๐จ๐ฆ
1gz
2026-07-13 02:51:14
(2 months ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /english/is-bitcoin-on-the-brink-of-a-new-bear-market/892954/
UA: Mozilla/5.0 (Linux; U; Android 12; NOH-NX9 Build/HUAWEINOH-N29; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/114.0.5735.196 Mobile Safari/537.36 OPR/99.2.2254.731
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฎ๐ฉ
sockominfo
2026-06-24 05:00:52
(3 months ago)
User login to application from malicious IP 141.0.8.142.. Threat Score: 3.6/10 (LOW). Confidence: 30 ...
show more
User login to application from malicious IP 141.0.8.142.. Threat Score: 3.6/10 (LOW). Confidence: 30%. CVSS v3.1: 0/10 (None). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:N. Bayesian Probability: 40%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-06-24 04:00:52
(3 months ago)
User login to application from malicious IP 141.0.8.142.. Threat Score: 3.7/10 (LOW). Confidence: 30 ...
show more
User login to application from malicious IP 141.0.8.142.. Threat Score: 3.7/10 (LOW). Confidence: 30%. CVSS v3.1: 0/10 (None). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:N. Bayesian Probability: 40%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-06-24 02:00:16
(3 months ago)
User login to application from malicious IP 141.0.8.142.. Threat Score: 0/10 (INFORMATIONAL). Report ...
show more
User login to application from malicious IP 141.0.8.142.. Threat Score: 0/10 (INFORMATIONAL). Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-04-17 06:01:25
(5 months ago)
SIMASN Account Signin from Blacklisted IP.. Threat Score: 7.8/10 (HIGH). Confidence: 60%. CVSS v3.1: ...
show more
SIMASN Account Signin from Blacklisted IP.. Threat Score: 7.8/10 (HIGH). Confidence: 60%. CVSS v3.1: 7.3/10 (High). CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L. Bayesian Probability: 93%. MITRE ATT&CK: T1071 (Application Layer Protocol). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-04-17 05:01:33
(5 months ago)
SIMASN Account Signin from Blacklisted IP.. Threat Score: 7.9/10 (HIGH). Confidence: 60%. CVSS v3.1: ...
show more
SIMASN Account Signin from Blacklisted IP.. Threat Score: 7.9/10 (HIGH). Confidence: 60%. CVSS v3.1: 7.3/10 (High). CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L. Bayesian Probability: 93%. MITRE ATT&CK: T1071 (Application Layer Protocol). Tactic: TA0001. Freshness: Very Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-11-13 05:57:34
(10 months ago)
[Thu Nov 13 12:57:03.134470 2025] [security2:error] [pid 1030093:tid 140632773347008] [client 141.0. ...
show more
[Thu Nov 13 12:57:03.134470 2025] [security2:error] [pid 1030093:tid 140632773347008] [client 141.0.8.142:36886] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "X-Forwarded-For" at REQUEST_HEADERS_NAMES:X-Forwarded-For. [file "/etc/modsecurity/coreruleset-4.20.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "394"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: X-Forwarded-For found within REQUEST_HEADERS_NAMES:X-Forwarded-For: X-Forwarded-For request_line = GET /index.php/prediksi-iklim/prediksi-bulanan/curah-hujan/3-bulan-ke-depan/555562275-prediksi-bulanan-curah-hujan-bulan-november-tahun-2025-update-dari-analisis-bulan-juli-tahun-2025-di-provinsi-jawa-timur HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/prediksi-iklim/prediksi-bulanan/curah-hujan/3-bulan-ke-depan/555562275-prediksi-bulanan-curah-hujan-bulan-november-tahun-2025-update-dari-analisis-bulan-juli-tahun-2025-di-pr
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-04-10 07:15:14
(1 year ago)
[Thu Apr 10 14:14:15.983112 2025] [security2:error] [pid 738514:tid 140595913795264] [client 141.0.8 ...
