This IP address has been reported a total of
14
times from
12 distinct
sources.
35.194.228.217 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show moreAuto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-15.
show less
Scraped content or possible DDoS. Loaded pages and then loaded all resources referenced on the pages ...
show moreScraped content or possible DDoS. Loaded pages and then loaded all resources referenced on the pages. Used multiple hundreds of UserAgents across scraping.
show less
Aggressive web search of vulnerable pages: /app/backend/.env /dev/.env /api/v3/.env /src/api/.env /d ...
show moreAggressive web search of vulnerable pages: /app/backend/.env /dev/.env /api/v3/.env /src/api/.env /development/.env ...
show less
[MonJun1501:36:58.2980502026][security2:error][pid3364310:tid3364330][client35.194.228.217:0]ModSecu ...
show more[MonJun1501:36:58.2980502026][security2:error][pid3364310:tid3364330][client35.194.228.217:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"martinairsagl.ch.136-243-54-122.cpanel.site\"][uri\"/env.bak\"][unique_id\"ai87GstimeK0es7A4q7ZPwAAAFE\"]
show less