hermawan
2025-05-31 17:00:45
(1 month ago)
[Sat May 31 23:58:00.896098 2025] [security2:error] [pid 76875:tid 139726186051264] [client 13.83.16 ... show more [Sat May 31 23:58:00.896098 2025] [security2:error] [pid 76875:tid 139726186051264] [client 13.83.167.134:26723] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /robots.txt HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/robots.txt"] [unique_id "aDs1GBdC0C9AoLQ3EEoD4QAA1Qs"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[76887] [EPrvbqm1eKk] [aDs1GBdC0C9AoLQ3EEoD4QAA1Qs] keep_alive=[1] [2025-05-31 23:58:00.896104] [R:aDs1GBdC0C9AoLQ3EEoD4QAA1Qs] UA:'Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/
... show less
Hacking
Web App Attack
MPL
2025-05-30 04:54:45
(1 month ago)
tcp/443 (2 or more attempts)
Port Scan
MPL
2025-05-30 04:54:45
(1 month ago)
tcp/443 (2 or more attempts)
Port Scan
hermawan
2025-05-29 16:36:17
(1 month ago)
[Thu May 29 23:31:46.756353 2025] [security2:error] [pid 6093:tid 139910037014208] [client 13.83.167 ... show more [Thu May 29 23:31:46.756353 2025] [security2:error] [pid 6093:tid 139910037014208] [client 13.83.167.134:39959] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /robots.txt HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/robots.txt"] [unique_id "aDiL8iz0BUJGGG9QsvPHZwABFhs"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[6122] [/+tt1VAyNbs] [aDiL8iz0BUJGGG9QsvPHZwABFhs] keep_alive=[1] [2025-05-29 23:31:46.756367] [R:aDiL8iz0BUJGGG9QsvPHZwABFhs] UA:'Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bo
... show less
Hacking
Web App Attack
hermawan
2025-05-28 14:17:23
(1 month ago)
[Wed May 28 21:16:36.308456 2025] [security2:error] [pid 387776:tid 139775917860544] [client 13.83.1 ... show more [Wed May 28 21:16:36.308456 2025] [security2:error] [pid 387776:tid 139775917860544] [client 13.83.167.134:20324] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /robots.txt HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/robots.txt"] [unique_id "aDcaxGvPrOofT4w820HZlAAAjRU"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[387798] [guYq1CqRnkc] [aDcaxGvPrOofT4w820HZlAAAjRU] keep_alive=[1] [2025-05-28 21:16:36.308463] [R:aDcaxGvPrOofT4w820HZlAAAjRU] UA:'Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.co
... show less
Hacking
Web App Attack
MAGIC
2025-05-28 03:00:51
(1 month ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
hermawan
2025-05-28 02:26:01
(1 month ago)
[Wed May 28 08:52:18.593287 2025] [security2:error] [pid 18810:tid 140018440984256] [client 13.83.16 ... show more [Wed May 28 08:52:18.593287 2025] [security2:error] [pid 18810:tid 140018440984256] [client 13.83.167.134:48406] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /robots.txt HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/robots.txt"] [unique_id "aDZsUqFpzw-dQGb4hSkUiwAByQQ"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[18815] [wztcbjBKY+g] [aDZsUqFpzw-dQGb4hSkUiwAByQQ] keep_alive=[1] [2025-05-28 08:52:18.593293] [R:aDZsUqFpzw-dQGb4hSkUiwAByQQ] UA:'Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/
... show less
Hacking
Web App Attack
hermawan
2025-05-27 21:54:16
(1 month ago)
[Wed May 28 04:51:25.967981 2025] [security2:error] [pid 75577:tid 140576209905344] [client 13.83.16 ... show more [Wed May 28 04:51:25.967981 2025] [security2:error] [pid 75577:tid 140576209905344] [client 13.83.167.134:49165] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /robots.txt HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/robots.txt"] [unique_id "aDYz3a6NpqA9ci4HNatD1AAAAh0"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[75607] [lbrqEL2rDZk] [aDYz3a6NpqA9ci4HNatD1AAAAh0] keep_alive=[1] [2025-05-28 04:51:25.967987] [R:aDYz3a6NpqA9ci4HNatD1AAAAh0] UA:'Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/
... show less
Hacking
Web App Attack
hermawan
2025-05-27 15:28:13
(1 month ago)
[Tue May 27 22:27:42.547251 2025] [security2:error] [pid 134930:tid 140061294192320] [client 13.83.1 ... show more [Tue May 27 22:27:42.547251 2025] [security2:error] [pid 134930:tid 140061294192320] [client 13.83.167.134:4250] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /robots.txt HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/robots.txt"] [unique_id "aDXZ7uzy4ktHW50x_b7eowAAyQE"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[134932] [ShedtMcS8a4] [aDXZ7uzy4ktHW50x_b7eowAAyQE] keep_alive=[1] [2025-05-27 22:27:42.547258] [R:aDXZ7uzy4ktHW50x_b7eowAAyQE] UA:'Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com
