This IP address has been reported a total of
39
times from
32 distinct
sources.
35.252.119.129 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show moreAuto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-26.
show less
[WedAug2620:10:42.9953582026][security2:error][pid1426573:tid1426617][client35.252.119.129:0]ModSecu ...
show more[WedAug2620:10:42.9953582026][security2:error][pid1426573:tid1426617][client35.252.119.129:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"labaita-lanzo.it\"][uri\"/@fs/../.env\"][unique_id\"ao8sIkoezOOKVAq4dFC0ggAAARQ\"]
show less
Bot / scanning and/or hacking attempts: GET /firebase-adminsdk.json HTTP/1.1, GET /credentials HTTP/ ...
show moreBot / scanning and/or hacking attempts: GET /firebase-adminsdk.json HTTP/1.1, GET /credentials HTTP/1.1, GET /.aws/ecs-task-credentials HTTP/1.1, GET /fetch?url=http%3A%2F%2F169.254.169.254%2Fmetadata%2Fidenti, GET /.continue/config.json HTTP/1.1, GET /.openai/config.json HTTP/1.1, GET /..;/..;/.aws/credentials HTTP/1.1, GET /google-credentials.json HTTP/1.1, GET /proxy?url=file%3A%2F%2F%2Froot%2F.env HTTP/1.1, GET /vendor/aws/credentials HTTP/1.1, GET /.aws/ecs-task-credentials.json HTTP/1.1, GET /public/env.js HTTP/1.1, GET /config/credentials.json HTTP/1.1, GET /read?url=file:///proc/1/environ HTTP/1.1, GET /actuator/logfile HTTP/1.1, GET /api/v1/credentials HTTP/1.1, GET /credentials.json HTTP/1.1, GET /.env.development.local HTTP/1.1, GET /?file=../../.env HTTP/1.1
show less
Hacking
Web App Attack
Anonymous
Bot / seems abusive / Apache connections: 107
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
Anonymous
suspicious request in access.log
Web App Attack
Showing 1 to
15
of 39 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