Anonymous
2026-07-18 07:22:46
(6 days ago)
denied SMB access attempt. destination port 445.
Port Scan
Hacking
๐จ๐ญ
backslash
2026-06-08 16:36:35
(1 month ago)
Badbot using very old user-agents
Bad Web Bot
๐ฎ๐ฉ
hermawan
2025-12-28 19:43:08
(6 months ago)
[Mon Dec 29 02:43:07.412501 2025] [security2:error] [pid 117571:tid 140326147712704] [client 103.180 ...
show more
[Mon Dec 29 02:43:07.412501 2025] [security2:error] [pid 117571:tid 140326147712704] [client 103.180.118.33:54406] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "anonymous-client-ip" at REQUEST_HEADERS:Sec-Purpose. [file "/etc/modsecurity/coreruleset-4.20.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "116"] [id "448200"] [msg "BAD REQUEST Header anonymous-client-ip"] [data "Matched Data: anonymous-client-ip found within REQUEST_HEADERS:Sec-Purpose: prefetch;anonymous-client-ip request_line = GET /index.php/profil/meteorologi/list-of-all-tags/gempa-terkini HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/list-of-all-tags/gempa-terkini"] [unique_id "aVGISxu1ehdxGo-_3qum6wAADAE"], referer https://www.google.com/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[117573] [y4ruVUjAGFM] [aVGISxu1ehdxGo-_3qum6wAADAE] keep_alive=[1] [2025-12-29 02:43:07.412505] [R:aVGISxu1ehdxGo-_3qum6wAADAE] UA:'Mozil
...
show less
Hacking
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-09-06 00:01:16
(10 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐ฎ๐ฉ
hermawan
2025-09-05 19:00:10
(10 months ago)
[Sat Sep 06 00:58:54.195283 2025] [security2:error] [pid 1041132:tid 140016937309888] [client 103.18 ...
show more
[Sat Sep 06 00:58:54.195283 2025] [security2:error] [pid 1041132:tid 140016937309888] [client 103.180.118.33:60608] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i),.*?[\\"'\\\\)0-9`-f][\\"'`](?:[\\"'`].*?[\\"'`]|(?:\\\\r?\\\\n)?\\\\z|[^\\"'`]+)|[^0-9A-Z_a-z]select.+[^0-9A-Z_a-z]*?from|(?:alter|(?:(?:cre|trunc|upd)at|renam)e|d(?:e(?:lete|sc)|rop)|(?:inser|selec)t|load)[\\\\s\\\\x0b]*?\\\\([\\\\s\\\\x0b]*?space[\\\\s\\\\x0b]*?\\\\(" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "2129"] [id "942200"] [msg "Detects MySQL comment-/space-obfuscated injections and backtick termination"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: , like Gecko) Version/4.0 Chrome/139.0.7258.158 Mobile Safari/537.36 OcIdWebView ({\\x22os\\x22:\\x22Android\\x22, found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (Linux; Android 10; RMX21
...
show less
Hacking
Web App Attack
๐บ๐ธ
RAP
2025-07-25 02:01:19
(11 months ago)
2025-07-25 02:01:19 UTC Unauthorized activity to TCP port 445. SMB
Port Scan
๐ฎ๐ฉ
hermawan
2025-07-24 03:14:44
(1 year ago)
[Thu Jul 24 10:14:14.093891 2025] [security2:error] [pid 320860:tid 140495345936064] [client 103.180 ...
show more
[Thu Jul 24 10:14:14.093891 2025] [security2:error] [pid 320860:tid 140495345936064] [client 103.180.118.33:56662] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "myactivity.google.com" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "465"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: myactivity.google.com found within REQUEST_HEADERS:Referer: https://myactivity.google.com/ request_line = GET /images/Klimatologi/Prakiraan/03-Prakiraan-Bulanan/Prakiraan_Curah_Hujan_Bulanan/Prakiraan_Curah_Hujan_Bulanan_Provinsi_Jawa_Timur/2025/04_April_2025/03_Prediksi_Curah_Hujan_Bulan_AGUSTUS_2025_di_Provinsi_Jawa_Timur-Update_dari_Analisis_Bulan_April_2025.jpg HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/Klimatologi/Prakiraan/03-Prakiraan-Bulanan/Prakiraan_Curah_Hujan_Bulanan/Prakiraan_Curah_Hujan_Bulanan_Provinsi_Jawa_Timur/2025/04_April_2025/03_Prediksi_Cura
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-06-27 07:56:41
(1 year ago)
[Fri Jun 27 14:56:40.873912 2025] [security2:error] [pid 185567:tid 140353452603072] [client 103.180 ...
