1.1, GET /.env.swp HTTP/1.1
show less