Log in to view charts and search reports for this IP.
Log In
Top Reporter Countries (Last 60 Days)
Example preview
Report Categories (Last 60 Days)
Example preview
Reports Activity
Example preview
Account required for the enhanced features
Log inSign up
IP Abuse Reports for 35.201.133.240:
This IP address has been reported a total of
61
times from
44 distinct
sources.
35.201.133.240 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
United States of America
with 16
reports;
Germany
with 11
reports;
Netherlands
with 7
reports.
The most common categories in these recent reports were:
Web App Attack
56
times;
Brute-Force
20
times;
Bad Web Bot
19
times;
Hacking
12
times;
SQL Injection
3
times;
Other
5
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Attempted access to sensitive endpoint (/.vscode/mcp.json) detected. Automated scan or unauthorized ...
show moreAttempted access to sensitive endpoint (/.vscode/mcp.json) detected. Automated scan or unauthorized probing.
show less
Repeated requests with invalid HTTP method or version, for example: 35.201.133.240 - - [08/Sep/2026: ...
show moreRepeated requests with invalid HTTP method or version, for example: 35.201.133.240 - - [08/Sep/2026:17:22:46 -0400] "-" 408 - 2 "-" "-" (HTTP, bogus vhost)
show less
Repeated requests for suspicious nonexistent URLs, for example: /backup.sql (HTTP/1.1 port 443, user ...
show moreRepeated requests for suspicious nonexistent URLs, for example: /backup.sql (HTTP/1.1 port 443, user agent: "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36")
show less
Automated report from CrowdSec: probing for exposed configuration and credential files. 5 events obs ...
show moreAutomated report from CrowdSec: probing for exposed configuration and credential files. 5 events observed.
show less
(modsec_5015) ModSec 5015: Suspicious User-Agent from 35.201.133.240 (TW/Taiwan/240.133.201.35.bc.go ...
show more(modsec_5015) ModSec 5015: Suspicious User-Agent from 35.201.133.240 (TW/Taiwan/240.133.201.35.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
[SunSep0605:17:54.4407972026][security2:error][pid2377578:tid2377674][client35.201.133.240:0]ModSecu ...
show more[SunSep0605:17:54.4407972026][security2:error][pid2377578:tid2377674][client35.201.133.240:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"dgtime.ch.136-243-54-122.cpanel.site\"][uri\"/.env.local\"][unique_id\"apzbYmKBHtL2qKwXYoQE4gAAAUA\"]
show less
CrowdSec local HTTP alert
scenario: crowdsecurity/http-sensitive-files
alert_id: 6426
events: 5
crea ...
show moreCrowdSec local HTTP alert
scenario: crowdsecurity/http-sensitive-files
alert_id: 6426
events: 5
created_at: 2026-09-06T00:02:45Z
message: Ip 35.201.133.240 performed 'crowdsecurity/http-sensitive-files' (5 events over 223.237258ms) at 2026-09-06 00:02:45.662970057 +0000 UTC
target_uri: ["/.env.save","/.env.dev","/.env.prod","/.env","/.env.local"]
method: ["GET"]
status: ["404"]
user_agent: ["crusader-worker/1.0"]
show less
(mod_security) mod_security triggered on hostname [redacted] 35.201.133.240 (TW/Taiwan/240.133.201.3 ...
show more(mod_security) mod_security triggered on hostname [redacted] 35.201.133.240 (TW/Taiwan/240.133.201.35.bc.googleusercontent.com): (CF_ENABLE)
show less