show more
[Thu Apr 10 14:14:15.983112 2025] [security2:error] [pid 738514:tid 140595913795264] [client 141.0.8.142:56722] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "X-Forwarded-For" at REQUEST_HEADERS_NAMES:X-Forwarded-For. [file "/etc/modsecurity/coreruleset-4.10.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "349"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: X-Forwarded-For found within REQUEST_HEADERS_NAMES:X-Forwarded-For: X-Forwarded-For request_line = GET /index.php/profil/meteorologi/list-all-categories/4267-konferensi-pers/rilis-prediksi-musim-hujan-2024-2025-di-provinsi-jawa-timur HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/index.php/profil/meteorologi/list-all-categories/4267-konferensi-pers/rilis-prediksi-musim-hujan-2024-2025-di-provinsi-jawa-timur"] [unique_id "Z_dvxxXjUNkurc4wYlMIJAAAAKI"], referer https://www.google.com/ [staklim-malang.info] [staklim-malang.info] top=[738600
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-04-08 14:30:22
(1 year ago)
[Tue Apr 08 21:30:21.650367 2025] [security2:error] [pid 285703:tid 140069310539456] [client 141.0.8 ...
show more
[Tue Apr 08 21:30:21.650367 2025] [security2:error] [pid 285703:tid 140069310539456] [client 141.0.8.142:52330] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "X-Forwarded-For" at REQUEST_HEADERS_NAMES:X-Forwarded-For. [file "/etc/modsecurity/coreruleset-4.10.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "349"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: X-Forwarded-For found within REQUEST_HEADERS_NAMES:X-Forwarded-For: X-Forwarded-For request_line = GET /images/Klimatologi/Analisis/Peta_Zona_Musim/Peta_Zona_Musim_ZOM_di_Provinsi_Jawa_Timur_Tahun_1991-2020-v1.webp HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/images/Klimatologi/Analisis/Peta_Zona_Musim/Peta_Zona_Musim_ZOM_di_Provinsi_Jawa_Timur_Tahun_1991-2020-v1.webp"] [unique_id "Z_Uy_f8lTyWtDkE5LhZyBgAAAAs"], referer https://www.google.com/ [staklim-malang.info] [staklim-malang.info] top=[285766] [KIVNMf3q2Ew] [Z_Uy_f8lTyWtDkE5LhZyB
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2024-11-27 20:11:20
(1 year ago)
[Wed Nov 27 19:53:26.239224 2024] [security2:error] [pid 540184:tid 129550683981504] [client 141.0.8 ...
show more
[Wed Nov 27 19:53:26.239224 2024] [security2:error] [pid 540184:tid 129550683981504] [client 141.0.8.142:32844] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "X-Forwarded-For" at REQUEST_HEADERS_NAMES:X-Forwarded-For. [file "/etc/modsecurity/coreruleset-4.8.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "190"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: X-Forwarded-For found within REQUEST_HEADERS_NAMES:X-Forwarded-For: X-Forwarded-For request_line = GET /index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-curah-hujan-bulanan/3-bulan-ke-depan/555561391-prakiraan-bulanan-curah-hujan-bulan-desember-tahun-2024-update-dari-analisis-bulan-agustus-tahun-2024-di-provinsi-jawa-timur HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-curah-hujan-bulanan/3-bulan-ke-depan/555561391-prakiraan-bulanan-curah-hujan-bulan-desember-tahun-2024-updat
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2024-08-01 02:00:30
(2 years ago)
[Thu Aug 01 09:00:22.999508 2024] [security2:error] [pid 421667:tid 134961338254912] [client 141.0.8 ...
show more
[Thu Aug 01 09:00:22.999508 2024] [security2:error] [pid 421667:tid 134961338254912] [client 141.0.8.142:54726] [client 141.0.8.142] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "X-Forwarded-For" at REQUEST_HEADERS_NAMES:X-Forwarded-For. [file "/etc/modsecurity/coreruleset-4.3.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "163"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: X-Forwarded-For found within REQUEST_HEADERS_NAMES:X-Forwarded-For: X-Forwarded-For request_line = GET /index.php/prakiraan-iklim/prakiraan-musim/prakiraan-musim-hujan/prakiraan-awal-musim-hujan HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/prakiraan-iklim/prakiraan-musim/prakiraan-musim-hujan/prakiraan-awal-musim-hujan"] [unique_id "ZqrsNk08uNGhtCTvGR7txAAAAAM"], referer https://www.google.com/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[421712] [SXTYkg2E/fc] [ZqrsNk08uNGhtCTvGR7txAAAAA
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2024-05-22 09:18:53
(2 years ago)
[Wed May 22 16:18:45.849231 2024] [security2:error] [pid 2032768:tid 128222524081728] [client 141.0. ...
