๐ฎ๐ณ
evicky2002
2026-05-05 06:00:00
(4 months ago)
Confirmed malicious by STILWaters CTI platform (score=90, sources=1)
Hacking
Brute-Force
SSH
๐ฉ๐ช
big-cloud.nl
2026-05-04 11:31:22
(4 months ago)
Try to access /.env
Web App Attack
๐ซ๐ท
Nicos
2026-05-04 11:20:31
(4 months ago)
2026-05-04T13:20:30.608834+02:00 PhoenixNas d4dd180d7bc8[1538]: {"auth_via": "unauthenticated", "dom ...
show more
2026-05-04T13:20:30.608834+02:00 PhoenixNas d4dd180d7bc8[1538]: {"auth_via": "unauthenticated", "domain_url": "auth.wise0wl.org", "event": "/.git/HEAD", "host": "auth.wise0wl.org", "level": "info", "logger": "authentik.asgi", "method": "GET", "pid": 54349, "remote": "2a02:4780:75:9b69::1", "request_id": "6909258ea63d449c9d0e987e55f9cac0", "runtime": 65, "schema_name": "public", "scheme": "https", "status": 404, "timestamp": "2026-05-04T11:20:30.608551", "user": "", "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 15.7; rv:149.0) Gecko/20100101 Firefox/149.0"}
2026-05-04T13:20:30.624043+02:00 PhoenixNas d4dd180d7bc8[1538]: {"auth_via": "unauthenticated", "domain_url": "auth.wise0wl.org", "event": "/env", "host": "auth.wise0wl.org", "level": "info", "logger": "authentik.asgi", "method": "GET", "pid": 58942, "remote": "2a02:4780:75:9b69::1", "request_id": "c23e495022194ab0bdf46ca26891797f", "runtime": 63, "schema_name": "public", "scheme": "https", "status": 404, "timestamp": "2026-0
...
show less
Hacking
Brute-Force
๐ฉ๐ช
seal
2026-05-04 11:02:31
(4 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
SSH
Brute-Force
๐ฉ๐ช
0x44
2026-05-04 10:24:17
(4 months ago)
Abusive host detected * Attempt to access sensitive files
Web App Attack
Hacking
๐ฉ๐ช
wsyq
2026-05-04 10:05:32
(4 months ago)
Fail2Ban - \[NGINX\]40x-Forcing to access a restricted resource
...
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-05-04 09:00:46
(4 months ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-04 08:36:13
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:75:9b69::1 (srv1636999.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:75:9b69::1 (srv1636999.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 04 04:36:09.246793 2026] [security2:error] [pid 6617:tid 6617] [client 2a02:4780:75:9b69::1:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.rejuvenationcruises.com"] [uri "/.env.production"] [unique_id "afhaeSzrRXW8zrK2WSs54gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
enjoyably
2026-05-04 01:04:02
(4 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฉ๐ช
Gwyneth Llewelyn
2026-05-04 00:09:39
(4 months ago)
2026/05/04 01:09:38 [error] 2316#2316: *256489 access forbidden by rule, client: 2a02:4780:75:9b69:: ...
show more
2026/05/04 01:09:38 [error] 2316#2316: *256489 access forbidden by rule, client: 2a02:4780:75:9b69::1, server: lisboa.betatechnologies.info, request: "GET /.env HTTP/2.0", host: "lisboa.betatechnologies.info"
2a02:4780:75:9b69::1 - - [04/May/2026:01:09:38 +0100] "GET /.env HTTP/2.0" 403 1045 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 15_7_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/26.0 Safari/605.1.15"
2026/05/04 01:09:38 [error] 2314#2314: *256501 access forbidden by rule, client: 2a02:4780:75:9b69::1, server: lisboa.betatechnologies.info, request: "GET /backend/.env HTTP/2.0", host: "lisboa.betatechnologies.info"
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-05-03 22:01:26
(4 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-02.
show less
Web App Attack
SSH
Hacking
๐ฉ๐ช
BlueWire Hosting
2026-05-03 17:56:50
(4 months ago)
Probing websites for vulnerabilities
Web App Attack
SQL Injection
๐ฉ๐ช
webko.si
2026-05-03 14:54:43
(4 months ago)
JZKK: Bruteforce web app access, URI detail: '/.git/config'.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-03 12:03:27
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:75:9b69::1 (srv1636999.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:75:9b69::1 (srv1636999.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 03 08:03:22.469302 2026] [security2:error] [pid 25858:tid 25868] [client 2a02:4780:75:9b69::1:35360] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jrc3.com.randycameron.com"] [uri "/.git/HEAD"] [unique_id "afc5igspbUp8PIfmCCH56wAAAMc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-03 09:36:14
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:75:9b69::1 (srv1636999.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:75:9b69::1 (srv1636999.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 03 05:36:06.044631 2026] [security2:error] [pid 17835:tid 17835] [client 2a02:4780:75:9b69::1:36784] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hersbach.net"] [uri "/.git/HEAD"] [unique_id "afcXBm72_3JD7TsEyzHT7wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack