findlab
2025-05-23 19:00:02
(1 month ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
hermawan
2025-05-23 13:08:10
(1 month ago)
[Fri May 23 19:48:59.231693 2025] [security2:error] [pid 257301:tid 140473998948032] [client 13.83.1 ... show more [Fri May 23 19:48:59.231693 2025] [security2:error] [pid 257301:tid 140473998948032] [client 13.83.167.134:17045] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /robots.txt HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/robots.txt"] [unique_id "aDBuu51aTSa9br0QAp0jKQACHxM"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[257342] [yTudBVV2OcA] [aDBuu51aTSa9br0QAp0jKQACHxM] keep_alive=[1] [2025-05-23 19:48:59.231701] [R:aDBuu51aTSa9br0QAp0jKQACHxM] UA:'Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.co
... show less
Hacking
Web App Attack
hermawan
2025-05-23 06:23:36
(1 month ago)
[Fri May 23 12:43:49.207597 2025] [security2:error] [pid 44924:tid 140474568046272] [client 13.83.16 ... show more [Fri May 23 12:43:49.207597 2025] [security2:error] [pid 44924:tid 140474568046272] [client 13.83.167.134:16430] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /robots.txt HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/robots.txt"] [unique_id "aDALFayx9TfRD-BhvJJz3gABgAA"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[44925] [liYZFT911c4] [aDALFayx9TfRD-BhvJJz3gABgAA] keep_alive=[1] [2025-05-23 12:43:49.207631] [R:aDALFayx9TfRD-BhvJJz3gABgAA] UA:'Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/
... show less
Hacking
Web App Attack
hermawan
2025-05-23 03:45:27
(1 month ago)
[Fri May 23 09:55:27.044849 2025] [security2:error] [pid 16266:tid 140123780875968] [client 13.83.16 ... show more [Fri May 23 09:55:27.044849 2025] [security2:error] [pid 16266:tid 140123780875968] [client 13.83.167.134:8873] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /index.php/informasi-iklim/infografis-iklim/infografis-bulanan/infografis-bulanan-buletin/555561537-infografis-bulanan-prakiraan-hujan-bulan-desember-tahun-2024-januari-februari-2025-update-dari-analisis-bulan-september-tahun-2024-di-provinsi-jawa-timur HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/informasi-iklim/infografis-iklim/infografis-bulanan/infografis-bulanan-buletin/555561537-infogra
... show less
Hacking
Web App Attack
MAGIC
2025-05-23 00:11:41
(1 month ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
hermawan
2025-05-21 14:22:57
(1 month ago)
[Wed May 21 21:17:40.162500 2025] [security2:error] [pid 120517:tid 140248102201024] [client 13.83.1 ... show more [Wed May 21 21:17:40.162500 2025] [security2:error] [pid 120517:tid 140248102201024] [client 13.83.167.134:38086] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /index.php/prakiraan-musim/4311-prakiraan-musim-kemarau/prakiraan-awal-musim-kemarau/prakiraan-awal-musim-kemarau-di-propinsi-jawa-timur/prediksi-6-bulanan-awal-musim-kemarau-tahun-2025-zona-musim-di-provinsi-jawa-timur/555561823-prediksi-6-bulanan-awal-musim-kemarau-tahun-2025-zona-musim-di-provinsi-jawa-timur HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/prakiraan-musim/4311-prakiraan-musi
... show less
Hacking
Web App Attack
hermawan
2025-05-21 00:05:15
(1 month ago)
[Wed May 21 07:04:00.240463 2025] [security2:error] [pid 137253:tid 140382502311616] [client 13.83.1 ... show more [Wed May 21 07:04:00.240463 2025] [security2:error] [pid 137253:tid 140382502311616] [client 13.83.167.134:56345] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /index.php/prediksi-iklim/prediksi-bulanan/curah-hujan/3-bulan-ke-depan/555561856-prediksi-bulanan-curah-hujan-bulan-mei-tahun-2025-update-dari-analisis-bulan-februari-tahun-2025-di-provinsi-jawa-timur HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/prediksi-iklim/prediksi-bulanan/curah-hujan/3-bulan-ke-depan/555561856-prediksi-bulanan-curah-hujan-bulan-mei-tahun-2025-update-dari-analisis-bula
... show less
Hacking
Web App Attack
hermawan
2025-05-20 14:55:39
(1 month ago)
