|
๐ฏ๐ต
VXG-NET
|
|
port=80, indicator_type=info-leak
|
Hacking
|
|
|
Anonymous
|
|
AndroxGh0st.Malware
|
Exploited Host
|
|
|
๐จ๐ญ
ViViV_
|
|
[Sentinel SOC] Incident Report (2026-02-28 12:25:58 UTC)
Malicious activity originating from this IP ...
show more
[Sentinel SOC] Incident Report (2026-02-28 12:25:58 UTC)
Malicious activity originating from this IP targeting our infrastructure (viviv.ovh).
Classification: EXPLOIT + RECON
Cumulative Score: 953 points
AbuseIPDB Score: 37% Confidence
Total Events: 16
Methods Used: GET (11), POST (5)
Honeypot Triggered: Yes (10 trapped events)
AI Threat Prob: 100.0%
Origin Info: ?? / Unknown
Top Targeted Paths (Evidence):
- /vendor/phpunit/phpunit/src/Util/PHP/eva... (6 hits)
- /.env (5 hits)
- / (5 hits)
Active Period:
First Seen: 2026-02-23 11:32:58 UTC
Last Seen: 2026-02-24 21:23:17 UTC
Autogen: Sentinel Watchtower SOC.
show less
|
Port Scan
Hacking
|
|
|
๐จ๐ญ
ViViV_
|
|
[Sentinel SOC] Incident Report (2026-02-25 03:07:43 UTC)
Malicious activity originating from this IP ...
show more
[Sentinel SOC] Incident Report (2026-02-25 03:07:43 UTC)
Malicious activity originating from this IP targeting our infrastructure (viviv.ovh).
Classification: EXPLOIT + RECON
Cumulative Score: 953 points
AbuseIPDB Score: 37% Confidence
Total Events: 16
Methods Used: GET (11), POST (5)
Honeypot Triggered: Yes (10 trapped events)
AI Threat Prob: 100.0%
Origin Info: ?? / Unknown
Top Targeted Paths (Evidence):
- /vendor/phpunit/phpunit/src/Util/PHP/eva... (6 hits)
- / (5 hits)
- /.env (5 hits)
Active Period:
First Seen: 2026-02-23 11:32:58 UTC
Last Seen: 2026-02-24 21:23:17 UTC
Autogen: Sentinel Watchtower SOC.
show less
|
Port Scan
Hacking
|
|
|
๐ฎ๐น
www.tana.it
|
|
PHP scan
|
Web App Attack
|
|
|
๐บ๐ฆ
URAN Publishing Service
|
|
192.159.99.51 - - [23/Feb/2026:15:46:18 +0200] "GET /.env HTTP/1.1" 404 340 "-" "Mozilla/5.0 (Linux; ...
show more
192.159.99.51 - - [23/Feb/2026:15:46:18 +0200] "GET /.env HTTP/1.1" 404 340 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30"
192.159.99.51 - - [23/Feb/2026:15:46:20 +0200] "GET /.env HTTP/1.1" 404 2953 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30"
...
show less
|
Web App Attack
|
|
|
๐ง๐ช
cmbplf
|
|
136 requests with url.path /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
|
Brute-Force
Bad Web Bot
|
|
|
๐ท๐บ
DZBOT
|
|
Website Scanning / Scraping
|
Bad Web Bot
Exploited Host
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 192.159.99.51 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 192.159.99.51 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 23 06:48:47.081535 2026] [security2:error] [pid 2103:tid 2103] [client 192.159.99.51:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blog.nyemdr.com"] [uri "/.env"] [unique_id "aZw-n3hgb5Ey8QhNK1du1wAAAAA"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ซ๐ท
Guardian
|
|
Multi abuses [2]: Unauthorized attempt to retrieve configuration file, Unauthorized connection attem ...
show more
Multi abuses [2]: Unauthorized attempt to retrieve configuration file, Unauthorized connection attempt / Port scanning
192.159.99.51 [23/Feb/2026:11:32:04] "GET /.env HTTP/1.1"
192.159.99.51 [23/Feb/2026:11:32:04] "POST / HTTP/1.1"
show less
|
Port Scan
Web App Attack
|
|
|
๐ณ๐ฑ
Jordy
|
|
23/Feb/2026:12:29:30.495294 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
23/Feb/2026:12:29:30.495294 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 192.159.99.51] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "autodiscover.familievandemaat.nl"] [uri "/.env"] [unique_id "aZw6Goc3KQVAl3tndLulAwAAAAY"]
23/Feb/2026:12:29:30.495294 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 192.159.99.51] ModSecurity: Warning. Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id
...
show less
|
Web App Attack
|
|
|
๐ณ๐ฑ
Linuxmalwarehuntingnl
|
|
Unauthorized connection attempt
|
Brute-Force
|
|
|
Anonymous
|
|
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
|
Brute-Force
SSH
|
|
|
๐ฌ๐ง
Mendip_Defender
|
|
192.159.99.51 - - [27/Mar/2024:07:28:18 +0000] "GET //wp-content/plugins/fix/up.php HTTP/1.0" 404 10 ...
show more
192.159.99.51 - - [27/Mar/2024:07:28:18 +0000] "GET //wp-content/plugins/fix/up.php HTTP/1.0" 404 1047 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36"
192.159.99.51 - - [27/Mar/2024:07:35:56 +0000] "GET //wp-content/plugins/fix/up.php HTTP/1.0" 404 1047 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36"
...
show less
|
Hacking
Web App Attack
|
|
|
๐ฉ๐ช
conseilgouz
|
|
ece-7 : Trying access unauthorized files/dir=>//wp-content/plugins/fix/up.php
|
Hacking
|
|