This IP address has been reported a total of
71
times from
48 distinct
sources.
35.252.85.119 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
(mod_security) mod_security (id:949110) triggered by 35.252.85.119 (US/United States/119.85.252.35.b ...
show more(mod_security) mod_security (id:949110) triggered by 35.252.85.119 (US/United States/119.85.252.35.bc.googleusercontent.com): N in the last X secs
show less
2026-08-30 14:38:25 GET /@fs/etc/passwd?raw?? [404] && 2026-08-30 14:38:25 GET /@fs/..%252f..%252f.. ...
show more2026-08-30 14:38:25 GET /@fs/etc/passwd?raw?? [404] && 2026-08-30 14:38:25 GET /@fs/..%252f..%252f..%252f..%252f..%252fapp/.env?raw?? [404] && 2026-08-30 14:38:25 GET /@fs/src/.env?raw?? [404] && 120 more within 20 minutes
show less
{"ClientAddr":"104.22.72.13:11432","ClientHost":"35.252.85.119","ClientPort":"11432","ClientUsername ...
show more{"ClientAddr":"104.22.72.13:11432","ClientHost":"35.252.85.119","ClientPort":"11432","ClientUsername":"-","DownstreamContentSize":0,"DownstreamStatus":403,"Duration":896580,"OriginContentSize":0,"OriginDuration":0,"OriginStatus":0,"Overhead":896580,"RequestAddr":"phpmyadmin.timvdberg.dev","RequestContentSize":0,"RequestCount":253920,"RequestHost":"phpmyadmin.timvdberg.dev","RequestMethod":"GET","RequestPath":"/","RequestPort":"-","RequestProtocol":"HTTP/2.0","RequestScheme":"https","RetryAttempts":0,"RouterName":"https-0-g781j1l22qyid4grmjq8a0lf-phpmyadmin@docker","StartLocal":"2026-08-30T11:23:24.14977002Z","StartUTC":"2026-08-30T11:23:24.14977002Z","TLSCipher":"TLS_AES_128_GCM_SHA256","TLSVersion":"1.3","entryPointName":"https","level":"info","msg":"","request_Cf-Connecting-Ip":"35.252.85.119","request_X-Forwarded-For":"35.252.85.119","request_X-Real-Ip":"104.22.72.13","time":"2026-08-30T11:23:24Z"}
{"ClientAddr":"108.162.246.95:11975","ClientHost":"35.252.85.119","ClientPort":"11975
...
show less
CrowdSec scenario: crowdsecurity/http-sensitive-files. Banned by Koru Cloud platform after multi-eve ...
show moreCrowdSec scenario: crowdsecurity/http-sensitive-files. Banned by Koru Cloud platform after multi-event detection. ASN: GOOGLE-CLOUD-PLATFORM. Country: US. Timestamp: 2026-08-30T06:26:02+00:00.
show less
BAD BOT - Detected and Blocked.. Matched phrase "claudebot" at REQUEST_HEADERS:User-Agent. (1100000- ...
show moreBAD BOT - Detected and Blocked.. Matched phrase "claudebot" at REQUEST_HEADERS:User-Agent. (1100000-135)
show less
{"level":"info","ts":1788068938.1837742,"logger":"http.log.access.log0","msg":"handled request","req ...
show more{"level":"info","ts":1788068938.1837742,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"35.252.85.119","remote_port":"13766","client_ip":"35.252.85.119","proto":"HTTP/1.1","method":"GET","host":"ynfs.status.updown.io","uri":"/","headers":{"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:132.0) Gecko/20100101 Firefox/132.0"],"Accept":["*/*"],"Accept-Encoding":["gzip"]}},"bytes_read":0,"user_id":"","duration":0.000085223,"size":0,"status":308,"resp_headers":{"Content-Type":[],"Server":["Caddy"],"Connection":["close"],"Location":["https://ynfs.status.updown.io/"]}}
{"level":"info","ts":1788068942.1198997,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"35.252.85.119","remote_port":"55182","client_ip":"35.252.85.119","proto":"HTTP/1.1","method":"GET","host":"ynfs.status.updown.io","uri":"/@fs/proc/self/environ?raw??","headers":{"Accept-Encoding":["gzip"],"User-Agent":["Mozilla/5.0 (iPhone; CPU iPhone OS 16_4 like Mac
...
show less
DDoS Attack
Web App Attack
Showing 1 to
15
of 71 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