[Tue May 20 20:56:52.275399 2025] [security2:error] [pid 35470:tid 140312757524160] [client 13.83.16 ... show more [Tue May 20 20:56:52.275399 2025] [security2:error] [pid 35470:tid 140312757524160] [client 13.83.167.134:24809] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /index.php/buku/479-buku-edisi-setiap-1-bulan-sekali/555558936-e-buletin-prakiraan-sifat-dan-curah-hujan-di-kabupaten-pamekasan HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/buku/479-buku-edisi-setiap-1-bulan-sekali/555558936-e-buletin-prakiraan-sifat-dan-curah-hujan-di-kabupaten-pamekasan"] [unique_id "aCyKJGOcfJJ5ObX7q1a8gQAAjgw"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[3
... show less
Hacking
Web App Attack
hermawan
2025-05-19 03:47:17
(1 month ago)
[Mon May 19 09:33:56.773637 2025] [security2:error] [pid 617045:tid 140017389160128] [client 13.83.1 ... show more [Mon May 19 09:33:56.773637 2025] [security2:error] [pid 617045:tid 140017389160128] [client 13.83.167.134:10287] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /index.php/profil/meteorologi/list-of-all-tags/prakiraan-klimatologi HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/list-of-all-tags/prakiraan-klimatologi"] [unique_id "aCqYlFvZJEIPdiL_smZzBQABFRk"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[617071] [1yex9mvkp0Q] [aCqYlFvZJEIPdiL_smZzBQABFRk] keep_alive=[1] [2025-05-19 09:33:56.773644] [R:aCqYlFvZJEIPdiL_smZ
... show less
Hacking
Web App Attack
hermawan
2025-05-17 07:47:17
(2 months ago)
[Sat May 17 14:46:16.532354 2025] [security2:error] [pid 191813:tid 140054579971776] [client 13.83.1 ... show more [Sat May 17 14:46:16.532354 2025] [security2:error] [pid 191813:tid 140054579971776] [client 13.83.167.134:26422] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-curah-hujan-bulanan/555560632-prakiraan-bulanan-curah-hujan-bulan-januari-tahun-2024-update-dari-analisis-bulan-november-tahun-2023-di-provinsi-jawa-timur HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-curah-hujan-bulanan/555560632-prakiraan-bulanan-curah-hujan-bulan-januari-tahun-2024-update-dari-an
... show less
Hacking
Web App Attack
MAGIC
2025-05-16 03:06:33
(2 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
hermawan
2025-05-15 23:11:27
(2 months ago)
[Fri May 16 06:10:03.555996 2025] [security2:error] [pid 56981:tid 140683184608960] [client 13.83.16 ... show more [Fri May 16 06:10:03.555996 2025] [security2:error] [pid 56981:tid 140683184608960] [client 13.83.167.134:44609] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /robots.txt HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/robots.txt"] [unique_id "aCZ0SwwZqlXStrxgTTFdQAAA5hU"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[57049] [2ewCxGxHQc4] [aCZ0SwwZqlXStrxgTTFdQAAA5hU] keep_alive=[1] [2025-05-16 06:10:03.556000] [R:aCZ0SwwZqlXStrxgTTFdQAAA5hU] UA:'Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/
... show less
Hacking
Web App Attack
Anonymous
2025-05-14 09:59:17
(2 months ago)
Action: Block, Reason: DDOS attack detected
DDoS Attack
hermawan
2025-05-14 05:56:48
(2 months ago)
[Wed May 14 09:57:38.514923 2025] [security2:error] [pid 474952:tid 139992735102656] [client 13.83.1 ... show more [Wed May 14 09:57:38.514923 2025] [security2:error] [pid 474952:tid 139992735102656] [client 13.83.167.134:34202] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-bulanan-tingkat-ketersediaan-air-bagi-tanaman/555561479-prakiraan-bulanan-tingkat-ketersediaan-air-bagi-tanaman-di-jawa-timur-untuk-bulan-januari-tahun-2025-update-dari-analisis-bulan-september-tahun-2024 HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-bulanan-tingkat-ketersediaan-air-bagi-tanama
... show less
Hacking
Web App Attack
hermawan
2025-05-13 14:59:56
(2 months ago)
[Tue May 13 21:39:29.431896 2025] [security2:error] [pid 135958:tid 139995794810560] [client 13.83.1 ... show more [Tue May 13 21:39:29.431896 2025] [security2:error] [pid 135958:tid 139995794810560] [client 13.83.167.134:19497] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /robots.txt HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/robots.txt"] [unique_id "aCNZoR_FZtRT07SsWrbvBwACIBM"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[135979] [7HFkZl3lMUE] [aCNZoR_FZtRT07SsWrbvBwACIBM] keep_alive=[1] [2025-05-13 21:39:29.431902] [R:aCNZoR_FZtRT07SsWrbvBwACIBM] UA:'Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.co
... show less
Hacking
Web App Attack