๐ช๐ธ
didevi
2025-10-19 00:50:43
(10 months ago)
SPAM or Brute force attack detected
Email Spam
Brute-Force
๐ฎ๐ฉ
hermawan
2025-05-31 13:05:22
(1 year ago)
[Sat May 31 19:59:47.620542 2025] [security2:error] [pid 1430173:tid 139909691008704] [client 103.15 ...
show more
[Sat May 31 19:59:47.620542 2025] [security2:error] [pid 1430173:tid 139909691008704] [client 103.155.196.22:44832] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "okhttp" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: okhttp found within REQUEST_HEADERS:User-Agent: okhttp/4.12.0 request_line = GET /images/Klimatologi/Infografis/Infografis-Iklim/Klimat_Story/2023/Mengenal_Fenomena_El_Nino_Yang_Mengancam_Indonesia.jpg HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/Klimatologi/Infografis/Infografis-Iklim/Klimat_Story/2023/Mengenal_Fenomena_El_Nino_Yang_Mengancam_Indonesia.jpg"] [unique_id "aDr9Q_wSxucfkFU2pHxAPgAADxA"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[1430190] [IFD/GvZ8WaU] [aDr9Q_wSxucfkFU2pHxAPgAADxA] keep_alive=[1] [2025-05-31 19:59:47.620557] [R:
...
show less
Hacking
Web App Attack
Anonymous
2025-05-12 13:52:12
(1 year ago)
Malicious activity detected
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-04-13 07:30:54
(1 year ago)
[Sun Apr 13 14:14:52.598494 2025] [security2:error] [pid 42596:tid 139663849535168] [client 103.155. ...
show more
[Sun Apr 13 14:14:52.598494 2025] [security2:error] [pid 42596:tid 139663849535168] [client 103.155.196.22:46992] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i),.*?[\\"'\\\\)0-9`-f][\\"'`](?:[\\"'`].*?[\\"'`]|(?:\\\\r?\\\\n)?\\\\z|[^\\"'`]+)|[^0-9A-Z_a-z]select.+[^0-9A-Z_a-z]*?from|(?:alter|(?:(?:cre|trunc|upd)at|renam)e|d(?:e(?:lete|sc)|rop)|(?:inser|selec)t|load)[\\\\s\\\\x0b]*?\\\\([\\\\s\\\\x0b]*?space[\\\\s\\\\x0b]*?\\\\(" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.10.0/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "2130"] [id "942200"] [msg "Detects MySQL comment-/space-obfuscated injections and backtick termination"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: , like Gecko) Version/4.0 Chrome/135.0.7049.38 Mobile Safari/537.36 OcIdWebView ({\\x22os\\x22:\\x22Android\\x22, found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (Linux; Android 12; CPH2139
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-04-12 16:33:06
(1 year ago)
[Sat Apr 12 23:31:44.031138 2025] [security2:error] [pid 237087:tid 139838372579008] [client 103.155 ...
show more
[Sat Apr 12 23:31:44.031138 2025] [security2:error] [pid 237087:tid 139838372579008] [client 103.155.196.22:37956] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i),.*?[\\"'\\\\)0-9`-f][\\"'`](?:[\\"'`].*?[\\"'`]|(?:\\\\r?\\\\n)?\\\\z|[^\\"'`]+)|[^0-9A-Z_a-z]select.+[^0-9A-Z_a-z]*?from|(?:alter|(?:(?:cre|trunc|upd)at|renam)e|d(?:e(?:lete|sc)|rop)|(?:inser|selec)t|load)[\\\\s\\\\x0b]*?\\\\([\\\\s\\\\x0b]*?space[\\\\s\\\\x0b]*?\\\\(" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.10.0/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "2130"] [id "942200"] [msg "Detects MySQL comment-/space-obfuscated injections and backtick termination"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: , like Gecko) Version/4.0 Chrome/135.0.7049.38 Mobile Safari/537.36 OcIdWebView ({\\x22os\\x22:\\x22Android\\x22, found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (Linux; Android 12; CPH2139
...
show less
Hacking
Web App Attack
๐ต๐ฑ
rafix
2022-10-25 15:56:06
(3 years ago)
Massive web scan, botnet/DDoS
DDoS Attack
Bad Web Bot
๐ฎ๐ธ
ISPLtd
2022-10-24 07:45:36
(3 years ago)
Oct 24 08:43:59 SRC=103.155.196.22 PROTO=TCP SPT=53740 DPT=3003 SYN
Oct 24 08:44:00 SRC=103.155.196. ...
show more
Oct 24 08:43:59 SRC=103.155.196.22 PROTO=TCP SPT=53740 DPT=3003 SYN
Oct 24 08:44:00 SRC=103.155.196.22 PROTO=TCP SPT=53740 DPT=3003 SYN
Oct 24 08:44:02 SRC=103.155.196.22 PROTO=TCP SPT=53740 DPT=3003
...
show less
Port Scan
๐ช๐ธ
IPV4Guard.com (AS215051)
2022-10-22 08:25:46
(3 years ago)
firewall,info SSH_ToMK input: in:ether1 out:(unknown 0), connection-state:new src-mac 00:5d:73:b9:5b ...
show more
firewall,info SSH_ToMK input: in:ether1 out:(unknown 0), connection-state:new src-mac 00:5d:73:b9:5b:4d, proto TCP (SYN), 103.155.196.22:58978->144.217.215.6:22, len 60
show less
Brute-Force
SSH
๐ง๐ช
Rory&
2022-06-02 23:00:00
(4 years ago)
Active DDoS Attack (botnet)
DDoS Attack
๐ง๐ช
Rory&
2022-06-02 23:00:00
(4 years ago)
Active DDoS Attack (botnet)
DDoS Attack
๐ฉ๐ช
SCHAPPY
2022-04-20 16:40:35
(4 years ago)
IP was involved in DDoS attack.
DDoS Attack
๐บ๐ธ
VSM Networks
2022-04-15 03:25:36
(4 years ago)
Credential Stuffing
Brute-Force
๐ฉ๐ช
SCHAPPY
2022-04-13 19:44:16
(4 years ago)
Critical web app attack detected. HTTP protocol version is not allowed by policy
Web App Attack
๐บ๐ธ
VSM Networks
2021-12-24 11:16:47
(4 years ago)
Credential Stuffing
Brute-Force
๐บ๐ธ
VSM Networks
2021-10-30 07:20:56
(4 years ago)
Credential Stuffing
Brute-Force