๐ฉ๐ช
razvangheorghies
2026-07-29 01:54:15
(5 hours ago)
Attack against a personal web server: HTTP scanning for common exploit paths (wp-login, .env, phpMyA ...
show more
Attack against a personal web server: HTTP scanning for common exploit paths (wp-login, .env, phpMyAdmin, etc.). Detected + blocked by fail2ban / nginx / firewall. Automated report.
show less
Web App Attack
Bad Web Bot
๐ฉ๐ช
razvangheorghies
2026-07-28 00:46:22
(1 day ago)
Attack against a personal web server: HTTP scanning for common exploit paths (wp-login, .env, phpMyA ...
show more
Attack against a personal web server: HTTP scanning for common exploit paths (wp-login, .env, phpMyAdmin, etc.). Detected + blocked by fail2ban / nginx / firewall. Automated report.
show less
Web App Attack
Bad Web Bot
๐ซ๐ท
mail.avx.gr
2026-07-27 15:40:29
(1 day ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: default:80 35.254.228.143 - - [25/Jul/2026:08:06: ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: default:80 35.254.228.143 - - [25/Jul/2026:08:06:39 +0300] "GET /.env HTTP/1.1" 403 407 "-" "internal-scan/1.0"
show less
Web App Attack
๐ฉ๐ช
razvangheorghies
2026-07-26 23:23:33
(2 days ago)
Attack against a personal web server: HTTP scanning for common exploit paths (wp-login, .env, phpMyA ...
show more
Attack against a personal web server: HTTP scanning for common exploit paths (wp-login, .env, phpMyAdmin, etc.). Detected + blocked by fail2ban / nginx / firewall. Automated report.
show less
Web App Attack
Bad Web Bot
๐ฎ๐ณ
evicky2002
2026-07-26 06:00:00
(3 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฌ๐ง
openstrike.co.uk
2026-07-26 05:14:14
(3 days ago)
3 attacks on env grabbing URLs:
GET /.env HTTP/1.1
Hacking
๐ซ๐ท
service Informatique
2026-07-26 04:00:37
(3 days ago)
GET /.env
Web App Attack
๐ฎ๐น
[email protected]
2026-07-25 22:32:31
(3 days ago)
35.254.228.143 - - [25/Jul/2026:08:42:09 +0200] "GET /.env HTTP/1.1" 404 6488 "-" "internal-scan/1.0 ...
show more
35.254.228.143 - - [25/Jul/2026:08:42:09 +0200] "GET /.env HTTP/1.1" 404 6488 "-" "internal-scan/1.0"
show less
Web App Attack
Hacking
๐ฎ๐ฉ
sockominfo
2026-07-25 08:00:55
(3 days ago)
Access to sensitive files detected w/ specific boundary.. Threat Score: 4.9/10 (MEDIUM). Confidence: ...
show more
Access to sensitive files detected w/ specific boundary.. Threat Score: 4.9/10 (MEDIUM). Confidence: 40%. CVSS v3.1: 2.9/10 (Low). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N. Bayesian Probability: 40%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Moderate. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐บ๐ธ
kosada.com
2026-07-25 07:04:40
(4 days ago)
Web vulnerability probing: /.env (bogus vhost/SNI)
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-07-25 07:00:53
(4 days ago)
Access to sensitive files detected w/ specific boundary.. Threat Score: 5/10 (MEDIUM). Confidence: 4 ...
show more
Access to sensitive files detected w/ specific boundary.. Threat Score: 5/10 (MEDIUM). Confidence: 40%. CVSS v3.1: 2.9/10 (Low). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N. Bayesian Probability: 40%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐บ๐ธ
BSG Webmaster
2026-07-25 07:00:08
(4 days ago)
Port scanning (Port 443)
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-25 06:59:49
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.254.228.143 (143.228.254.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.254.228.143 (143.228.254.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 02:59:45.758505 2026] [security2:error] [pid 935972:tid 935972] [client 35.254.228.143:38190] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.58"] [uri "/.env"] [unique_id "amRe4fP6ANtPrOV39Y7XHQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
brantknudson.org
2026-07-25 06:58:43
(4 days ago)
Request path 'GET /.env HTTP/1.1'
Web App Attack
Hacking
๐ณ๐ฑ
wlt-blocker
2026-07-25 06:39:31
(4 days ago)
Unauthorized access to webpage admin
Web App Attack