๐ฎ๐ณ
evicky2002
2026-05-20 04:30:47
(4 months ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-05-13 16:09:08
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 5.255.123.230 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 5.255.123.230 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 12:09:03.542144 2026] [security2:error] [pid 29134:tid 29134] [client 5.255.123.230:37970] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cherishedcompanions.com"] [uri "/.git/config"] [unique_id "agSiH4wuFhL10RMpQKd6BAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-05-13 15:02:48
(4 months ago)
Excessive multi-domain requests
Brute-Force
๐ฆ๐น
penguin-solutions.at
2026-05-13 14:49:57
(4 months ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-05-13 14:39:22
(4 months ago)
5.255.123.230 - - [13/May/2026:17:39:22 +0300] "GET /public/.env HTTP/1.1" 404 3044 "-" "Mozilla/5.0 ...
show more
5.255.123.230 - - [13/May/2026:17:39:22 +0300] "GET /public/.env HTTP/1.1" 404 3044 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36"
5.255.123.230 - - [13/May/2026:17:39:22 +0300] "GET /.env HTTP/1.1" 404 3044 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-05-13 14:37:28
(4 months ago)
Blocked by CSF 13 firewall - Rule: NL/Netherlands/-
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-13 14:34:24
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 5.255.123.230 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 5.255.123.230 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 10:34:16.630723 2026] [security2:error] [pid 18358:tid 18458] [client 5.255.123.230:40640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chelseyrae.com"] [uri "/.env.backup"] [unique_id "agSL6GW1MYGEk57O0npEVAAAAgo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-05-13 14:05:15
(4 months ago)
Too many Status 40X (13)
Brute-Force
Web App Attack
๐ฉ๐ช
NewGastroline
2026-05-13 13:53:54
(4 months ago)
Malicious request blocked by CrowdSec on gastro-prod1.boreus.de
Bad Web Bot
Web App Attack
๐ณ๐ฑ
wlt-blocker
2026-05-13 13:48:32
(4 months ago)
Unauthorized access to webpage admin
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-13 13:43:32
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 5.255.123.230 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 5.255.123.230 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 09:43:24.378217 2026] [security2:error] [pid 25893:tid 25893] [client 5.255.123.230:43032] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chefmarcelcooks.com"] [uri "/.env.production"] [unique_id "agR__K6HDDm6p2qwvNEjUgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
Origon
2026-05-13 13:28:46
(4 months ago)
http-sensitive-files - IP: 5.255.123.230 - time="2026-05-13T15:28:46+02:00" level=info msg="(555f66 ...
show more
http-sensitive-files - IP: 5.255.123.230 - time="2026-05-13T15:28:46+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-sensitive-files by ip 5.255.123.230 (NL/60404) : 4h ban on Ip 5.255.123.230" module=db
show less
Web App Attack
๐ซ๐ฎ
Shaik Sai Meera
2026-05-13 12:20:06
(4 months ago)
IM360 WAF: Hidden file access
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-13 11:57:17
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 5.255.123.230 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 5.255.123.230 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 07:57:08.813256 2026] [security2:error] [pid 22213:tid 22213] [client 5.255.123.230:49954] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cheaptrafficschool247.com"] [uri "/.env.staging"] [unique_id "agRnFHIdGMBBm_-xRTYsqgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
jormaster3k
2026-05-13 11:18:37
(4 months ago)
Attack against Apache (too many 404s)
Web App Attack