๐ฎ๐ฉ
hermawan
2026-09-21 02:15:49
(3 days ago)
[Mon Sep 21 09:15:43.172229 2026] [security2:error] [pid 62364:tid 139825046775488] [client 121.101. ...
show more
[Mon Sep 21 09:15:43.172229 2026] [security2:error] [pid 62364:tid 139825046775488] [client 121.101.132.12:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.bmkg.go.id" at REQUEST_HEADERS:referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "601"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.bmkg.go.id found within REQUEST_HEADERS:referer: https://www.bmkg.go.id/ request_line = GET /index.php/profil/meteorologi/list-all-categories HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/list-all-categories"] [unique_id "arCTTzrFOarWIzK9y47lPgAAAAE"], referer https://www.bmkg.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[62421] [/8nC0/Q1y6Q] [arCTTzrFOarWIzK9y47lPgAAAAE] keep_alive=[0] [2026-09-21 09:15:43.172233] [R:arCTTzrFOarWIzK9y47lPgAAAAE] UA:'Mozilla/5.0 (Linux; Android 8; SM-S901B) AppleWebKit/537.36 (KHTML, like Gecko) Chr
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-09-20 02:45:27
(4 days ago)
[Sun Sep 20 09:45:24.222253 2026] [security2:error] [pid 269275:tid 140496718501568] [client 121.101 ...
show more
[Sun Sep 20 09:45:24.222253 2026] [security2:error] [pid 269275:tid 140496718501568] [client 121.101.132.12:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.bmkg.go.id" at REQUEST_HEADERS:referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "601"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.bmkg.go.id found within REQUEST_HEADERS:referer: https://www.bmkg.go.id/ request_line = GET /index.php/informasi-iklim/buletin-1/buletin-informasi-iklim-dan-lingkungan HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/informasi-iklim/buletin-1/buletin-informasi-iklim-dan-lingkungan"] [unique_id "aq9IxNN3ZlGa0OsI4CNnXwAAAsc"], referer https://www.bmkg.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[269320] [jBQUIGGDigo] [aq9IxNN3ZlGa0OsI4CNnXwAAAsc] keep_alive=[0] [2026-09-20 09:45:24.222257] [R:aq9IxNN3ZlGa0OsI4CNnXwAAAsc] UA:'Mozilla/5.0 (Linux; Android 8
...
show less
Email Spam
Hacking
Anonymous
2026-09-14 00:24:16
(1 week ago)
Web attack
Bad Web Bot
Web App Attack
๐บ๐ธ
SX Communications
2026-07-22 20:42:48
(2 months ago)
HTTP application-layer DoS / botnet traffic from 121.101.132.12: repeated high-cost dynamic page and ...
show more
HTTP application-layer DoS / botnet traffic from 121.101.132.12: repeated high-cost dynamic page and feed requests (profile/tag views, forums, tracker, RSS) at abusive rates via completed TCP/HTTPS. Likely compromised end-user host.
show less
DDoS Attack
Bad Web Bot
Exploited Host
๐บ๐ธ
SX Communications
2026-07-21 14:18:43
(2 months ago)
HTTP application-layer DoS / botnet traffic from 121.101.132.12: repeated high-cost dynamic page and ...
show more
HTTP application-layer DoS / botnet traffic from 121.101.132.12: repeated high-cost dynamic page and feed requests (profile/tag views, forums, tracker, RSS) at abusive rates via completed TCP/HTTPS. Likely compromised end-user host.
show less
DDoS Attack
Bad Web Bot
Exploited Host
๐ฎ๐ฉ
hermawan
2026-05-30 19:14:25
(3 months ago)
[Sun May 31 02:14:20.590362 2026] [authz_core:error] [pid 563000:tid 140573598627520] [client 121.10 ...
