๐ฎ๐ณ
evicky2002
2026-05-13 07:18:32
(4 months ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฌ๐ง
openstrike.co.uk
2026-05-12 05:13:43
(4 months ago)
25 attacks on VC URLs, password grabbing URLs, config grabbing URLs (type 2), env grabbing URLs:
GET ...
show more
25 attacks on VC URLs, password grabbing URLs, config grabbing URLs (type 2), env grabbing URLs:
GET /.git/config HTTP/1.1
GET /.aws/credentials HTTP/1.1
GET /app-config.json HTTP/1.1
GET /app/.env HTTP/1.1
show less
Hacking
๐ณ๐ฑ
Savvii
2026-05-11 14:28:02
(4 months ago)
20 attempts against mh-misbehave-ban on frost
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-11 14:11:40
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 5.255.103.213 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 5.255.103.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 10:11:36.657761 2026] [security2:error] [pid 29761:tid 29761] [client 5.255.103.213:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sistememail.com"] [uri "/.env.test"] [unique_id "agHjmIfMf6IPEYkdclCsMwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-05-11 13:51:44
(4 months ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 5.255.103.213 (NL/Netherlands/-): 2 ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 5.255.103.213 (NL/Netherlands/-): 2 in the last 3600 secs
show less
Web App Attack
๐ฉ๐ช
yvoictra
2026-05-11 13:35:45
(4 months ago)
5.255.103.213 - - [11/May/2026:15:35:43 +0200] "GET /sitemap.xml HTTP/1.1" 404 186 "http://sirocovia ...
show more
5.255.103.213 - - [11/May/2026:15:35:43 +0200] "GET /sitemap.xml HTTP/1.1" 404 186 "http://sirocoviajes.com/sitemap.xml" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm) Chrome/116.0.0.0 Safari/537.36"
5.255.103.213 - - [11/May/2026:15:35:43 +0200] "GET /robots.txt HTTP/1.1" 404 153 "http://sirocoviajes.com/robots.txt" "DuckDuckBot/1.1; (+http://duckduckgo.com/duckduckbot.html)"
5.255.103.213 - - [11/May/2026:15:35:43 +0200] "GET /asset-manifest.json HTTP/1.1" 404 153 "http://sirocoviajes.com/asset-manifest.json" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
5.255.103.213 - - [11/May/2026:15:35:43 +0200] "GET /manifest.json HTTP/1.1" 404 153 "http://sirocoviajes.com/manifest.json" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/bot)"
5.255.103.213 - - [11/May/2026:15:35:43 +0200] "GET /build-manifest.json HTTP/1.1" 404 153 "http://sirocoviajes.co
...
show less
Brute-Force
Web App Attack
Anonymous
2026-05-11 13:30:21
(4 months ago)
Aggressive web scan
Web App Attack
๐ฎ๐ฉ
Burayot
2026-05-11 13:03:24
(4 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 5.255.103.213 (NL/Netherlands/-): 1 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 5.255.103.213 (NL/Netherlands/-): 1 in the last 3600 secs
show less
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-05-11 12:41:04
(4 months ago)
Bad bot ignoring robot.txt
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-11 12:28:42
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 5.255.103.213 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 5.255.103.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 08:28:35.948767 2026] [security2:error] [pid 29073:tid 29073] [client 5.255.103.213:33438] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sinobabel.com"] [uri "/.env.development"] [unique_id "agHLc4KSB0vxasCAorUhwQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-11 12:12:09
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 5.255.103.213 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 5.255.103.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 08:12:05.845671 2026] [security2:error] [pid 17346:tid 17346] [client 5.255.103.213:55190] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "singleslidestrategy.com"] [uri "/.env.staging"] [unique_id "agHHlY7pMTvYZhdma2HkHwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-05-11 11:00:50
(4 months ago)
Suspicious URL access.. Threat Score: 5.3/10 (MEDIUM). Confidence: 40%. CVSS v3.1: 2.9/10 (Low). CVS ...
show more
Suspicious URL access.. Threat Score: 5.3/10 (MEDIUM). Confidence: 40%. CVSS v3.1: 2.9/10 (Low). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N. Bayesian Probability: 57%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฆ๐บ
artful
2026-05-11 10:54:00
(4 months ago)
Excessive errors, high load and multiple hits per second
Web App Attack
๐ง๐ท
SOC PR
2026-05-11 10:35:19
(4 months ago)
IPS: Web Server Exposed Git Repository Information Disclosure.
Hacking
๐ฎ๐ฉ
sockominfo
2026-05-11 10:00:49
(4 months ago)
Suspicious URL access.. Threat Score: 5.4/10 (MEDIUM). Confidence: 40%. CVSS v3.1: 2.9/10 (Low). CVS ...
show more
Suspicious URL access.. Threat Score: 5.4/10 (MEDIUM). Confidence: 40%. CVSS v3.1: 2.9/10 (Low). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N. Bayesian Probability: 57%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack