|
๐ฉ๐ช
blueSh4rk
|
|
Directory scanning
|
Bad Web Bot
Web App Attack
|
|
|
๐ณ๐ฑ
mawan
|
|
Suspected of having performed illicit activity on AMS server.
|
Web App Attack
|
|
|
๐ฎ๐ฉ
hermawan
|
|
[Thu Oct 06 06:20:13.439691 2022] [-:error] [pid 290736:tid 139706608416320] [client 20.193.146.73:4 ...
show more
[Thu Oct 06 06:20:13.439691 2022] [-:error] [pid 290736:tid 139706608416320] [client 20.193.146.73:42432] [client 20.193.146.73] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_FILENAME. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "155"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/4.0.0-rc1"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/.env"] [unique_id "Yz4RLeOHU4f9vhsJsvMtbQAAAME"] [karangploso.jatim.bmkg.go.id] [karangploso.jatim.bmkg.go.id] top=[290816] [4JGb0fmeg1Y] [Yz4RLeOHU4f9vhsJsvMtbQAAAME] keep_alive=[0] [2022-10-06 06:20:13.439702] [R:Yz4RLeOHU4f9vhsJsvMtbQAAAME] UA:'Mozilla/5.0 (Window
...
show less
|
Hacking
Web App Attack
|
|
|
๐ฎ๐ฉ
NOC Monitoring KAI
|
|
Web attack
|
Web App Attack
|
|
|
๐ธ๐ฌ
pusathosting.com
|
|
uvcm 20.193.146.73 [06/Oct/2022:00:49:48 "-" "GET /vendor/phpunit/phpunit/src/Util/PHP/login.php 302 ...
show more
uvcm 20.193.146.73 [06/Oct/2022:00:49:48 "-" "GET /vendor/phpunit/phpunit/src/Util/PHP/login.php 302 411
20.193.146.73 [06/Oct/2022:00:49:48 "-" "GET /vendor/phpunit/phpunit/src/Util/PHP/login.php 302 411
20.193.146.73 [06/Oct/2022:00:49:48 "-" "GET /vendor/phpunit/phpunit/src/Util/PHP/login.php 302 411
show less
|
Brute-Force
Web App Attack
|
|
|
๐บ๐ฆ
URAN Publishing Service
|
|
20.193.146.73 - - [01/Oct/2022:07:38:39 +0300] "GET /.env HTTP/1.1" 404 279 "-" "Mozilla/5.0 (Window ...
show more
20.193.146.73 - - [01/Oct/2022:07:38:39 +0300] "GET /.env HTTP/1.1" 404 279 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4859.172 Safari/537.36"
20.193.146.73 - - [01/Oct/2022:07:45:55 +0300] "GET /.env HTTP/1.1" 404 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4859.172 Safari/537.36"
...
show less
|
Web App Attack
|
|
|
๐บ๐ฆ
URAN Publishing Service
|
|
20.193.146.73 - - [01/Oct/2022:05:55:43 +0300] "GET /.env HTTP/1.1" 404 273 "-" "Mozilla/5.0 (Window ...
show more
20.193.146.73 - - [01/Oct/2022:05:55:43 +0300] "GET /.env HTTP/1.1" 404 273 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4859.172 Safari/537.36"
20.193.146.73 - - [01/Oct/2022:06:03:57 +0300] "GET /.env HTTP/1.1" 404 272 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4859.172 Safari/537.36"
...
show less
|
Web App Attack
|
|
|
๐บ๐ฆ
URAN Publishing Service
|
|
20.193.146.73 - - [01/Oct/2022:04:16:20 +0300] "GET /.env HTTP/1.1" 404 274 "-" "Mozilla/5.0 (Window ...
show more
20.193.146.73 - - [01/Oct/2022:04:16:20 +0300] "GET /.env HTTP/1.1" 404 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4859.172 Safari/537.36"
20.193.146.73 - - [01/Oct/2022:04:21:37 +0300] "GET /.env HTTP/1.1" 404 276 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4859.172 Safari/537.36"
...
show less
|
Web App Attack
|
|
|
๐บ๐ฆ
URAN Publishing Service
|
|
20.193.146.73 - - [01/Oct/2022:00:22:33 +0300] "GET /.env HTTP/1.1" 404 281 "-" "Mozilla/5.0 (Window ...
