๐ฎ๐ณ
evicky2002
2026-05-13 07:18:32
(4 months ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ญ๐บ
DumaNet
2026-05-13 01:54:00
(4 months ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 May 12. 12:53:45
Source IP: 5.255. ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 May 12. 12:53:45
Source IP: 5.255.121.14
Portion of the log(s):
5.255.121.14 - [12/May/2026:12:53:44 +0200] "GET /.env HTTP/1.1" 404 153 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.6 Safari/605.1.15"
5.255.121.14 - [12/May/2026:12:53:44 +0200] "GET /.env.example HTTP/1.1" 404 153 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:133.0) Gecko/20100101 Firefox/133.0"
5.255.121.14 - [12/May/2026:12:53:44 +0200] "GET /.env.production HTTP/1.1" 404 153 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1 Safari/605.1.15"
5.255.121.14 - [12/May/2026:12:53:44 +0200] "GET /.env.staging HTTP/1.1" 404 555 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
5.255.121.14 - [12/May/2026:12:53:44 +0200] "GET /.env.test HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64
show less
Web App Attack
๐บ๐ธ
mnsf
2026-05-12 13:05:35
(4 months ago)
Too many Status 40X (19)
Brute-Force
Web App Attack
๐ฉ๐ช
maxpower
2026-05-12 12:38:00
(4 months ago)
(junkbot) REGOLA 7 - Junk Bot Blocked 5.255.121.14 (NL/Netherlands/-): 1 in the last 3600 secs; Port ...
show more
(junkbot) REGOLA 7 - Junk Bot Blocked 5.255.121.14 (NL/Netherlands/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 5.255.121.14 - - [12/May/2026:14:37:55 +0200] "GET /_next/build-manifest.json HTTP/1.1" 200 11828 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)" "-" host=matteoappignani.business
show less
Port Scan
๐บ๐ธ
lavnet.net
2026-05-12 11:37:34
(4 months ago)
5.255.121.14 - - [12/May/2026:11:37:33 +0000] "GET /sitemap.xml HTTP/1.1" 404 354 "-" "Mozilla/5.0 ( ...
show more
5.255.121.14 - - [12/May/2026:11:37:33 +0000] "GET /sitemap.xml HTTP/1.1" 404 354 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
5.255.121.14 - - [12/May/2026:11:37:33 +0000] "GET /robots.txt HTTP/1.1" 404 354 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)"
5.255.121.14 - - [12/May/2026:11:37:33 +0000] "GET /asset-manifest.json HTTP/1.1" 404 354 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
...
show less
Web App Attack
๐ฉ๐ช
Starburst SysOp Team
2026-05-12 11:34:32
(4 months ago)
Malware host (X-Forwarded-For) detected by rbl.malware.expert. RBL lookup of 14.121.255.5.rbl.malwar ...
show more
Malware host (X-Forwarded-For) detected by rbl.malware.expert. RBL lookup of 14.121.255.5.rbl.malware.expert succeeded at REQUEST_HEADERS:x-forwarded-for. (1001000-nue6-2)
show less
Hacking
๐บ๐ธ
alecj.com
2026-05-12 11:26:12
(4 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฎ๐น
madaello
2026-05-12 11:22:25
(4 months ago)
5.255.121.14 - - [12/May/2026:13:22:14 +0200] "GET /404/ HTTP/1.1" 404 94528 "https://matrimonio.eli ...
show more
5.255.121.14 - - [12/May/2026:13:22:14 +0200] "GET /404/ HTTP/1.1" 404 94528 "https://matrimonio.elisa-andrea.it/wp-admin/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:133.0) Gecko/20100101 Firefox/133.0"
5.255.121.14 - - [12/May/2026:13:22:15 +0200] "GET /asset-manifest.json HTTP/1.1" 404 94576 "-" "Mozilla/5.0 (compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user)"
5.255.121.14 - - [12/May/2026:13:22:16 +0200] "GET /manifest.json HTTP/1.1" 404 94558 "-" "Mozilla/5.0 (compatible; GoogleOther; +https://developers.google.com/search/docs/crawling-indexing/overview-google-crawlers)"
5.255.121.14 - - [12/May/2026:13:22:18 +0200] "GET /build-manifest.json HTTP/1.1" 404 94576 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://about.you.com/youbot/)"
5.255.121.14 - - [12/May/2026:13:22:19 +0200] "GET /_next/static/buildManifest.js HTTP/1.1" 404 94806 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm) Chrome/1
...
show less
Web App Attack
๐ฉ๐ช
LRob
2026-05-12 10:45:03
(4 months ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
๐ฉ๐ช
Dominik Lysiak
2026-05-12 10:36:49
(4 months ago)
5.255.121.14 - - [12/May/2026:12:36:49 +0200] "GET /.ssh/id_ed25519 HTTP/1.1" 404 274 "-" "Mozilla/5 ...
show more
5.255.121.14 - - [12/May/2026:12:36:49 +0200] "GET /.ssh/id_ed25519 HTTP/1.1" 404 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:132.0) Gecko/20100101 Firefox/132.0"
5.255.121.14 - - [12/May/2026:12:36:49 +0200] "GET /.ssh/id_rsa HTTP/1.1" 404 274 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1 Mobile/15E148 Safari/604.1"
5.255.121.14 - - [12/May/2026:12:36:49 +0200] "GET /.ssh/id_dsa HTTP/1.1" 404 274 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14.7; rv:133.0) Gecko/20100101 Firefox/133.0"
...
show less
Web App Attack
๐ฉ๐ช
Skyrider
2026-05-12 09:07:56
(4 months ago)
crowdsecurity/http-sensitive-files
Hacking
๐ฉ๐ช
Petros Stefanakis
2026-05-12 08:59:42
(4 months ago)
(mod_security) mod_security triggered on hostname [redacted] 5.255.121.14 (NL/Netherlands/-)
SQL Injection
๐ฉ๐ช
s@ch@
2026-05-12 06:15:02
(4 months ago)
Jail: plesk-modsecurity | Web application attack (Plesk ModSecurity)
Web App Attack
๐น๐ท
baku.hosting
2026-05-12 05:34:22
(4 months ago)
CSF Auto Report: (mod_security) mod_security (id:949110) triggered by 5.255.121.14 (NL/The Netherlan ...
show more
CSF Auto Report: (mod_security) mod_security (id:949110) triggered by 5.255.121.14 (NL/The Netherlands/-): 5 in the last 3600 secs
show less
Brute-Force
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-05-12 05:13:35
(4 months ago)
25 attacks on VC URLs, password grabbing URLs, config grabbing URLs (type 2), env grabbing URLs:
GET ...
show more
25 attacks on VC URLs, password grabbing URLs, config grabbing URLs (type 2), env grabbing URLs:
GET /.git/config HTTP/1.1
GET /.aws/credentials HTTP/1.1
GET /app-config.json HTTP/1.1
GET /app/.env HTTP/1.1
show less
Hacking