This IP address has been reported a total of
50
times from
30 distinct
sources.
157.173.208.242 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
(caddyscan) Scanner path probe from 157.173.208.242 (US/United States/-): 5 in the last 3600 secs; P ...
show more(caddyscan) Scanner path probe from 157.173.208.242 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 157.173.208.242 - - [24/Jun/2026:05:36:52 +0000] "GET /admin/.env HTTP/1.1"
[REDACTED] 200 2627 157.173.208.242 - - [24/Jun/2026:05:36:52 +0000] "GET /dev/.env HTTP/1.1"
[REDACTED] 200 2627 157.173.208.242 - - [24/Jun/2026:05:36:52 +0000] "GET /core/.env.save HTTP/1.1"
[REDACTED] 200 2627 157.173.208.242 - - [24/Jun/2026:05:36:52 +0000] "GET /members/.env HTTP/1.1"
[REDACTED] 200 2627 157.173.208.242 - - [24/Jun/2026:05:36:52 +0000] "GET /core/.env HTTP/1.1"
show less
[WedJun2405:38:07.8742192026][security2:error][pid3880600:tid3880649][client157.173.208.242:0]ModSec ...
show more[WedJun2405:38:07.8742192026][security2:error][pid3880600:tid3880649][client157.173.208.242:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\b\(\?:\\\\\\\\.\(\?:ht\(\?:access\|passwd\|group\)\|www_\?acl\)\|global\\\\\\\\.asa\|httpd\\\\\\\\.conf\|boot\\\\\\\\.ini\|web.config\)\\\\\\\\b\|\(\|\^\|\\\\\\\\.\\\\\\\\.\)/etc/\|/\\\\\\\\.\(\?:history\|bash_history\|sh_history\|env\)\$\)\"atREQUEST_FILENAME.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"204\"][id\"390709\"][rev\"30\"][msg\"Atomicorp.comWAFRules:Attempttoaccessprotectedfileremotely\"][data\"/.env\"][severity\"CRITICAL\"][hostname\"traslocarealugano.ch\"][uri\"/app/.env\"][unique_id\"ajtRHwZMqpkibXRvaaKq9QAAAEo\"]
show less
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad ...
show moreFail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad bot behaviour. Technical log details and local server identifiers intentionally omitted for privacy.
show less
Aggressive web search of vulnerable pages: /dev/.env /backend/.env /core/.env /.env /members/.env . ...
show moreAggressive web search of vulnerable pages: /dev/.env /backend/.env /core/.env /.env /members/.env ...
show less
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show moreAuto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-07.
show less