This IP address has been reported a total of
44
times from
36 distinct
sources.
35.229.128.68 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Netherlands
with 10
reports;
United States of America
with 8
reports;
Germany
with 5
reports.
The most common categories in these recent reports were:
Web App Attack
37
times;
Bad Web Bot
18
times;
Brute-Force
16
times;
Hacking
5
times;
Port Scan
2
times;
Other
4
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: TW, Attack patterns: Word ...
show moreBlocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: TW, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
(mod_security) mod_security (id:930120) triggered by 35.229.128.68 (TW/Taiwan/68.128.229.35.bc.googl ...
show more(mod_security) mod_security (id:930120) triggered by 35.229.128.68 (TW/Taiwan/68.128.229.35.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Bot / scanning and/or hacking attempts: GET /index.php?-d_allow_url_include%3Don_-d_auto_prepend_fil ...
show moreBot / scanning and/or hacking attempts: GET /index.php?-d_allow_url_include%3Don_-d_auto_prepend_file%3, [74/74] done: stream 147, GET /.aws/credentials, POST /index.php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_fi, GET /__/firebase/init.json HTTP/2.0, POST /cgi-bin/php-cgi?-d+allow_url_include%3don+-d+auto_prepend, POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e, POST /cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_, POST /php-cgi/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_, GET /.env.backup HTTP/2.0, POST /cgi-bin/php?-d+allow_url_include%3don+-d+auto_prepend_fil, GET /api/uploads/%2e%2e%2f%2e%2e%2f.env HTTP/2.0
show less
(mod_security) mod_security (id:210492) triggered by 35.229.128.68 (68.128.229.35.bc.googleuserconte ...
show more(mod_security) mod_security (id:210492) triggered by 35.229.128.68 (68.128.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 16:20:27.823397 2026] [security2:error] [pid 32597:tid 32597] [client 35.229.128.68:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "socialstudiesforkids.com"] [uri "/.//.env"] [unique_id "asapi9K7jtttKA0zo_vO7AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: TW, Attack patterns: Word ...
show moreBlocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: TW, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Aggressive web search of vulnerable pages: /css../.env /js../.env /static/.env /build../.env /dist.. ...
show moreAggressive web search of vulnerable pages: /css../.env /js../.env /static/.env /build../.env /dist../.env ...
show less