JuicyJ
09 Jan 2023
Excessive crawling/scraping
Web App Attack
hermawan
15 Dec 2022
[Thu Dec 15 23:51:50.482841 2022] [-:error] [pid 564229:tid 140525418853952] [client 114.119.147.211 ... show more [Thu Dec 15 23:51:50.482841 2022] [-:error] [pid 564229:tid 140525418853952] [client 114.119.147.211:64189] [client 114.119.147.211] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-3.3.4/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (Linux; Android 7.0;) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; PetalBot;+https://webmaster.petalsearch.com/site/petalbot) request_line = GET /index.php/profil/meteorologi/list-all-categories/1106-agroklimatologi/kalender-tanam-katam-terpadu/kalender-tanam-katam-terpadu-nasional-indonesia/kalender-tanam-katam-terpadu-pulau-jawa/kalender-tanam-katam-terpadu-provinsi-jawa-timur/kalender-tanam-katam-terpadu..."] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/index.php/profil/meteorologi/
... show less
Hacking
Web App Attack
Anonymous
13 Dec 2022
Excessive crawling/scraping
Hacking
Brute-Force
NoAbuseforU
12 Dec 2022
"HTTP protocol compliance failed,Illegal host name"
Brute-Force
hermawan
11 Dec 2022
[Sun Dec 11 12:13:12.682043 2022] [-:error] [pid 477495:tid 140324633704000] [client 114.119.147.211 ... show more [Sun Dec 11 12:13:12.682043 2022] [-:error] [pid 477495:tid 140324633704000] [client 114.119.147.211:49683] [client 114.119.147.211] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-3.3.4/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (Linux; Android 7.0;) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; PetalBot;+https://webmaster.petalsearch.com/site/petalbot) request_line = GET /index.php/profil/meteorologi/prakiraan-meteorologi/3916-prakiraan-cuaca-jawa-timur-lusa-hari/555556570-prakiraan-cuaca-jawa-timur-lusa-hari-berlaku-mulai-kamis-02-agustus-2018-jam-07-00-wib-hingga-jumat-03-agustus-2018-jam-07-00-wib-update-selasa-31-juli-2018 HTTP..."] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/profil/met
... show less
Hacking
Web App Attack
Bytemark
09 Dec 2022
114.119.147.211 - - [09/Dec/2022:23:03:26 +0000] "GET /phpBB3/viewtopic.php?p=42659 HTTP/1.1" 404 71 ... show more 114.119.147.211 - - [09/Dec/2022:23:03:26 +0000] "GET /phpBB3/viewtopic.php?p=42659 HTTP/1.1" 404 7161 "https://www.distancelearningcentre.org.uk/phpBB3/viewtopic.php?f=60&t=10838&p=42697" "Mozilla/5.0 (Linux; Android 7.0;) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; PetalBot;+https://webmaster.petalsearch.com/site/petalbot)" show less
Brute-Force
Web App Attack
hermawan
08 Dec 2022
[Thu Dec 08 11:25:47.455224 2022] [-:error] [pid 407893:tid 140385140192832] [client 114.119.147.211 ... show more [Thu Dec 08 11:25:47.455224 2022] [-:error] [pid 407893:tid 140385140192832] [client 114.119.147.211:62701] [client 114.119.147.211] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-3.3.4/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (Linux; Android 7.0;) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; PetalBot;+https://webmaster.petalsearch.com/site/petalbot) request_line = GET /index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-hujan-bulanan/prakiraan-sifat-hujan-bulanan/555557078-prakiraan-sifat-hujan-bulan-april-tahun-2019-update-dari-analisis-bulan-januari-2019 HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-hujan-bulanan/prakiraan-sifat-hu
... show less
Hacking
Web App Attack
hermawan
07 Dec 2022
