This IP address has been reported a total of
52
times from
32 distinct
sources.
89.116.35.97 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad ...
show moreFail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad bot behaviour. Technical log details and local server identifiers intentionally omitted for privacy.
show less
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show moreAuto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-06.
show less
[SunJun0719:12:42.7776512026][security2:error][pid4126658:tid4126695][client89.116.35.97:0]ModSecuri ...
show more[SunJun0719:12:42.7776512026][security2:error][pid4126658:tid4126695][client89.116.35.97:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\b\(\?:\\\\\\\\.\(\?:ht\(\?:access\|passwd\|group\)\|www_\?acl\)\|global\\\\\\\\.asa\|httpd\\\\\\\\.conf\|boot\\\\\\\\.ini\|web.config\)\\\\\\\\b\|\(\|\^\|\\\\\\\\.\\\\\\\\.\)/etc/\|/\\\\\\\\.\(\?:history\|bash_history\|sh_history\|env\)\$\)\"atREQUEST_FILENAME.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"204\"][id\"390709\"][rev\"30\"][msg\"Atomicorp.comWAFRules:Attempttoaccessprotectedfileremotely\"][data\"/.env\"][severity\"CRITICAL\"][hostname\"modularss.com\"][uri\"/dev/.env\"][unique_id\"aiWmigJa0by8-jdXoqa61gAAABA\"]
show less
Port Scan
Brute-Force
Web App Attack
Anonymous
(caddyscan) Scanner path probe from 89.116.35.97 (FR/France/-): 5 in the last 3600 secs; Ports: *; D ...
show more(caddyscan) Scanner path probe from 89.116.35.97 (FR/France/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 89.116.35.97 - - [07/Jun/2026:15:01:38 +0000] "GET /app/.env HTTP/1.1"
[REDACTED] 200 2627 89.116.35.97 - - [07/Jun/2026:15:01:38 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 89.116.35.97 - - [07/Jun/2026:15:01:38 +0000] "GET /dev/.env HTTP/1.1"
[REDACTED] 200 2627 89.116.35.97 - - [07/Jun/2026:15:01:38 +0000] "GET /backend/.env HTTP/1.1"
[REDACTED] 200 2627 89.116.35.97 - - [07/Jun/2026:15:01:38 +0000] "GET /member/.env HTTP/1.1"
show less
[SunJun0714:15:03.5461782026][security2:error][pid3061330:tid3062534][client89.116.35.97:0]ModSecuri ...
show more[SunJun0714:15:03.5461782026][security2:error][pid3061330:tid3062534][client89.116.35.97:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"364\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"buonviaggio.ch\"][uri\"/.env\"][unique_id\"aiVgxxftFAKqHG5oEywXMAAAAII\"]
show less