๐ฆ๐บ
MAGIC
2025-06-28 15:01:06
(11 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ฎ๐ฉ
hermawan
2025-06-20 09:56:14
(11 months ago)
[Fri Jun 20 16:54:35.090492 2025] [security2:error] [pid 105657:tid 140596850108096] [client 103.171 ...
show more
[Fri Jun 20 16:54:35.090492 2025] [security2:error] [pid 105657:tid 140596850108096] [client 103.171.244.133:59406] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "myactivity.google.com" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.15.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "455"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: myactivity.google.com found within REQUEST_HEADERS:Referer: https://myactivity.google.com/ request_line = GET /images/Klimatologi/Infografis/Infografis-Iklim/Dasarian/2025/06_Juni_2025/Das-I/Infografis_Dasarian_Iklim_Jawa_Timur_Update_10_Juni_2025.jpg HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/Klimatologi/Infografis/Infografis-Iklim/Dasarian/2025/06_Juni_2025/Das-I/Infografis_Dasarian_Iklim_Jawa_Timur_Update_10_Juni_2025.jpg"] [unique_id "aFUv24eJLmyprg-u1mYJkwAAihg"], referer https://myactivity.google.com/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] t
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-06-09 07:48:46
(1 year ago)
[Mon Jun 09 14:48:45.115950 2025] [security2:error] [pid 972264:tid 139881576584896] [client 103.171 ...
show more
[Mon Jun 09 14:48:45.115950 2025] [security2:error] [pid 972264:tid 139881576584896] [client 103.171.244.133:42148] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "myactivity.google.com" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "439"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: myactivity.google.com found within REQUEST_HEADERS:Referer: https://myactivity.google.com/ request_line = GET /images/berita/2025/04/04-04-2025/Ucapan_Duka_Atas_Meninggalnya_Lestari.jpg HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/berita/2025/04/04-04-2025/Ucapan_Duka_Atas_Meninggalnya_Lestari.jpg"] [unique_id "aEaR3Wrv5ZFQKAgVXPoYcwABWxE"], referer https://myactivity.google.com/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[972283] [7CIzz4b2KQA] [aEaR3Wrv5ZFQKAgVXPoYcwABWxE] keep_alive=[1] [2025-06-09 14:48:45.115958] [R:aEaR3Wrv5ZFQKAgVXPoYcwABWxE]
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-06-01 07:53:40
(1 year ago)
[Sun Jun 01 14:53:09.864078 2025] [security2:error] [pid 504390:tid 139726121043648] [client 103.171 ...
show more
[Sun Jun 01 14:53:09.864078 2025] [security2:error] [pid 504390:tid 139726121043648] [client 103.171.244.133:54508] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "myactivity.google.com" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "439"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: myactivity.google.com found within REQUEST_HEADERS:Referer: https://myactivity.google.com/ request_line = GET /images/gempa/webp/20250601014150.mmi.jpg.webp HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/gempa/webp/20250601014150.mmi.jpg.webp"] [unique_id "aDwG5Ttjfssyv-Wpb47qZwAAlgY"], referer https://myactivity.google.com/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[504397] [Xb4/8GW5UK8] [aDwG5Ttjfssyv-Wpb47qZwAAlgY] keep_alive=[1] [2025-06-01 14:53:09.864086] [R:aDwG5Ttjfssyv-Wpb47qZwAAlgY] UA:'Mozilla/5.0 (Linux; Android 11; SM-A225F Build/RP1A.20
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-05-30 09:09:47
(1 year ago)
[Fri May 30 11:32:52.779266 2025] [security2:error] [pid 414036:tid 139910022371008] [client 103.171 ...
show more
[Fri May 30 11:32:52.779266 2025] [security2:error] [pid 414036:tid 139910022371008] [client 103.171.244.133:44814] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "myactivity.google.com" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "439"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: myactivity.google.com found within REQUEST_HEADERS:Referer: https://myactivity.google.com/ request_line = GET /images/berita/2025/04/04-04-2025/Ucapan_Duka_Atas_Meninggalnya_Lestari.jpg HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/berita/2025/04/04-04-2025/Ucapan_Duka_Atas_Meninggalnya_Lestari.jpg"] [unique_id "aDk09O-6g_NWSof_6w6dmgAAlg0"], referer https://myactivity.google.com/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[414050] [WzdL6Mq423Y] [aDk09O-6g_NWSof_6w6dmgAAlg0] keep_alive=[1] [2025-05-30 11:32:52.779273] [R:aDk09O-6g_NWSof_6w6dmgAAlg0]
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-05-29 10:14:48
(1 year ago)
[Thu May 29 17:09:46.067604 2025] [security2:error] [pid 16651:tid 140697863640768] [client 103.171. ...
