๐ซ๐ท
MeduzaCTI
2026-03-05 00:16:14
(6 months ago)
Indicator Report
Indicator: 192.159.99.83
Reporter: CloudStrife
Description: AsyncRAT Malware Found ...
show more
Indicator Report
Indicator: 192.159.99.83
Reporter: CloudStrife
Description: AsyncRAT Malware Found
Tags: AsyncRAT,Malware,C2
Source: MeduzaCTI Platform
Reference: https://meduzacti.com
show less
Hacking
๐ซ๐ท
Linux-Tech
2025-12-12 03:30:24
(9 months ago)
192.159.99.83 - - [12/Dec/2025:04:30:22 +0100] "GET /.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Linux; ...
show more
192.159.99.83 - - [12/Dec/2025:04:30:22 +0100] "GET /.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" 192.159.99.83 - - [12/Dec/2025:04:30:23 +0100] "GET /.env HTTP/1.1" 400 154 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30"
show less
Port Scan
Bad Web Bot
Web App Attack
๐ซ๐ท
Little Iguana
2025-12-12 03:28:36
(9 months ago)
Attempt to hack Wordpress Login, XMLRPC or other login
Hacking
๐ซ๐ฎ
nNordic
2025-12-12 00:44:53
(9 months ago)
Connection attempt blocked by IDS/IPS from IP 192.159.99.83/32
Hacking
๐ฌ๐ง
SilverZippo
2025-12-11 23:59:22
(9 months ago)
Web App Attack
Web App Attack
๐บ๐ธ
Major Hostility
2025-12-11 23:41:57
(9 months ago)
"GET /.env HTTP/1.1" 404
"GET /.env HTTP/1.1" 404
Web App Attack
๐จ๐ฑ
ifiguero
2025-12-11 22:09:46
(9 months ago)
Web Attack (\x00\x00\x00\x00\x00). 7d ban
Web App Attack
Anonymous
2025-12-11 18:33:23
(9 months ago)
192.159.99.83 - - [11/Dec/2025:18:33:22 +0000] "GET /.env HTTP/1.1" 404 397 "-" "Mozilla/5.0 (Linux; ...
show more
192.159.99.83 - - [11/Dec/2025:18:33:22 +0000] "GET /.env HTTP/1.1" 404 397 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
oh.mg
2025-12-11 14:40:58
(9 months ago)
[Thu Dec 11 15:40:57.613345 2025] [security2:error] [pid 1749562:tid 1749587] [client 192.159.99.83: ...
show more
[Thu Dec 11 15:40:57.613345 2025] [security2:error] [pid 1749562:tid 1749587] [client 192.159.99.83:52624] [client 192.159.99.83] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 8)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "95.216.72.247"] [uri "/.env"] [unique_id "aTrX-c5ONr0fWWTrHyaQJwAAABc"]
[Thu Dec 11 15:40:58.342028 2025] [security2:error] [pid 997425:tid 997458] [client 192.159.99.83:53682] [client 192.159.99.83] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 8)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "an
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
enpepet
2025-12-11 14:08:11
(9 months ago)
GENERAL: parametres: [url:env=] UA:Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT ...
show more
GENERAL: parametres: [url:env=] UA:Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30 URL:/.env
show less
Port Scan
Hacking
Brute-Force
Bad Web Bot
๐บ๐ธ
Cyber Crusader
2025-12-11 09:20:36
(9 months ago)
Hundreds of Attempts (at least) to Connect to and Access Firewall Ports
Port Scan
Hacking
Brute-Force
๐ฎ๐ช
RoboSOC
2025-12-10 14:54:05
(9 months ago)
SCAN: Host Sweep CloudCIX Reconnaissance Scan Detected, PTR: PTR record not found
Port Scan
Anonymous
2025-12-10 11:43:54
(9 months ago)
192.159.99.83 - - [10/Dec/2025:11:43:53 +0000] "GET /.env HTTP/1.1" 404 397 "-" "Mozilla/5.0 (Linux; ...
show more
192.159.99.83 - - [10/Dec/2025:11:43:53 +0000] "GET /.env HTTP/1.1" 404 397 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30"
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
ingroscart.it
2025-12-10 11:41:35
(9 months ago)
(apache-scanners) Failed apache-scanners trigger with match [redacted] from 192.159.99.83 (NL/The Ne ...
show more
(apache-scanners) Failed apache-scanners trigger with match [redacted] from 192.159.99.83 (NL/The Netherlands/-)
show less
Port Scan
๐ณ๐ฑ
f2b_bot
2025-12-10 11:09:14
(9 months ago)
Mass port scanning, brute-force attack
Port Scan
Brute-Force
Bad Web Bot