๐ฉ๐ช
ut-addicted.com
2026-10-09 17:28:31
(12 hours ago)
\[Fri Oct 09 19:28:29.709992 2026\] \[:error\] \[pid 31638:tid 140352535099136\] \[client 159.65.123 ...
show more
\[Fri Oct 09 19:28:29.709992 2026\] \[:error\] \[pid 31638:tid 140352535099136\] \[client 159.65.123.254:41760\] \[client 159.65.123.254\] ModSecurity: Access denied with code 403 \(phase 2\). Operator GE matched 5 at TX:anomaly_score. \[file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-949-BLOCKING-EVALUATION.conf"\] \[line "57"\] \[id "949110"\] \[msg "Inbound Anomaly Score Exceeded \(Total Score: 5\)"\] \[severity "CRITICAL"\] \[tag "application-multi"\] \[tag "language-multi"\] \[tag "platform-multi"\] \[tag "attack-generic"\] \[hostname "www.ut-addicted.com"\] \[uri "/bank/.env"\] \[unique_id "askkPZgD8kAIhQPeq36pjgAAAEk"\]
show less
Brute-Force
Web App Attack
๐ง๐ช
cmbplf
2026-10-09 16:33:09
(13 hours ago)
446 requests with url.path *.aws/*
272 requests with url.path *.php.bak
133 requests with url.pat ...
show more
446 requests with url.path *.aws/*
272 requests with url.path *.php.bak
133 requests with url.path *config.php
122 requests with url.path *phpinfo.php
show less
Brute-Force
Bad Web Bot
๐ฟ๐ฆ
conure.sh
2026-10-09 16:17:13
(13 hours ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 0s
Web App Attack
๐ฉ๐ช
ut-addicted.com
2026-10-09 15:58:07
(13 hours ago)
\[Fri Oct 09 17:58:05.666120 2026\] \[:error\] \[pid 31638:tid 140352440690432\] \[client 159.65.123 ...
show more
\[Fri Oct 09 17:58:05.666120 2026\] \[:error\] \[pid 31638:tid 140352440690432\] \[client 159.65.123.254:36718\] \[client 159.65.123.254\] ModSecurity: Access denied with code 403 \(phase 2\). Operator GE matched 5 at TX:anomaly_score. \[file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-949-BLOCKING-EVALUATION.conf"\] \[line "57"\] \[id "949110"\] \[msg "Inbound Anomaly Score Exceeded \(Total Score: 5\)"\] \[severity "CRITICAL"\] \[tag "application-multi"\] \[tag "language-multi"\] \[tag "platform-multi"\] \[tag "attack-generic"\] \[hostname "www.crx.it"\] \[uri "/.env"\] \[unique_id "askPDZgD8kAIhQPeq36nlwAAAFI"\]
show less
Brute-Force
Web App Attack
๐บ๐ธ
ssssssssssssssssssssuper
2026-10-09 14:58:06
(14 hours ago)
159.65.123.254 - - [09/Oct/2026:10:58:05 -0400] "GET /.env HTTP/1.1" 404 15169 "-" "Mozilla/5.0 (Win ...
show more
159.65.123.254 - - [09/Oct/2026:10:58:05 -0400] "GET /.env HTTP/1.1" 404 15169 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
159.65.123.254 - - [09/Oct/2026:10:58:05 -0400] "GET /.env.backup HTTP/1.1" 404 15169 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
159.65.123.254 - - [09/Oct/2026:10:58:05 -0400] "GET /.aws/credentials HTTP/1.1" 404 15169 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
...
show less
Port Scan
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
ut-addicted.com
2026-10-09 14:36:55
(15 hours ago)
\[Fri Oct 09 16:36:53.864229 2026\] \[:error\] \[pid 31722:tid 140352430200576\] \[client 159.65.123 ...
