๐บ๐ธ
ANTI SCANNER
2026-09-20 17:33:35
(22 hours ago)
Scanner : /.env.swp
Web Spam
๐บ๐ธ
WPJoe
2026-09-17 15:46:00
(4 days ago)
9.160.160.1 - - [17/Sep/2026:15:45:55 +0000] "GET /.env.swp HTTP/1.1" 403 444 "-" "ExposureScanner/1 ...
show more
9.160.160.1 - - [17/Sep/2026:15:45:55 +0000] "GET /.env.swp HTTP/1.1" 403 444 "-" "ExposureScanner/1.0 (internal-security-audit)"
9.160.160.1 - - [17/Sep/2026:15:45:59 +0000] "GET /.env.production/ HTTP/1.1" 403 443 "https://54.175.81.26/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:133.0) Gecko/20100101 Firefox/133.0"
...
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
mnsf
2026-09-16 14:05:30
(5 days ago)
Too many Status 50X (11)
Brute-Force
Web App Attack
๐ฎ๐ช
AutosOnShow
2026-09-16 09:45:07
(5 days ago)
blocked for webapp attack | path requested: /.env | seen at 2026-09-16 09:44:52.103 |
Web App Attack
๐บ๐ธ
Gabriel Camargo
2026-09-08 06:34:57
(1 week ago)
9.160.160.1 - - [08/Sep/2026:01:34:51 -0500] "GET /id_rsa HTTP/1.1" 404 162 "-" "ExposureScanner/1.0 ...
show more
9.160.160.1 - - [08/Sep/2026:01:34:51 -0500] "GET /id_rsa HTTP/1.1" 404 162 "-" "ExposureScanner/1.0 (internal-security-audit)"
9.160.160.1 - - [08/Sep/2026:01:34:55 -0500] "GET /wp-config.php.old HTTP/1.1" 404 162 "-" "ExposureScanner/1.0 (internal-security-audit)"
9.160.160.1 - - [08/Sep/2026:01:34:56 -0500] "GET /config/credentials.yml.enc HTTP/1.1" 404 162 "-" "ExposureScanner/1.0 (internal-security-audit)"
...
show less
Brute-Force
SSH
Anonymous
2026-09-04 10:02:10
(2 weeks ago)
Scanner hitting /.env.docker on 176.31.46.240 () โ aaguard
Brute-Force
Port Scan
๐ซ๐ท
guillaume illien
2026-08-27 09:25:53
(3 weeks ago)
9.160.160.1 - - [27/Aug/2026:09:25:48 +0000] "GET /.env HTTP/1.1" 301 178 "-" "ExposureScanner/1.0 ( ...
show more
9.160.160.1 - - [27/Aug/2026:09:25:48 +0000] "GET /.env HTTP/1.1" 301 178 "-" "ExposureScanner/1.0 (internal-security-audit)"
9.160.160.1 - - [27/Aug/2026:09:25:50 +0000] "GET /wp-config.php.swp HTTP/1.1" 301 178 "-" "ExposureScanner/1.0 (internal-security-audit)"
9.160.160.1 - - [27/Aug/2026:09:25:52 +0000] "GET /config/database.yml HTTP/1.1" 301 178 "-" "ExposureScanner/1.0 (internal-security-audit)"
9.160.160.1 - - [27/Aug/2026:09:25:52 +0000] "GET /config/secrets.yml HTTP/1.1" 301 178 "-" "ExposureScanner/1.0 (internal-security-audit)"
9.160.160.1 - - [27/Aug/2026:09:25:52 +0000] "GET /application.yml HTTP/1.1" 301 178 "-" "ExposureScanner/1.0 (internal-security-audit)"
9.160.160.1 - - [27/Aug/2026:09:25:52 +0000] "GET /bootstrap.properties HTTP/1.1" 301 178 "-" "ExposureScanner/1.0 (internal-security-audit)"
9.160.160.1 - - [27/Aug/2026:09:25:53 +0000] "GET /application-dev.yml HTTP/1.1" 301 178 "-" "ExposureScanner/1.0 (internal-security-audit)"
...
show less
Hacking
Brute-Force
Web App Attack
SSH
๐ซ๐ท
id2i
2026-08-27 06:12:22
(3 weeks ago)
2026-08-27T08:12:19.648060+02:00 coraza-spoa[187074]: [client "9.160.160.1"] Coraza: Access denied ( ...
show more
2026-08-27T08:12:19.648060+02:00 coraza-spoa[187074]: [client "9.160.160.1"] Coraza: Access denied (phase 2). Inbound Anomaly Score Exceeded (Total Score: 8)
show less
Hacking
Web App Attack
๐ฎ๐ณ
evicky2002
2026-08-27 06:00:33
(3 weeks ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ซ๐ท
LRob
2026-08-27 05:11:56
(3 weeks ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /.env.production | 2026-08-27 05:11 UTC
show less
Hacking
Web App Attack
๐ซ๐ท
Vaction
2026-08-26 23:15:38
(3 weeks ago)
9.160.160.1 - - [27/Aug/2026:01:15:38 +0200] "GET /web.config HTTP/1.1" 404 437 "-" "ExposureScanner ...
show more
9.160.160.1 - - [27/Aug/2026:01:15:38 +0200] "GET /web.config HTTP/1.1" 404 437 "-" "ExposureScanner/1.0 (internal-security-audit)"
show less
Hacking
Bad Web Bot
Web App Attack
๐ฌ๐ง
Interceptor_HQ
2026-08-26 18:11:50
(3 weeks ago)
request_uri: /.env.local -- automatic report --
Brute-Force
Hacking
๐บ๐ธ
masterguru
2026-08-26 16:04:34
(3 weeks ago)
Host header is a numeric IP address. Pattern match "^ (920350-166)
Hacking
Bad Web Bot
๐ณ๐ฑ
JCB
2026-08-26 14:45:00
(3 weeks ago)
9.160.160.1 - - [26/Aug/2026:00:29:03 +0300] "GET /.git/COMMIT_EDITMSG/ HTTP/1.1" 403 239 "-" "Mozil ...
show more
9.160.160.1 - - [26/Aug/2026:00:29:03 +0300] "GET /.git/COMMIT_EDITMSG/ HTTP/1.1" 403 239 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_7_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.2 Safari/605.1.15"
...
show less
Web App Attack
Hacking
๐ซ๐ท
COMAITE
2026-08-26 07:56:18
(3 weeks ago)
Common web attack from 9.160.160.1.
Web App Attack