This IP address has been reported a total of
18
times from
15 distinct
sources.
35.203.99.136 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Brazil
with 10
reports;
France
with 3
reports;
United States of America
with 3
reports.
The most common categories in these recent reports were:
Web App Attack
11
times;
Brute-Force
6
times;
Bad Web Bot
6
times;
Hacking
4
times;
Exploited Host
2
times;
Other
5
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Triggered Cloudflare WAF (firewallManaged) from CA.
Action taken: BLOCK
Protocol: HTTP/2 (POST metho ...
show moreTriggered Cloudflare WAF (firewallManaged) from CA.
Action taken: BLOCK
Protocol: HTTP/2 (POST method)
Endpoint: /admin
UA: Mozilla/5.0 (compatible; Bytespider; [email protected]) AppleWebKit/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Fail2Ban: request for a known-malicious path (.env, .git, wp-login, actuator, ...) on a public web s ...
show moreFail2Ban: request for a known-malicious path (.env, .git, wp-login, actuator, ...) on a public web server; honeypot hit, banned on first attempt.
show less
Triggered Cloudflare WAF (firewallManaged) from CA.
Action taken: BLOCK
Protocol: HTTP/2 (POST metho ...
show moreTriggered Cloudflare WAF (firewallManaged) from CA.
Action taken: BLOCK
Protocol: HTTP/2 (POST method)
Endpoint: /dashboard
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected])
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
{"level":"info","ts":1790936120.0211515,"logger":"http.log.access.log1","msg":"handled request","req ...
show more{"level":"info","ts":1790936120.0211515,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"35.203.99.136","remote_port":"55922","client_ip":"35.203.99.136","proto":"HTTP/2.0","method":"GET","host":"status.kwara.com.br","uri":"/webpack-stats.json","headers":{"Sec-Fetch-Site":["none"],"Sec-Ch-Ua-Mobile":["?0"],"Accept":["text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8"],"X-Nextjs-Data":["1"],"Sec-Ch-Ua-Platform":["\"macOS\""],"Sec-Ch-Ua":["\"Chromium\";v=\"153\", \"Brave\";v=\"153\", \"Not_A Brand\";v=\"8\""],"Sec-Fetch-Dest":["document"],"Sec-Fetch-Mode":["navigate"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"Sec-Fetch-User":["?1"],"Upgrade-Insecure-Requests":["1"],"User-Agent":["Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153
...
show less
Web vulnerability scanning: requests to known exploit/probe paths; requests blocked by WAF (ModSecur ...
show moreWeb vulnerability scanning: requests to known exploit/probe paths; requests blocked by WAF (ModSecurity) rules. Blocked by firewall on 7 different hosting servers. Protocol TCP, port 80, 443 (HTTP/HTTPS). Requested paths: /wp-json, /_profiler/latest, /firebase-service-account.json, /graphql, /info.php. Automated report.
show less
[Honeypot] Malicious activity detected by honeypot on port 80. IP attempted unauthorized access to d ...
show more[Honeypot] Malicious activity detected by honeypot on port 80. IP attempted unauthorized access to decoy service. Original message: Web honeypot: 464 malicious requests. Attack types: file_inclusion, admin_scan, vulnerability_scan, generic_scan, wordpress_scan. Sample: GET / HTTP/2.0. Attempted credentials captured.
show less