show more
[Fri Jun 27 14:56:40.873912 2025] [security2:error] [pid 185567:tid 140353452603072] [client 103.180.118.33:43984] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "350685531728" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.15.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "455"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: 350685531728 found within REQUEST_HEADERS:Referer: fbapp://350685531728/unknown request_line = GET /images/berita/2025/04/04-04-2025/Ucapan_Duka_Atas_Meninggalnya_Lestari-600.webp HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/berita/2025/04/04-04-2025/Ucapan_Duka_Atas_Meninggalnya_Lestari-600.webp"] [unique_id "aF5OuBETpvCh6jTgYZl7dAAATgo"], referer fbapp://350685531728/unknown [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[185578] [LlKyBMmTWrE] [aF5OuBETpvCh6jTgYZl7dAAATgo] keep_alive=[1] [2025-06-27 14:56:40.873917] [R:aF5OuBETpvCh6jTgYZl7dAAATgo] UA:'[FBAN/FB4
...
show less
Hacking
Web App Attack
Anonymous
2025-05-28 11:00:24
(1 year ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
๐ฏ๐ต
www.winos.me
2025-05-20 07:09:22
(1 year ago)
port scan
Port Scan
๐ฉ๐ช
botreporter
2025-05-07 04:29:47
(1 year ago)
botnet ignoring robots.txt
Bad Web Bot
๐ณ๐ฑ
Study Bitcoin ๐ค
2025-04-07 12:01:01
(1 year ago)
Port probe to tcp/445 (smb)
[srv135]
Port Scan
Hacking
๐จ๐ญ
cybsecaoccol
2025-03-01 13:44:43
(1 year ago)
unauthorized connection or malicious port scan attempted on tcp port 445 - sch
Port Scan
Hacking
๐ฎ๐ฉ
hermawan
2024-06-07 14:20:16
(2 years ago)
[Fri Jun 07 21:19:13.746366 2024] [security2:error] [pid 77143:tid 137429902165568] [client 103.180. ...
show more
[Fri Jun 07 21:19:13.746366 2024] [security2:error] [pid 77143:tid 137429902165568] [client 103.180.118.33:47264] [client 103.180.118.33] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "ru" at REQUEST_HEADERS:Accept-Language. [file "/etc/modsecurity/coreruleset-4.3.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "41"] [id "440001"] [msg "Seperti Ddos bahasa Rusia ada di ip vietnam 2.59.0.188 "] [data "Matched Data: ru found within REQUEST_HEADERS:Accept-Language: id-ID,id;q=0.9,ru-RU;q=0.8,ru;q=0.7,ar-AE;q=0.6,ar;q=0.5,en-US;q=0.4,en;q=0.3 request_line = GET /images/Klimatologi/Analisis/Peta_Zona_Musim/Peta_Zona_Musim_ZOM_di_Provinsi_Jawa_Timur_Tahun_1991-2020-v1.jpg HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/Klimatologi/Analisis/Peta_Zona_Musim/Peta_Zona_Musim_ZOM_di_Provinsi_Jawa_Timur_Tahun_1991-2020-v1.jpg"] [unique_id "ZmMW4YYgcweyLS_GqbJ3owAARic"], referer https://www.google.com/ [staklim-jatim.bmkg.go.id] [staklim
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2024-06-03 21:39:49
(2 years ago)
[Tue Jun 04 04:38:48.106951 2024] [security2:error] [pid 170615:tid 131246543865408] [client 103.180 ...
show more
[Tue Jun 04 04:38:48.106951 2024] [security2:error] [pid 170615:tid 131246543865408] [client 103.180.118.33:45752] [client 103.180.118.33] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "zh-CN" at REQUEST_HEADERS:Accept-Language. [file "/etc/modsecurity/coreruleset-4.3.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "41"] [id "440001"] [msg "Seperti Ddos bahasa Rusia ada di ip vietnam 2.59.0.188 "] [data "Matched Data: zh-CN found within REQUEST_HEADERS:Accept-Language: id-ID,id;q=0.9,en-US;q=0.8,en;q=0.7,zh-CN;q=0.6,zh;q=0.5 request_line = GET /index.php/profil/meteorologi/list-of-all-tags/penakar-hujan-manual-ombrometer-di-kabupaten-lamongan-provinsi-jawa-timur HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/list-of-all-tags/penakar-hujan-manual-ombrometer-di-kabupaten-lamongan-provinsi-jawa-timur"] [unique_id "Zl436MIk4bgTTqJb2Tv9-gAAoAs"], referer https://www.google.com/ [staklim-jatim.bmkg.go.id] [s
...
show less
Hacking
Web App Attack