show more
[Thu May 29 17:09:46.067604 2025] [security2:error] [pid 16651:tid 140697863640768] [client 103.171.244.133:48606] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "myactivity.google.com" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "439"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: myactivity.google.com found within REQUEST_HEADERS:Referer: https://myactivity.google.com/ request_line = GET /images/berita/2025/04/04-04-2025/Ucapan_Duka_Atas_Meninggalnya_Lestari.jpg HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/berita/2025/04/04-04-2025/Ucapan_Duka_Atas_Meninggalnya_Lestari.jpg"] [unique_id "aDgyasNQtX3blWM8fr0p0AAAGhU"], referer https://myactivity.google.com/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[16725] [L9RBfxt3Luo] [aDgyasNQtX3blWM8fr0p0AAAGhU] keep_alive=[1] [2025-05-29 17:09:46.067614] [R:aDgyasNQtX3blWM8fr0p0AAAGhU] UA
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-05-28 10:15:28
(1 year ago)
[Wed May 28 17:14:57.212383 2025] [security2:error] [pid 265208:tid 140335268128448] [client 103.171 ...
show more
[Wed May 28 17:14:57.212383 2025] [security2:error] [pid 265208:tid 140335268128448] [client 103.171.244.133:58276] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "myactivity.google.com" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "439"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: myactivity.google.com found within REQUEST_HEADERS:Referer: https://myactivity.google.com/ request_line = GET /images/berita/2025/04/04-04-2025/Ucapan_Duka_Atas_Meninggalnya_Lestari.jpg HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/berita/2025/04/04-04-2025/Ucapan_Duka_Atas_Meninggalnya_Lestari.jpg"] [unique_id "aDbiIb8Ocl3HTasITKFIsQAAjho"], referer https://myactivity.google.com/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[265235] [ZFX2c7f5iYA] [aDbiIb8Ocl3HTasITKFIsQAAjho] keep_alive=[1] [2025-05-28 17:14:57.212389] [R:aDbiIb8Ocl3HTasITKFIsQAAjho]
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-05-22 16:02:11
(1 year ago)
[Thu May 22 23:01:25.397710 2025] [security2:error] [pid 103267:tid 139791572604608] [client 103.171 ...
show more
[Thu May 22 23:01:25.397710 2025] [security2:error] [pid 103267:tid 139791572604608] [client 103.171.244.133:37088] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "myactivity.google.com" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "439"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: myactivity.google.com found within REQUEST_HEADERS:Referer: https://myactivity.google.com/ request_line = GET /images/berita/2025/04/04-04-2025/Ucapan_Duka_Atas_Meninggalnya_Lestari.jpg HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/berita/2025/04/04-04-2025/Ucapan_Duka_Atas_Meninggalnya_Lestari.jpg"] [unique_id "aC9KVQJqDRv8bkK2gBNUOwAAwTE"], referer https://myactivity.google.com/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[103317] [89X6l0O6Gl0] [aC9KVQJqDRv8bkK2gBNUOwAAwTE] keep_alive=[1] [2025-05-22 23:01:25.397718] [R:aC9KVQJqDRv8bkK2gBNUOwAAwTE]
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-05-13 13:29:20
(1 year ago)
[Tue May 13 19:29:27.664432 2025] [security2:error] [pid 68110:tid 139997726271168] [client 103.171. ...
show more
[Tue May 13 19:29:27.664432 2025] [security2:error] [pid 68110:tid 139997726271168] [client 103.171.244.133:36752] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "myactivity.google.com" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "439"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: myactivity.google.com found within REQUEST_HEADERS:Referer: https://myactivity.google.com/ request_line = GET /images/Klimatologi/Infografis/Infografis-Iklim/Bulanan/2025/03_Maret_2025/Infografis-Bulanan_Prediksi_Hujan_Bulan_MEI-JUNI-JULI_Tahun_2025_Update_Dari_Analisis_Bulan_Maret_2025_di_Provinsi_Jawa_Timur.jpg HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/Klimatologi/Infografis/Infografis-Iklim/Bulanan/2025/03_Maret_2025/Infografis-Bulanan_Prediksi_Hujan_Bulan_MEI-JUNI-JULI_Tahun_2025_Update_Dari_Analisis_Bulan_Maret_2025_di_Provinsi_Jawa_Timur.jpg"] [unique_id "
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-05-10 02:56:43
(1 year ago)
[Sat May 10 09:55:57.078650 2025] [security2:error] [pid 287218:tid 140583619221184] [client 103.171 ...
show more
[Sat May 10 09:55:57.078650 2025] [security2:error] [pid 287218:tid 140583619221184] [client 103.171.244.133:56264] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "myactivity.google.com" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "439"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: myactivity.google.com found within REQUEST_HEADERS:Referer: https://myactivity.google.com/ request_line = GET /images/gempa/webp/20250506055735.mmi.jpg.webp HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/gempa/webp/20250506055735.mmi.jpg.webp"] [unique_id "aB7APaDG0AcgOBcNGdgYcQABXQY"], referer https://myactivity.google.com/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[287225] [hfvSOGfTL04] [aB7APaDG0AcgOBcNGdgYcQABXQY] keep_alive=[1] [2025-05-10 09:55:57.078657] [R:aB7APaDG0AcgOBcNGdgYcQABXQY] UA:'Mozilla/5.0 (Linux; Android 11; SM-A225F Build/RP1A.20
...
show less
Hacking
Web App Attack
Anonymous
2025-05-06 09:58:53
(1 year ago)
Fail2Ban - Nginx Bot Probes
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-01-19 20:29:56
(1 year ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐ฉ๐ช
David Ferneding
2025-01-03 16:36:09
(1 year ago)
Part of large-scale ddos-attack, 2759792 requests from this ip
DDoS Attack
Bad Web Bot