show more
[Sun May 31 02:14:20.590362 2026] [authz_core:error] [pid 563000:tid 140573598627520] [client 121.101.132.12:50060] AH01630: client denied by server configuration: /var/www/images/Klimatologi/Prakiraan/03-Prakiraan-Bulanan/Prakiraan_Sifat_Hujan_Bulanan/Prakiraan_Sifat_Hujan_Bulanan_Provinsi_Jawa_Timur/2026/01_Januari_2026/01_Prediksi_Sifat_Hujan_Bulan_MARET_2026_di_Provinsi_Jawa_Timur-Update_dari_Analisis_Bulan_Januari_2026.webp [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[563016] [qrC2xM1uFQg] [ahs3DIKTEUb02Z-kyIs2CAABFA8] keep_alive=[1] [2026-05-31 02:14:20.590366] [R:ahs3DIKTEUb02Z-kyIs2CAABFA8] UA:'Mozilla/5.0 (iPhone; CPU iPhone OS 17_4 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/124.0.6367.88 Mobile/15E148 Safari/604.1' Host:'staklim-jatim.bmkg.go.id:443' ACCEPT:'*/*' Accept-Encoding:'gzip, deflate, br Accept-Language:'en-US,en;q=0.8
...
show less
Email Spam
Hacking
๐น๐ท
Threat.live
2026-05-20 23:05:04
(4 months ago)
Suspicious Connection Attempts
Brute-Force
๐บ๐ธ
Cyber Crusader
2026-05-12 14:50:17
(4 months ago)
Hundreds of Attempts (at least) to Connect to and Access Firewall Ports
Port Scan
Hacking
Brute-Force
๐บ๐ธ
kosada.com
2026-04-22 17:50:32
(5 months ago)
Web bot: DDoS
DDoS Attack
Bad Web Bot
๐ฉ๐ช
femboy.cat
2026-04-02 14:58:22
(5 months ago)
Port scan to tcp/139 from 121.101.132.12
Brute-Force
๐จ๐ฆ
TechnoSolutions CL
2026-03-30 23:43:51
(5 months ago)
2026-03-30T23:43:47.673809+00:00 lb01 kernel: - [16526333.492869] PORTSCAN_DROP: IN=eth0 OUT= MAC=3a ...
show more
2026-03-30T23:43:47.673809+00:00 lb01 kernel: - [16526333.492869] PORTSCAN_DROP: IN=eth0 OUT= MAC=3a:07:4f:e8:59:e5:fe:00:00:00:01:01:08:00 SRC=121.101.132.12 DST=159.203.62.209 LEN=48 TOS=0x08 PREC=0x20 TTL=109 ID=750 DF PROTO=TCP SPT=60245 DPT=139 WINDOW=8192 RES=0x00 SYN URGP=0
2026-03-30T23:43:50.681845+00:00 lb01 kernel: - [16526336.500901] PORTSCAN_DROP: IN=eth0 OUT= MAC=3a:07:4f:e8:59:e5:fe:00:00:00:01:01:08:00 SRC=121.101.132.12 DST=159.203.62.209 LEN=48 TOS=0x08 PREC=0x20 TTL=109 ID=1679 DF PROTO=TCP SPT=60245 DPT=139 WINDOW=8192 RES=0x00 SYN URGP=0
...
show less
Port Scan
Brute-Force
Bad Web Bot
๐จ๐ญ
cybsecaoccol
2026-02-21 15:37:09
(7 months ago)
multiple malicious connection attempts on tcp port 139 - sch
DDoS Attack
Port Scan
Hacking
Brute-Force
Anonymous
2026-02-01 15:50:55
(7 months ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
๐บ๐ธ
Cyber Crusader
2025-12-19 09:05:42
(9 months ago)
Hundreds of Attempts (at least) to Connect to and Access Firewall Ports
Port Scan
Hacking
Brute-Force
๐ซ๐ท
oonux.net
2025-12-16 16:27:38
(9 months ago)
RouterOS: Scanning detected TCP 121.101.132.12:51642 > x.x.x.x:139
Port Scan