... show less
Hacking
Web App Attack
hermawan
2025-05-27 11:06:35
(1 month ago)
[Tue May 27 18:01:45.398624 2025] [security2:error] [pid 284104:tid 140241663874752] [client 13.83.1 ... show more [Tue May 27 18:01:45.398624 2025] [security2:error] [pid 284104:tid 140241663874752] [client 13.83.167.134:31567] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /robots.txt HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/robots.txt"] [unique_id "aDWbmQYvPkbdnYeV7K0b4gAAkRE"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[284122] [r3B+/cOZIes] [aDWbmQYvPkbdnYeV7K0b4gAAkRE] keep_alive=[1] [2025-05-27 18:01:45.398629] [R:aDWbmQYvPkbdnYeV7K0b4gAAkRE] UA:'Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.co
... show less
Hacking
Web App Attack
hermawan
2025-05-27 10:34:35
(1 month ago)
[Tue May 27 17:32:03.383231 2025] [security2:error] [pid 275949:tid 140241743603392] [client 13.83.1 ... show more [Tue May 27 17:32:03.383231 2025] [security2:error] [pid 275949:tid 140241743603392] [client 13.83.167.134:40567] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET / HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/"] [unique_id "aDWUo34zczZDzE4-JqPrzwABAAg"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[275958] [oBNHk0MQiOo] [aDWUo34zczZDzE4-JqPrzwABAAg] keep_alive=[1] [2025-05-27 17:32:03.383235] [R:aDWUo34zczZDzE4-JqPrzwABAAg] UA:'Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot' Host:'staklim
... show less
Hacking
Web App Attack
hermawan
2025-05-27 03:21:20
(1 month ago)
[Tue May 27 08:57:27.039145 2025] [security2:error] [pid 35061:tid 140241884145344] [client 13.83.16 ... show more [Tue May 27 08:57:27.039145 2025] [security2:error] [pid 35061:tid 140241884145344] [client 13.83.167.134:41144] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /robots.txt HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/robots.txt"] [unique_id "aDUcBz18ZumdE5wsMAqarQAAyAQ"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[35066] [PB/nYowmW+4] [aDUcBz18ZumdE5wsMAqarQAAyAQ] keep_alive=[1] [2025-05-27 08:57:27.039150] [R:aDUcBz18ZumdE5wsMAqarQAAyAQ] UA:'Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/
... show less
Hacking
Web App Attack
hermawan
2025-05-26 08:58:48
(1 month ago)
[Mon May 26 15:58:44.226184 2025] [security2:error] [pid 6251:tid 139690345690816] [client 13.83.167 ... show more [Mon May 26 15:58:44.226184 2025] [security2:error] [pid 6251:tid 139690345690816] [client 13.83.167.134:33974] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /robots.txt HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/robots.txt"] [unique_id "aDQtRN5SSGdbXmt74hUuMAAB1xM"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[6273] [M/6xJ96EJpE] [aDQtRN5SSGdbXmt74hUuMAAB1xM] keep_alive=[1] [2025-05-26 15:58:44.226223] [R:aDQtRN5SSGdbXmt74hUuMAAB1xM] UA:'Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bo
... show less
Hacking
Web App Attack
hermawan
2025-05-25 10:10:03
(1 month ago)
[Sun May 25 16:42:55.696637 2025] [security2:error] [pid 39659:tid 140499004061376] [client 13.83.16 ... show more [Sun May 25 16:42:55.696637 2025] [security2:error] [pid 39659:tid 140499004061376] [client 13.83.167.134:51392] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /robots.txt HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/robots.txt"] [unique_id "aDLmHxzXYcto5aXZ2cqy6AAA1QE"] [staklim-malang.info] [staklim-malang.info] top=[39661] [IjHmp+o9/qY] [aDLmHxzXYcto5aXZ2cqy6AAA1QE] keep_alive=[1] [2025-05-25 16:42:55.696643] [R:aDLmHxzXYcto5aXZ2cqy6AAA1QE] UA:'Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot' Host:'stak
... show less
Hacking
Web App Attack
hermawan
2025-05-24 15:24:28
(1 month ago)
[Sat May 24 20:37:27.443506 2025] [security2:error] [pid 87125:tid 140105955067584] [client 13.83.16 ... show more [Sat May 24 20:37:27.443506 2025] [security2:error] [pid 87125:tid 140105955067584] [client 13.83.167.134:50656] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /robots.txt HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/robots.txt"] [unique_id "aDHLl7JYZcKOTIipUfSq5gABChM"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[87145] [T5zM0PlVNBs] [aDHLl7JYZcKOTIipUfSq5gABChM] keep_alive=[1] [2025-05-24 20:37:27.443512] [R:aDHLl7JYZcKOTIipUfSq5gABChM] UA:'Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/
... show less
Hacking
Web App Attack