🇫🇷
Catalin Negru
2026-09-06 06:28:28
(9 hours ago)
2026-09-06 09:28:27,167 fail2ban.actions [1796604]: NOTICE [laravel-env] Ban 35.199.102.113
...
show more
2026-09-06 09:28:27,167 fail2ban.actions [1796604]: NOTICE [laravel-env] Ban 35.199.102.113
2026-09-06 09:28:27,201 fail2ban.actions [1796604]: NOTICE [apache-dirscan] Ban 35.199.102.113
2026-09-06 09:28:27,260 fail2ban.actions [1796604]: NOTICE [web-scanner] Ban 35.199.102.113
2026-09-06 09:28:27,293 fail2ban.actions [1796604]: NOTICE [apache-404] Ban 35.199.102.113
2026-09-06 09:28:27,365 fail2ban.actions [1796604]: NOTICE [laravel-auth] Ban 35.199.102.113
...
show less
Brute-Force
Web App Attack
🇳🇱
Cloud86 B.V.
2026-09-06 03:27:01
(12 hours ago)
categories: DDoS Attack
DDoS Attack
🇺🇸
TPI-Abuse
2026-09-06 03:01:14
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.102.113 (113.102.199.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.102.113 (113.102.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:01:07.387200 2026] [security2:error] [pid 5244:tid 5244] [client 35.199.102.113:59288] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.allisonstiles.org"] [uri "/.env"] [unique_id "apzXc9t5UTGLoPZNH-m0eQAAADk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ghostwarriors
2026-09-06 02:50:11
(12 hours ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 02:45:48
(12 hours ago)
[server.tmg.gr] httpd-config-scan: sites=www.aegeanpvdforum.com; logs=/var/log/httpd/domains/aegeanp ...
show more
[server.tmg.gr] httpd-config-scan: sites=www.aegeanpvdforum.com; logs=/var/log/httpd/domains/aegeanpvdforum.com.log; samples=/.env.old | /wp-config.php.bak | /.env.prod
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:28:04
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.102.113 (113.102.199.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.102.113 (113.102.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:28:00.042500 2026] [security2:error] [pid 11934:tid 11946] [client 35.199.102.113:50410] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "skillcert.org"] [uri "/.env.example"] [unique_id "apzPsCkz-efFYVN710Pa3AAAAIo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-06 02:27:59
(13 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.199.102.113 (BR/Brazil/113.102.199 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.199.102.113 (BR/Brazil/113.102.199.35.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
🇩🇪
Enno
2026-09-06 02:19:49
(13 hours ago)
P23::Fail2Ban: automated bot scanning / credential probing detected.
Web App Attack
Bad Web Bot
🇺🇸
Gabriel Camargo
2026-09-06 01:51:23
(13 hours ago)
35.199.102.113 - - [05/Sep/2026:20:51:23 -0500] "GET /.env HTTP/1.1" 301 178 "-" "crusader-worker/1. ...
show more
35.199.102.113 - - [05/Sep/2026:20:51:23 -0500] "GET /.env HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
35.199.102.113 - - [05/Sep/2026:20:51:23 -0500] "GET /.env.prod HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
35.199.102.113 - - [05/Sep/2026:20:51:23 -0500] "GET /.env.production HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
...
show less
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-06 01:32:12
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.102.113 (113.102.199.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.102.113 (113.102.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:32:06.876067 2026] [security2:error] [pid 23075:tid 23075] [client 35.199.102.113:47944] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mrconway.com"] [uri "/.env.dev"] [unique_id "apzCluvgS2x8XRAYFx8GKgAAAFE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇷
setupgr
2026-09-06 01:15:06
(14 hours ago)
(mod_security) mod_security (id:11000011) triggered by 35.199.102.113 (BR/Brazil/São Paulo/São Pau ...
show more
(mod_security) mod_security (id:11000011) triggered by 35.199.102.113 (BR/Brazil/São Paulo/São Paulo/-/[AS396982 Google LLC]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Sun Sep 06 04:15:03.716498 2026] [security2:error] [pid 3133:tid 3268] [client 35.199.102.113:57992] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "googleusercontent.com" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: 113.102.199.35.bc.googleusercontent.com"] [severity "CRITICAL"] [hostname "mail.adoro.gr"] [uri "/.env.backup"] [unique_id "apy-l1J2j4XvP9HFAd15OgAAA8g"]
show less
Port Scan
🇺🇸
TPI-Abuse
2026-09-06 01:14:46
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.102.113 (113.102.199.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.102.113 (113.102.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:14:40.356041 2026] [security2:error] [pid 6218:tid 6218] [client 35.199.102.113:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "luisgtechgroup.com"] [uri "/.env.production"] [unique_id "apy-gMsVVK6jZZVKI8c11wAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:48:55
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.102.113 (113.102.199.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.102.113 (113.102.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:48:50.393882 2026] [security2:error] [pid 10649:tid 10649] [client 35.199.102.113:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.grainavi.com"] [uri "/.env.old"] [unique_id "apy4chN4g7PrCx3xSu5UMAAAAG0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
SCHAPPY
2026-09-06 00:31:39
(15 hours ago)
Malicious activity from IP detected: crowdsecurity/http-sensitive-files.
Web App Attack
Hacking
🇬🇧
consul.to
2026-09-06 00:28:42
(15 hours ago)
Web attack/malicious scanning detected
Web App Attack