๐บ๐ฆ
URAN Publishing Service
2026-07-22 21:47:45
(17 minutes ago)
91.92.47.135 - - [23/Jul/2026:00:47:44 +0300] "GET /static/home/user/.env HTTP/1.1" 404 788 "http:// ...
show more
91.92.47.135 - - [23/Jul/2026:00:47:44 +0300] "GET /static/home/user/.env HTTP/1.1" 404 788 "http://pharmed.zsmu.edu.ua/static//home/user/.env" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
91.92.47.135 - - [23/Jul/2026:00:47:45 +0300] "GET /static/app/.env HTTP/1.1" 404 788 "http://pharmed.zsmu.edu.ua/static//app/.env" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:123.0) Gecko/20100101 Firefox/123.0"
...
show less
Web App Attack
๐ฌ๐ง
ISPLtd
2026-07-22 21:25:35
(39 minutes ago)
91.92.47.135 [22/Jul/2026:18:25:34 -0300] claire.target.domain:80 URL:/public/.git/config "GET /publ ...
show more
91.92.47.135 [22/Jul/2026:18:25:34 -0300] claire.target.domain:80 URL:/public/.git/config "GET /public/.git/config
91.92.47.135 [22/Jul/2026:18:25:34 -0300] claire.target.domain:80 URL:/.env.local "GET /.env.local
...
show less
Hacking
Web App Attack
๐ซ๐ท
Lunix
2026-07-22 18:58:08
(3 hours ago)
Brute-Force
Web App Attack
Anonymous
2026-07-22 14:06:04
(7 hours ago)
Trying to access config files
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-07-22 05:14:20
(16 hours ago)
85 attacks on env grabbing URLs, VC URLs, PHP URLs, site downloads, password grabbing URLs:
GET /.en ...
show more
85 attacks on env grabbing URLs, VC URLs, PHP URLs, site downloads, password grabbing URLs:
GET /.env HTTP/1.1
GET /public/.git/config HTTP/1.1
GET /phpinfo.php HTTP/1.1
GET /.git.tar HTTP/1.1
GET /.aws/credentials HTTP/1.1
show less
Hacking
Web App Attack
Anonymous
2026-07-22 03:06:00
(18 hours ago)
Blocked: Reason='Suspicious traffic score=80 (review-based detection)'; Requests=56
Hacking
๐ฉ๐ช
webanyone
2026-07-22 02:00:53
(20 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ฉ๐ช
LRob
2026-07-22 01:46:36
(20 hours ago)
CrowdSec: crowdsecurity/http-sensitive-files | req: /.aws/credentials | 5 distinct paths | UA: Mozil ...
show more
CrowdSec: crowdsecurity/http-sensitive-files | req: /.aws/credentials | 5 distinct paths | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36 Edg/121.0.0.0
show less
Hacking
๐ซ๐ท
conseilgouz
2026-07-21 22:42:45
(23 hours ago)
joe-6 : Trying access system files=>/phpinfo.php(phpinfo.php)
Hacking
๐ฉ๐ช
louis77
2026-07-21 22:14:30
(23 hours ago)
Sensitive file access attempt - Path: /api/.env, Method: GET, UA: Mozilla/5.0 (Windows NT 10.0; Win6 ...
show more
Sensitive file access attempt - Path: /api/.env, Method: GET, UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36 Edg/121.0.0.0
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-21 21:57:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 91.92.47.135 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 91.92.47.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 17:57:29.166415 2026] [security2:error] [pid 23022:tid 23022] [client 91.92.47.135:54144] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.179vfs.com"] [uri "/public_html/.git/config"] [unique_id "al_rSfIyd0ExfHNWTU9jwgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 21:25:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 91.92.47.135 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 91.92.47.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 17:25:42.373850 2026] [security2:error] [pid 437936:tid 437936] [client 91.92.47.135:40796] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "listings.cruisingforsex.com"] [uri "/backup/.git/config"] [unique_id "al_j1jmKR-wPfaZcbp3Z2wAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Interceptor_HQ
2026-07-21 14:27:17
(1 day ago)
request_uri: / -- automatic report --
Brute-Force
Hacking
๐ฉ๐ช
pscriptos
2026-07-21 12:21:09
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ธ๐ช
vaia.cloud
2026-07-21 11:15:02
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack