๐ฎ๐ณ
evicky2002
2026-07-14 10:21:11
(2 months ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐จ๐ฆ
polycoda
2026-05-29 12:26:59
(3 months ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based)
Hacking
Web App Attack
๐ฉ๐ช
Progetto1
2026-05-23 05:39:02
(3 months ago)
Detected via HAProxyScanner at 2026-05-23 05:39:02 UTC on destination port WEB (80/443). Repeated sc ...
show more
Detected via HAProxyScanner at 2026-05-23 05:39:02 UTC on destination port WEB (80/443). Repeated scan / connection.
show less
Port Scan
Hacking
Brute-Force
๐ฌ๐ง
Axel
2026-05-23 05:25:39
(3 months ago)
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /.env Server: ...
show more
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /.env Server: UK-01
show less
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
itabu
2026-05-23 05:00:29
(3 months ago)
Malicious web scanner/bot detected.
Bad Web Bot
Web App Attack
๐บ๐ธ
antlac1
2026-05-23 03:55:30
(3 months ago)
crowdsecurity/CVE-2017-9841
Brute-Force
Web App Attack
๐ฉ๐ช
markawes
2026-05-23 02:34:37
(3 months ago)
[markis] Auto banned by Fail2Ban. Reason: Malicious web scan / attempted access to sensitive paths. ...
show more
[markis] Auto banned by Fail2Ban. Reason: Malicious web scan / attempted access to sensitive paths. Evidence:
51.120.0.216 - - [23/May/2026:03:34:34 +0100] "GET /.env HTTP/1.1" 404 492 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30"
51.120.0.216 - - [23/May/2026:03:34:35 +0100] "GET /.env HTTP/1.1" 404 3121 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30"
51.120.0.216 - - [23/May/2026:03:34:36 +0100] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 492 "-" "python-requests/2.33.1"
show less
Port Scan
Hacking
Web App Attack
๐ฆ๐บ
dyln
2026-05-22 23:24:49
(3 months ago)
Dyls honeypot brute-force: proto8 (2 total hits)
Brute-Force
Anonymous
2026-05-22 22:35:01
(3 months ago)
May 23 00:34:58 mail2 Nextcloud[185100]: {"reqId":"ahDaEZw-T6EHjBVJ44sHfgAAANI","level":1,"time":"20 ...
show more
May 23 00:34:58 mail2 Nextcloud[185100]: {"reqId":"ahDaEZw-T6EHjBVJ44sHfgAAANI","level":1,"time":"2026-05-22T22:34:58+00:00","remoteAddr":"51.120.0.216","user":"--","app":"core","method":"GET","url":"/.env","scriptName":"/index.php","message":"Trusted domain error. \"51.120.0.216\" tried to access using \"178.254.3.7\" as host.","userAgent":"Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30","version":"32.0.5.0","data":{"app":"core"}}
May 23 00:34:58 mail2 Nextcloud[262948]: {"reqId":"ahDaEj4AuJXSwuUvZnVFggAAAUE","level":1,"time":"2026-05-22T22:34:58+00:00","remoteAddr":"51.120.0.216","user":"--","app":"core","method":"POST","url":"/","scriptName":"/index.php","message":"Trusted domain error. \"51.120.0.216\" tried to access using \"178.254.3.7\" as host.","userAgent":"Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, l
...
show less
Brute-Force
Web App Attack
๐ซ๐ท
ar2000
2026-05-22 20:27:42
(3 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/CVE-2017-9841
Web App Attack
๐ฉ๐ช
barbarella
2026-05-22 17:52:47
(3 months ago)
Configuration snooping with .env file (GET /.env)
Hacking
Web App Attack
๐ฉ๐ช
barbarella
2026-05-22 17:52:47
(3 months ago)
Multiple (3) times attack on http port 80: Configuration snooping in .env file (GET /.env)
19:52: ...
show more
Multiple (3) times attack on http port 80: Configuration snooping in .env file (GET /.env)
19:52:47 Configuration snooping in .env file (GET /.env)
19:52:49 unauthorized access PHPunit framework files (GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php)
show less
Hacking
Web App Attack
๐ฎ๐ฉ
Burayot
2026-05-22 15:52:04
(3 months ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 51.120.0.216 (NO/Norway/-): 1 in the ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 51.120.0.216 (NO/Norway/-): 1 in the last 3600 secs
show less
Web App Attack
๐ฎ๐ฉ
securejdprop
2026-05-22 15:48:56
(3 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ET INFO Request to ...
show more
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ET INFO Request to Hidden Environment File - Inbound). Ip 51.120.0.216 performed 'crowdsecurity/suricata-major-severity' (1 events over 0s) at 2026-05-22 15:48:55.384485261 +0000 UTC
show less
Hacking
Web App Attack
๐ต๐ฑ
Roper123
2026-05-22 15:05:04
(3 months ago)
Web app exploits
Web App Attack