Anonymous
2026-09-21 23:25:32
(4 hours ago)
"GET /core/.env HTTP/1.1"
Hacking
Web App Attack
๐ณ๐ฑ
oisecnet
2026-09-21 21:02:28
(6 hours ago)
Automated report: Unauthorized vulnerability scanning detected on 2026-09-21. 507 requests from this ...
show more
Automated report: Unauthorized vulnerability scanning detected on 2026-09-21. 507 requests from this IP.
show less
Port Scan
Hacking
Web App Attack
Anonymous
2026-09-21 19:14:18
(8 hours ago)
Sensitive Configuration File Disclosure.
Hacking
๐ฆ๐บ
paulshipley.com.au
2026-09-21 19:12:41
(8 hours ago)
[Tue Sep 22 05:12:39.825358 2026] [security2:error] [pid 148660] [client 35.185.30.66:54920] [client ...
show more
[Tue Sep 22 05:12:39.825358 2026] [security2:error] [pid 148660] [client 35.185.30.66:54920] [client 35.185.30.66] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "paulshipley.com.au"] [uri "/core/.env"] [unique_id "arGBpwB10dZViwL_xP6-GAAAABQ"]
...
show less
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-09-21 19:06:02
(8 hours ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,ice02,wa01,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ช
AutosOnShow
2026-09-21 19:05:06
(8 hours ago)
blocked for webapp attack | path requested: /.env | seen at 2026-09-21 19:04:24.386 |
Web App Attack
๐บ๐ธ
nationaleventpros.com
2026-09-21 19:02:15
(8 hours ago)
vulnerability scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:01:29
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.185.30.66 (66.30.185.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.30.66 (66.30.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:01:25.024780 2026] [security2:error] [pid 5673:tid 5673] [client 35.185.30.66:58564] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "midnight-tech.com"] [uri "/.env"] [unique_id "arF_BfMF6gfErARkWFOccAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
s@ch@
2026-09-21 19:00:02
(8 hours ago)
Jail: plesk-modsecurity | Web application attack (Plesk ModSecurity)
Web App Attack
๐ฉ๐ช
pltcldvlpr
2026-09-21 18:55:54
(8 hours ago)
CMS/framework probe: 35.185.30.66 - - [21/Sep/2026:20:55:53 +0200] "GET /.env HTTP/1.1" 301 178 "-" ...
show more
CMS/framework probe: 35.185.30.66 - - [21/Sep/2026:20:55:53 +0200] "GET /.env HTTP/1.1" 301 178 "-" "python-requests/2.34.2" asn=396982 org="Google LLC" country=US
...
show less
Web App Attack
Anonymous
2026-09-21 18:46:29
(9 hours ago)
[21/Sep/2026:18:46:29 +0000] host=lovelyrender.com server=_ ip=35.185.30.66 method=GET req=/core/.en ...
show more
[21/Sep/2026:18:46:29 +0000] host=lovelyrender.com server=_ ip=35.185.30.66 method=GET req=/core/.env uri=/core/.env status=301 bytes=162 rt=0.000 urt=- ref="-" ua="python-requests/2.34.2"
...
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
Lee Daniel
2026-09-21 18:36:44
(9 hours ago)
35.185.30.66 - - [21/Sep/2026:14:36:44 -0400] "GET /.env HTTP/1.1" 403 6284 "-" "python-requests/2.3 ...
show more
35.185.30.66 - - [21/Sep/2026:14:36:44 -0400] "GET /.env HTTP/1.1" 403 6284 "-" "python-requests/2.34.2"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 18:30:18
(9 hours ago)
35.185.30.66 - - [21/Sep/2026:18:30:18 +0000] "GET /core/.env HTTP/1.1" 302 491 "-" "python-requests ...
show more
35.185.30.66 - - [21/Sep/2026:18:30:18 +0000] "GET /core/.env HTTP/1.1" 302 491 "-" "python-requests/2.34.2"
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ฎ
paissangroup
2026-09-21 18:25:24
(9 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 18:20:34
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.185.30.66 (66.30.185.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.30.66 (66.30.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 14:20:26.980348 2026] [security2:error] [pid 24805:tid 24805] [client 35.185.30.66:58440] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kirbysmw.com"] [uri "/.env"] [unique_id "arF1aum1ebnBU-0hZGSopAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack