๐ง๐ช
sid3windr
2026-02-28 07:15:29
(6 months ago)
GET /.env (Tarpitted for 1d15h8m33s, wasted 8.06MB)
Web App Attack
๐จ๐ณ
ThreatBook.io
2026-02-27 23:58:43
(6 months ago)
ThreatBook Intelligence: Zombie,Spam more details on https://threatbook.io/ip/74.179.83.62
2026-02-2 ...
show more
ThreatBook Intelligence: Zombie,Spam more details on https://threatbook.io/ip/74.179.83.62
2026-02-27 05:43:17 /.env
2026-02-27 10:20:27 /.env
show less
Web App Attack
๐ฎ๐น
mgarofano80
2026-02-27 15:38:05
(6 months ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-27 01:53:17
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 74.179.83.62 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 74.179.83.62 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 26 20:53:09.719342 2026] [security2:error] [pid 13353:tid 13353] [client 74.179.83.62:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.virtualizecr.net"] [uri "/.env"] [unique_id "aaD5BTJEacsXcC6-APuC7wAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
[email protected]
2026-02-27 01:04:16
(6 months ago)
Fail2Ban jail apache-json-scanners detected activity on 2026-02-27T01:04:16Z
Brute-Force
๐บ๐ธ
[email protected]
2026-02-27 00:08:02
(6 months ago)
Fail2Ban jail apache-json-scanners detected activity on 2026-02-27T00:08:02Z
Brute-Force
๐บ๐ธ
mnsf
2026-02-26 22:05:21
(6 months ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
Anonymous
2026-02-26 20:42:08
(6 months ago)
git/env leak probe
Web App Attack
๐ฌ๐ง
consul.to
2026-02-26 18:35:42
(6 months ago)
Web attack/malicious scanning detected
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-02-26 13:00:57
(6 months ago)
Access to sensitive files detected w/ specific boundary.. Threat Score: 4.6/10 (MEDIUM). Confidence: ...
show more
Access to sensitive files detected w/ specific boundary.. Threat Score: 4.6/10 (MEDIUM). Confidence: 40%. CVSS v3.1: 2.9/10 (Low). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N. Bayesian Probability: 40%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Moderate. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-02-26 09:01:27
(6 months ago)
Access to sensitive files detected w/ specific boundary.. Threat Score: 5/10 (MEDIUM). Confidence: 4 ...
show more
Access to sensitive files detected w/ specific boundary.. Threat Score: 5/10 (MEDIUM). Confidence: 40%. CVSS v3.1: 2.9/10 (Low). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N. Bayesian Probability: 40%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ต๐ฑ
IROK
2026-02-26 08:44:25
(6 months ago)
Firewall Blocked - Unauthorized Port Scanning
...
Port Scan
๐ฎ๐ฉ
Kencang.ID
2026-02-26 08:13:00
(6 months ago)
Failed Login Attempt 2026-02-26 08:13:00 | 74.179.83.62 | Desktop | Unknown | Quincy, Washington, Un ...
show more
Failed Login Attempt 2026-02-26 08:13:00 | 74.179.83.62 | Desktop | Unknown | Quincy, Washington, United States | Microsoft Corporation | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36
show less
Brute-Force
FTP Brute-Force
๐ฎ๐ฉ
sockominfo
2026-02-26 08:00:51
(6 months ago)
Access to sensitive files detected w/ specific boundary.. Threat Score: 5.7/10 (MEDIUM). Reported by ...
show more
Access to sensitive files detected w/ specific boundary.. Threat Score: 5.7/10 (MEDIUM). Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-26 08:00:20
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 74.179.83.62 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 74.179.83.62 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 26 03:00:14.967476 2026] [security2:error] [pid 20541:tid 20541] [client 74.179.83.62:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.eddysgroup.com"] [uri "/.env"] [unique_id "aZ_9jquTJ3zKaC0oi21WXgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack