This IP address has been reported a total of
46
times from
33 distinct
sources.
195.35.44.252 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show moreAuto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-07.
show less
Web App Attack
SSH
Hacking
Anonymous
suspicious request in access.log
Web App Attack
Anonymous
(caddyscan) Scanner path probe from 195.35.44.252 (IN/India/-): 5 in the last 3600 secs; Ports: *; D ...
show more(caddyscan) Scanner path probe from 195.35.44.252 (IN/India/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 195.35.44.252 - - [08/Jun/2026:03:17:07 +0000] "GET /admin/.env HTTP/1.1"
[REDACTED] 200 2627 195.35.44.252 - - [08/Jun/2026:03:17:07 +0000] "GET /.env.save HTTP/1.1"
[REDACTED] 200 2627 195.35.44.252 - - [08/Jun/2026:03:17:07 +0000] "GET /dev/.env HTTP/1.1"
[REDACTED] 200 2627 195.35.44.252 - - [08/Jun/2026:03:17:07 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 195.35.44.252 - - [08/Jun/2026:03:17:07 +0000] "GET /backend/.env HTTP/1.1"
show less
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 127
Exploited Host
Web App Attack
Anonymous
Bot / scanning and/or hacking attempts: GET /.env.save HTTP/1.1, GET /core/.env HTTP/1.1, GET /backe ...
show moreBot / scanning and/or hacking attempts: GET /.env.save HTTP/1.1, GET /core/.env HTTP/1.1, GET /backend/.env HTTP/1.1, GET /dev/.env HTTP/1.1, GET /members/.env HTTP/1.1, GET /app/.env HTTP/1.1, GET /api/.env HTTP/1.1, GET /admin/.env HTTP/1.1, GET /.env HTTP/1.1, GET /core/.env.save HTTP/1.1, GET /laravel/.env HTTP/1.1, GET /api/.env.save HTTP/1.1
show less
Multiple HTTP calls attempting to GET resources using common/malformed API calls or formats on port ...
show moreMultiple HTTP calls attempting to GET resources using common/malformed API calls or formats on port 8080
show less
Web App Attack
Showing 1 to
15
of 46 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