show more
[Wed May 22 16:18:45.849231 2024] [security2:error] [pid 2032768:tid 128222524081728] [client 141.0.8.142:50294] [client 141.0.8.142] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "X-Forwarded-For" at REQUEST_HEADERS_NAMES:X-Forwarded-For. [file "/etc/modsecurity/coreruleset-4.0.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "124"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: X-Forwarded-For found within REQUEST_HEADERS_NAMES:X-Forwarded-For: X-Forwarded-For request_line = GET /index.php/profil/meteorologi/list-of-all-tags/prakiraan-cuaca-sampang HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/list-of-all-tags/prakiraan-cuaca-sampang"] [unique_id "Zk24dZQVOHfZ_Pixx8_OPAAAAgs"], referer https://www.google.com/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[2032821] [N+jda3diKXQ] [Zk24dZQVOHfZ_Pixx8_OPAAAAgs] keep_alive=[0] [2024-05-22 16:18:45.8
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2024-05-18 03:07:49
(2 years ago)
[Sat May 18 10:07:47.611482 2024] [security2:error] [pid 301191:tid 131783016318528] [client 141.0.8 ...
show more
[Sat May 18 10:07:47.611482 2024] [security2:error] [pid 301191:tid 131783016318528] [client 141.0.8.142:58860] [client 141.0.8.142] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "X-Forwarded-For" at REQUEST_HEADERS_NAMES:X-Forwarded-For. [file "/etc/modsecurity/coreruleset-4.0.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "122"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: X-Forwarded-For found within REQUEST_HEADERS_NAMES:X-Forwarded-For: X-Forwarded-For request_line = GET /index.php/profil/meteorologi/list-all-categories/4073-meteorologi/prakiraan-meteorologi/prakiraan-cuaca-harian-tiap-3-jam-sekali-per-kecamatan/1210-prakiraan-cuaca-kediri HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/index.php/profil/meteorologi/list-all-categories/4073-meteorologi/prakiraan-meteorologi/prakiraan-cuaca-harian-tiap-3-jam-sekali-per-kecamatan/1210-prakiraan-cuaca-kediri"] [unique_id "Zkgbg5pAywOGsTyK
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2024-04-29 08:42:23
(2 years ago)
[Mon Apr 29 15:42:13.692717 2024] [security2:error] [pid 404336:tid 132790769157696] [client 141.0.8 ...
show more
[Mon Apr 29 15:42:13.692717 2024] [security2:error] [pid 404336:tid 132790769157696] [client 141.0.8.142:42300] [client 141.0.8.142] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "X-Forwarded-For" at REQUEST_HEADERS_NAMES:X-Forwarded-For. [file "/etc/modsecurity/coreruleset-4.0.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "122"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: X-Forwarded-For found within REQUEST_HEADERS_NAMES:X-Forwarded-For: X-Forwarded-For request_line = GET /index.php/profil/meteorologi/list-all-categories/4236-konferensi-pers/rilis-prakiraan-musim-kemarau-2024-provinsi-jawa-timur HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/index.php/profil/meteorologi/list-all-categories/4236-konferensi-pers/rilis-prakiraan-musim-kemarau-2024-provinsi-jawa-timur"] [unique_id "Zi9dZcbsnsKFvuqfclXl0wAAAAk"], referer https://www.google.com/ [staklim-malang.info] [staklim-malang.info] t
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2024-04-29 03:01:57
(2 years ago)
[Mon Apr 29 10:01:53.233335 2024] [security2:error] [pid 13587:tid 132793510135360] [client 141.0.8. ...
show more
[Mon Apr 29 10:01:53.233335 2024] [security2:error] [pid 13587:tid 132793510135360] [client 141.0.8.142:44036] [client 141.0.8.142] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "X-Forwarded-For" at REQUEST_HEADERS_NAMES:X-Forwarded-For. [file "/etc/modsecurity/coreruleset-4.0.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "122"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: X-Forwarded-For found within REQUEST_HEADERS_NAMES:X-Forwarded-For: X-Forwarded-For request_line = GET /images/Logo_ASN/Logo_EVP.webp HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/Logo_ASN/Logo_EVP.webp"] [unique_id "Zi8NoV8YxxPjWBsyLXu3YgAAAOY"], referer https://staklim-jatim.bmkg.go.id/index.php/profil/meteorologi/list-of-all-tags/prakiraan-cuaca-ponorogo [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[13667] [64GyeVs2VM0] [Zi8NoV8YxxPjWBsyLXu3YgAAAOY] keep_alive=[0] [2024-04-29 10:01:53.23333
...
show less
Hacking
Web App Attack