[Wed Dec 07 14:49:58.126843 2022] [-:error] [pid 67904:tid 140554834150976] [client 114.119.147.211: ... show more [Wed Dec 07 14:49:58.126843 2022] [-:error] [pid 67904:tid 140554834150976] [client 114.119.147.211:27749] [client 114.119.147.211] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-3.3.4/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (Linux; Android 7.0;) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; PetalBot;+https://webmaster.petalsearch.com/site/petalbot) request_line = GET /index.php/profil/meteorologi/list-all-categories/2779-agroklimatologi/kalender-tanam-katam-terpadu/kalender-tanam-katam-terpadu-nasional-indonesia/kalender-tanam-katam-terpadu-pulau-kalimantan/kalender-tanam-katam-terpadu-provinsi-kalimantan-barat/kalender-tanam-k..."] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/index.php/profil/meteorologi/l
... show less
Hacking
Web App Attack
mypatricks
07 Dec 2022
114.119.147.211 | Port: 36166 | DNS: ecs-114-119-147-211.compute.hwclouds-dns.com 2022-12-07T15:42:0 ... show more 114.119.147.211 | Port: 36166 | DNS: ecs-114-119-147-211.compute.hwclouds-dns.com 2022-12-07T15:42:09+08:00 Asia/Singapore | Fake Petalbot Detected | UA: Mozilla/5.0 (Linux; Android 7.0;) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; PetalBot;+https://webmaster.petalsearch.com/site/petalbot) HTTP/1.1 443 GET | URL: /malaysia/johor/skudai/edible-photo-sweet-cake/?limit=100 | Ref: https://xxxxxx/malaysia/johor/skudai/?limit=100 | Country: SG/Singapore/+08:00 775b9f7bcd636bd0-SIN/Singapore, Singapore 1 hits/0 secs Robots 2 show less
Web Spam
Blog Spam
Brute-Force
Exploited Host
Web App Attack
SCHAPPY
06 Dec 2022
Bad bot identified by user agent
Bad Web Bot
hermawan
06 Dec 2022
[Tue Dec 06 11:49:45.776904 2022] [-:error] [pid 107671:tid 139845592204864] [client 114.119.147.211 ... show more [Tue Dec 06 11:49:45.776904 2022] [-:error] [pid 107671:tid 139845592204864] [client 114.119.147.211:56747] [client 114.119.147.211] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-3.3.4/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (Linux; Android 7.0;) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; PetalBot;+https://webmaster.petalsearch.com/site/petalbot) request_line = GET /index.php/profil/meteorologi/list-all-categories/868-agroklimatologi/kalender-tanam-katam-terpadu/kalender-tanam-katam-terpadu-nasional-indonesia/kalender-tanam-katam-terpadu-pulau-jawa/kalender-tanam-katam-terpadu-provinsi-jawa-timur/kalender-tanam-katam-terpadu-..."] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/index.php/profil/meteorologi/
... show less
Hacking
Web App Attack
Bytemark
05 Dec 2022
114.119.147.211 - - [06/Dec/2022:01:09:54 +0000] "GET /phpBB3/viewtopic.php?p=39174 HTTP/1.1" 301 73 ... show more 114.119.147.211 - - [06/Dec/2022:01:09:54 +0000] "GET /phpBB3/viewtopic.php?p=39174 HTTP/1.1" 301 7398 "-" "Mozilla/5.0 (Linux; Android 7.0;) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; PetalBot;+https://webmaster.petalsearch.com/site/petalbot)" show less
Brute-Force
Web App Attack
Anonymous
05 Dec 2022
Web App Attack
vestibtech
04 Dec 2022
114.119.147.211 - - [04/Dec/2022:10:14:10 -0700] "GET / HTTP/1.1" 200 12565 "https://tbi.equipment/O ... show more 114.119.147.211 - - [04/Dec/2022:10:14:10 -0700] "GET / HTTP/1.1" 200 12565 "https://tbi.equipment/Overview-of-Posturography-Devices-for-TBI-and-Concussion-Management.html" "Mozilla/5.0 (Linux; Android 7.0;) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; PetalBot;+https://webmaster.petalsearch.com/site/petalbot)"
... show less
Web App Attack
AvonleaConsulting
03 Dec 2022
Attempt to use web contact page to send SPAM
Web Spam