🇮🇩
RemyLebeau
2026-08-24 07:16:22
(2 weeks ago)
Web App Attack
Port Scan
🇺🇸
kosada.com
2026-07-20 10:30:17
(1 month ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
🇮🇩
hermawan
2025-02-26 04:32:52
(1 year ago)
[Wed Feb 26 11:31:18.005065 2025] [security2:error] [pid 122009:tid 139762840696512] [client 125.166 ...
show more
[Wed Feb 26 11:31:18.005065 2025] [security2:error] [pid 122009:tid 139762840696512] [client 125.166.0.235:28394] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "ms" at REQUEST_HEADERS:Accept-Language. [file "/etc/modsecurity/coreruleset-4.10.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "189"] [id "440001"] [msg "Seperti Ddos bahasa Rusia ada di ip vietnam 2.59.0.188 "] [data "Matched Data: ms found within REQUEST_HEADERS:Accept-Language: en-US,en;q=0.9,id;q=0.8,ms;q=0.7 request_line = GET /index.php/profil/meteorologi/list-of-all-tags/gempa-terkini HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/list-of-all-tags/gempa-terkini"] [unique_id "Z76ZFo6TIiIc4LxTvKCKBAAAORA"], referer https://www.google.com/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[122026] [JtNKCwzOlkI] [Z76ZFo6TIiIc4LxTvKCKBAAAORA] keep_alive=[1] [2025-02-26 11:31:18.005070] [R:Z76ZFo6TIiIc4LxTvKCKBAAAORA] UA:'Mozilla/5.0
...
show less
Hacking
Web App Attack
🇮🇩
hermawan
2025-02-25 18:42:55
(1 year ago)
[Wed Feb 26 01:42:41.256039 2025] [security2:error] [pid 293303:tid 140576645342912] [client 125.166 ...
show more
[Wed Feb 26 01:42:41.256039 2025] [security2:error] [pid 293303:tid 140576645342912] [client 125.166.0.235:8018] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "ms" at REQUEST_HEADERS:Accept-Language. [file "/etc/modsecurity/coreruleset-4.10.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "189"] [id "440001"] [msg "Seperti Ddos bahasa Rusia ada di ip vietnam 2.59.0.188 "] [data "Matched Data: ms found within REQUEST_HEADERS:Accept-Language: en-US,en;q=0.9,id;q=0.8,ms;q=0.7 request_line = GET /index.php/profil/meteorologi/list-of-all-tags/gempa-terkini HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/list-of-all-tags/gempa-terkini"] [unique_id "Z74PIeG256V4xAXsE6euIAABdjQ"], referer https://www.google.com/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[293356] [ZmHHz/NFAig] [Z74PIeG256V4xAXsE6euIAABdjQ] keep_alive=[1] [2025-02-26 01:42:41.256045] [R:Z74PIeG256V4xAXsE6euIAABdjQ] UA:'Mozilla/5.0
...
show less
Hacking
Web App Attack
🇮🇩
hermawan
2023-12-11 11:33:49
(2 years ago)
[Mon Dec 11 18:33:46.036728 2023] [security2:error] [pid 505053:tid 140285907547712] [client 125.166 ...
show more
[Mon Dec 11 18:33:46.036728 2023] [security2:error] [pid 505053:tid 140285907547712] [client 125.166.0.235:18928] [client 125.166.0.235] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "X-Requested-With" at REQUEST_HEADERS_NAMES:X-Requested-With. [file "/etc/modsecurity/coreruleset-3.3.5/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "10"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: X-Requested-With found within REQUEST_HEADERS_NAMES:X-Requested-With: X-Requested-With request_line = GET /index.php/profil/meteorologi/list-of-all-tags/prakiraan-cuaca-ponorogo HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/list-of-all-tags/prakiraan-cuaca-ponorogo"] [unique_id "ZXbzmm0rdi_cxA2MF5NL0wAAiz8"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[505117] [eq2NTjr4ruU] [ZXbzmm0rdi_cxA2MF5NL0wAAiz8] keep_alive=[1] [2023-12-11 18:33:46.036732] [R:ZXbzmm0rdi_cxA2
...
show less
Hacking
Web App Attack
🇮🇩
hermawan
2022-12-05 05:40:56
(3 years ago)
[Mon Dec 05 16:38:02.334676 2022] [-:error] [pid 294695:tid 140040208324160] [client 125.166.0.235:2 ...
show more
[Mon Dec 05 16:38:02.334676 2022] [-:error] [pid 294695:tid 140040208324160] [client 125.166.0.235:27811] [client 125.166.0.235] ModSecurity: Access denied with code 403 (phase 1). Match of "pm www.google.com myactivity.google.com googleweblight.com applebot iPhone bingbot https://yandex.com/ https://www.google.com.tw facebookbot https://www.ecosia.org/ https://duckduckgo.com/ facebookcatalog facebookexternalhit Googlebot/2.1 http://www.googl ..." against "REQUEST_HEADERS:Referer" required. [file "/etc/modsecurity/coreruleset-3.3.4/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "59"] [id "440067"] [msg "BAD Referer"] [data "Matched Data: karangploso.jatim.bmkg.go.id found within REQUEST_HEADERS:Referer: https://www.cakapsemuanya.one/ request_line = GET /images/Klimatologi/Prakiraan/03-Prakiraan-Bulanan/Prakiraan_Curah_Hujan_Bulanan/Prakiraan_Curah_Hujan_Bulanan_Provinsi_Jawa_Timur/2020/08/02-Prakiraan_Curah_Hujan_Bulan_NOVEMBER_Tahun_2020_di_Provinsi_Jawa_Timur-Update_dari_Analisi
...
show less
Hacking
Web App Attack
🇿🇦
IrisFlower
2022-02-28 12:54:47
(4 years ago)
Unauthorized connection attempt detected from IP address 125.166.0.235 to port 23 [J]
Port Scan
Hacking
🇿🇦
IrisFlower
2022-02-26 19:12:10
(4 years ago)
Unauthorized connection attempt detected from IP address 125.166.0.235 to port 23 [J]
Port Scan
Hacking
🇿🇦
IrisFlower
2022-02-26 08:11:29
(4 years ago)
Unauthorized connection attempt detected from IP address 125.166.0.235 to port 80 [J]
Port Scan
Hacking
🇿🇦
IrisFlower
2022-02-25 16:47:48
(4 years ago)
Unauthorized connection attempt detected from IP address 125.166.0.235 to port 8080 [J]
Port Scan
Hacking
🇩🇪
_ArminS_
2022-02-24 12:08:24
(4 years ago)
SP-Scan 27159:23 detected 2022.02.24 13:08:24
blocked until 2022.04.15 07:11:11
Port Scan