show more
\[Fri Oct 09 16:36:53.864229 2026\] \[:error\] \[pid 31722:tid 140352430200576\] \[client 159.65.123.254:48378\] \[client 159.65.123.254\] ModSecurity: Access denied with code 403 \(phase 2\). Operator GE matched 5 at TX:anomaly_score. \[file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-949-BLOCKING-EVALUATION.conf"\] \[line "57"\] \[id "949110"\] \[msg "Inbound Anomaly Score Exceeded \(Total Score: 5\)"\] \[severity "CRITICAL"\] \[tag "application-multi"\] \[tag "language-multi"\] \[tag "platform-multi"\] \[tag "attack-generic"\] \[hostname "ut-addicted.com"\] \[uri "/%2eenv%2elive"\] \[unique_id "asj8BczmqIlsZ6TK87ziagAAANM"\]
show less
Brute-Force
Web App Attack
๐ง๐ช
voormedia
2026-10-09 08:08:57
(21 hours ago)
Accessed trap at '/.aws/credentials'
Web App Attack
๐ง๐ช
voormedia
2026-10-09 07:44:15
(22 hours ago)
Accessed trap at '/.aws/config'
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-10-09 05:01:53
(1 day ago)
Login credentials theft attempt
Hacking
๐ช๐ธ
librebit
2026-10-09 04:42:42
(1 day ago)
Brute force
Brute-Force
๐ฉ๐ช
ut-addicted.com
2026-10-09 04:28:35
(1 day ago)
\[Fri Oct 09 06:28:33.639063 2026\] \[:error\] \[pid 31638:tid 140352535099136\] \[client 159.65.123 ...
show more
\[Fri Oct 09 06:28:33.639063 2026\] \[:error\] \[pid 31638:tid 140352535099136\] \[client 159.65.123.254:39572\] \[client 159.65.123.254\] ModSecurity: Access denied with code 403 \(phase 2\). Operator GE matched 5 at TX:anomaly_score. \[file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-949-BLOCKING-EVALUATION.conf"\] \[line "57"\] \[id "949110"\] \[msg "Inbound Anomaly Score Exceeded \(Total Score: 8\)"\] \[severity "CRITICAL"\] \[tag "application-multi"\] \[tag "language-multi"\] \[tag "platform-multi"\] \[tag "attack-generic"\] \[hostname "78.46.187.162"\] \[uri "/.env.bak"\] \[unique_id "ashtcZgD8kAIhQPeq36WiQAAAEk"\]
show less
Brute-Force
Web App Attack
๐ง๐ช
voormedia
2026-10-09 03:16:55
(1 day ago)
Accessed trap at '/.env'
Web App Attack
๐บ๐ธ
ssssssssssssssssssssuper
2026-10-09 01:31:13
(1 day ago)
159.65.123.254 - - [08/Oct/2026:21:31:12 -0400] "GET /.env HTTP/1.1" 404 15169 "-" "Mozilla/5.0 (iPh ...
show more
159.65.123.254 - - [08/Oct/2026:21:31:12 -0400] "GET /.env HTTP/1.1" 404 15169 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.2 Mobile/15E148 Safari/605.1.15"
159.65.123.254 - - [08/Oct/2026:21:31:12 -0400] "GET /.env.backup HTTP/1.1" 404 15169 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0"
159.65.123.254 - - [08/Oct/2026:21:31:12 -0400] "GET /.env.bak HTTP/1.1" 404 15169 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
...
show less
Port Scan
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-10-09 01:19:11
(1 day ago)
159.65.123.254 - - [08/Oct/2026:20:18:11 -0500] "GET /.env.live HTTP/1.1" 403 199 "-" "Mozilla/5.0 ( ...
show more
159.65.123.254 - - [08/Oct/2026:20:18:11 -0500] "GET /.env.live HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 159.65.123.254
159.65.123.254 - - [08/Oct/2026:20:18:11 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:134.0) Gecko/20100101 Firefox/134.0" 159.65.123.254
159.65.123.254 - - [08/Oct/2026:20:18:11 -0500] "GET /.env.example HTTP/1.1" 403 199 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.2 Mobile/15E148 Safari/605.1.15" 159.65.123.254
159.65.123.254 - - [08/Oct/2026:20:18:11 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 159.65.123.254
159.65.123.254 - - [08/Oct/2026:20:18:11 -0500] "GET /.env.old HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebK
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ท
setupgr
2026-10-09 01:09:38
(1 day ago)
(mod_security) mod_security (id:9999001) triggered by 159.65.123.254 (DE/Germany/Hesse/Frankfurt am ...
show more
(mod_security) mod_security (id:9999001) triggered by 159.65.123.254 (DE/Germany/Hesse/Frankfurt am Main/-/[AS14061 DigitalOcean, LLC]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Fri Oct 09 04:09:34.177839 2026] [security2:error] [pid 438366:tid 438518] [client 159.65.123.254:32986] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^154\\\\.57\\\\.7\\\\.73$" at REQUEST_HEADERS:Host. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "155"] [id "9999001"] [msg "Direct incoming request to server shared IP blocked by admin"] [hostname "154.57.7.73"] [uri "/%00%2f%2eenv.old"] [unique_id "asg-zuyaMBNz-To3wdcodwAABFI"]
show less
Port Scan