Birdflew
21 Sep 2022
Port scanning
Hacking
gwynethllewelyn.net
21 Sep 2022
2022/09/21 22:01:04 [error] 52040#52040: *157887 access forbidden by rule, client: 20.10.20.66, serv ... show more 2022/09/21 22:01:04 [error] 52040#52040: *157887 access forbidden by rule, client: 20.10.20.66, server: feminina.eu, request: "GET /.env HTTP/2.0", host: "feminina.eu"
20.10.20.66 - - [21/Sep/2022:22:01:04 +0100] "GET /.env HTTP/2.0" 403 146 "-" "python-requests/2.27.1"
2022/09/21 22:01:19 [error] 52040#52040: *157899 access forbidden by rule, client: 20.10.20.66, server: feminina.eu, request: "GET /laravel/.env HTTP/2.0", host: "feminina.eu"
... show less
Web App Attack
AC - Team
21 Sep 2022
20.10.20.66 - - [21/Sep/2022:15:33:21 -0300] "GET /.env HTTP/1.1" 403 396 "-" "python-requests/2.27. ... show more 20.10.20.66 - - [21/Sep/2022:15:33:21 -0300] "GET /.env HTTP/1.1" 403 396 "-" "python-requests/2.27.1"
... show less
Exploited Host
Web App Attack
blinx
21 Sep 2022
Suspicious activity detected by Modsecurity
Web Spam
Port Scan
Hacking
Bad Web Bot
Web App Attack
URAN Publishing Service
21 Sep 2022
20.10.20.66 - - [21/Sep/2022:17:27:13 +0300] "GET /.env HTTP/1.1" 404 284 "-" "python-requests/2.27. ... show more 20.10.20.66 - - [21/Sep/2022:17:27:13 +0300] "GET /.env HTTP/1.1" 404 284 "-" "python-requests/2.27.1"
20.10.20.66 - - [21/Sep/2022:17:27:15 +0300] "GET /laravel/.env HTTP/1.1" 404 284 "-" "python-requests/2.27.1"
... show less
Web App Attack
zorrigas
21 Sep 2022
(mod_security) mod_security (id:210492) triggered by 20.10.20.66 (US/United States/-): 5 in the last ... show more (mod_security) mod_security (id:210492) triggered by 20.10.20.66 (US/United States/-): 5 in the last 3600 secs show less
Brute-Force
Web App Attack
AC - Team
21 Sep 2022
20.10.20.66 - - [21/Sep/2022:07:09:36 -0300] "GET /.env HTTP/1.1" 403 433 "-" "python-requests/2.27. ... show more 20.10.20.66 - - [21/Sep/2022:07:09:36 -0300] "GET /.env HTTP/1.1" 403 433 "-" "python-requests/2.27.1"
... show less
Exploited Host
Web App Attack
Ba-Yu
21 Sep 2022
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
URAN Publishing Service
21 Sep 2022
20.10.20.66 - - [21/Sep/2022:10:41:54 +0300] "GET /.env HTTP/1.1" 404 272 "-" "python-requests/2.27. ... show more 20.10.20.66 - - [21/Sep/2022:10:41:54 +0300] "GET /.env HTTP/1.1" 404 272 "-" "python-requests/2.27.1"
20.10.20.66 - - [21/Sep/2022:10:41:56 +0300] "GET /laravel/.env HTTP/1.1" 404 272 "-" "python-requests/2.27.1"
... show less
Web App Attack
10dencehispahard SL
21 Sep 2022
Abusive use detected
Brute-Force
SH SysOp Team
19 Sep 2022
[Mon Sep 19 12:01:22.197236 2022] [:error] [pid 227586:tid 139651935368960] [client 20.10.20.66:4483 ... show more [Mon Sep 19 12:01:22.197236 2022] [:error] [pid 227586:tid 139651935368960] [client 20.10.20.66:44832] [client 20.10.20.66] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/usr/local/apache/modsecurity-cwaf/rules/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "-"] [uri "/.env"] [unique_id "YyhaEhfyaymCIQtKXw4fXwAAAMM"]
[Mon Sep 19 12:01:22.574220 2022] [:error] [pid 4124743:tid 139651222316800] [client 20.10.20.66:45404] [client 20.10.20.66] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/usr/local/apache/modsecurity-cwaf/rules/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "-"] [uri "/.env.example"] [unique_id "YyhaEnNrDVCJIqeG9gIBQwAAAJY"] show less
Hacking
Brute-Force
Web App Attack
SH SysOp Team
19 Sep 2022
[Mon Sep 19 15:43:46.269711 2022] [:error] [pid 4089797:tid 140094736340736] [client 20.10.20.66:601 ... show more [Mon Sep 19 15:43:46.269711 2022] [:error] [pid 4089797:tid 140094736340736] [client 20.10.20.66:60164] [client 20.10.20.66] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/usr/local/apache/modsecurity-cwaf/rules/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "-"] [uri "/.env"] [unique_id "YyiOMh0eo_uxoKxHFVJjbAAAAFY"]
[Mon Sep 19 15:43:48.400226 2022] [:error] [pid 91416:tid 140094870624000] [client 20.10.20.66:33574] [client 20.10.20.66] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/usr/local/apache/modsecurity-cwaf/rules/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "-"] [uri "/.env.example"] [unique_id "YyiONAI-QR98U7H0ZagkEAAAAMY"] show less
Hacking
Brute-Force
Web App Attack
npcautomotive.com
19 Sep 2022
20.10.20.66 - - [19/Sep/2022:20:49:56 +0000] "GET /.env HTTP/1.1" 301 245 "-" "python-requests/2.27. ... show more 20.10.20.66 - - [19/Sep/2022:20:49:56 +0000] "GET /.env HTTP/1.1" 301 245 "-" "python-requests/2.27.1"
... show less
Hacking
ISPLtd
19 Sep 2022
20.10.20.66 - - [19/Sep/2022:09:51:28 -0600] "GET /.env
...
Hacking
Web App Attack
IrisFlower
19 Sep 2022
Unauthorized connection attempt detected from IP address 20.10.20.66 to port 80 [J]
Port Scan
Hacking