show more
20.193.146.73 - - [01/Oct/2022:00:22:33 +0300] "GET /.env HTTP/1.1" 404 281 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4859.172 Safari/537.36"
20.193.146.73 - - [01/Oct/2022:00:23:15 +0300] "GET /.env HTTP/1.1" 404 276 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4859.172 Safari/537.36"
...
show less
|
Web App Attack
|
|
|
๐บ๐ฆ
URAN Publishing Service
|
|
20.193.146.73 - - [30/Sep/2022:18:22:54 +0300] "GET /.env HTTP/1.1" 404 270 "-" "Mozilla/5.0 (Window ...
show more
20.193.146.73 - - [30/Sep/2022:18:22:54 +0300] "GET /.env HTTP/1.1" 404 270 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4859.172 Safari/537.36"
20.193.146.73 - - [30/Sep/2022:18:26:00 +0300] "GET /.env HTTP/1.1" 404 275 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4859.172 Safari/537.36"
...
show less
|
Web App Attack
|
|
|
๐บ๐ฆ
URAN Publishing Service
|
|
20.193.146.73 - - [30/Sep/2022:17:19:40 +0300] "GET /.env HTTP/1.1" 404 277 "-" "Mozilla/5.0 (Window ...
show more
20.193.146.73 - - [30/Sep/2022:17:19:40 +0300] "GET /.env HTTP/1.1" 404 277 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4859.172 Safari/537.36"
20.193.146.73 - - [30/Sep/2022:17:21:36 +0300] "GET /.env HTTP/1.1" 404 275 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4859.172 Safari/537.36"
...
show less
|
Web App Attack
|
|
|
๐บ๐ฆ
URAN Publishing Service
|
|
20.193.146.73 - - [30/Sep/2022:15:28:18 +0300] "GET /.env HTTP/1.1" 404 287 "-" "Mozilla/5.0 (Window ...
show more
20.193.146.73 - - [30/Sep/2022:15:28:18 +0300] "GET /.env HTTP/1.1" 404 287 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4859.172 Safari/537.36"
20.193.146.73 - - [30/Sep/2022:15:36:31 +0300] "GET /.env HTTP/1.1" 404 279 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4859.172 Safari/537.36"
...
show less
|
Web App Attack
|
|
|
๐บ๐ฆ
URAN Publishing Service
|
|
20.193.146.73 - - [30/Sep/2022:14:17:17 +0300] "GET /.env HTTP/1.1" 404 277 "-" "Mozilla/5.0 (Window ...
show more
20.193.146.73 - - [30/Sep/2022:14:17:17 +0300] "GET /.env HTTP/1.1" 404 277 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4859.172 Safari/537.36"
20.193.146.73 - - [30/Sep/2022:14:25:44 +0300] "GET /.env HTTP/1.1" 404 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4859.172 Safari/537.36"
...
show less
|
Web App Attack
|
|
|
๐บ๐ฆ
URAN Publishing Service
|
|
20.193.146.73 - - [30/Sep/2022:13:09:19 +0300] "GET /.env HTTP/1.1" 404 275 "-" "Mozilla/5.0 (Window ...
show more
20.193.146.73 - - [30/Sep/2022:13:09:19 +0300] "GET /.env HTTP/1.1" 404 275 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4859.172 Safari/537.36"
20.193.146.73 - - [30/Sep/2022:13:09:23 +0300] "GET /.env HTTP/1.1" 404 281 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4859.172 Safari/537.36"
...
show less
|
Web App Attack
|
|
|
๐บ๐ฆ
URAN Publishing Service
|
|
20.193.146.73 - - [30/Sep/2022:11:56:15 +0300] "GET /.env HTTP/1.1" 404 274 "-" "Mozilla/5.0 (Window ...
show more
20.193.146.73 - - [30/Sep/2022:11:56:15 +0300] "GET /.env HTTP/1.1" 404 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4859.172 Safari/537.36"
20.193.146.73 - - [30/Sep/2022:11:56:21 +0300] "GET /.env HTTP/1.1" 404 275 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4859.172 Safari/537.36"
...
show less
|
Web App Attack
|
|