๐บ๐ธ
TPI-Abuse
2026-10-07 11:43:05
(55 minutes ago)
(mod_security) mod_security (id:210492) triggered by 151.71.48.197 (71.151.in-addr.arpa): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 151.71.48.197 (71.151.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 07:42:58.729959 2026] [security2:error] [pid 14813:tid 14813] [client 151.71.48.197:33112] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "darkcodeproductions.com.darkcodedesign.net"] [uri "/qa/.env.production"] [unique_id "asYwQo1bGDCKMJXmwRbVMQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
hermawan
2026-10-06 00:40:19
(1 day ago)
Captured JA4H: ge11n_772dbfd78624 | Log: 151.71.48.197 - - [06/Oct/2026:07:38:56 +0700] "GET /index. ...
show more
Captured JA4H: ge11n_772dbfd78624 | Log: 151.71.48.197 - - [06/Oct/2026:07:38:56 +0700] "GET /index.php/profil/meteorologi/list-all-categories/113-meteorologi/prakiraan-meteorologi/1234-peringatan-dini-3-harian-jawa-timur-tanggal-31-desember-2019-2-januari-2020 HTTP/1.1" 200 14562 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_4 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) EdgiOS/122.0.2365.99 Version/17.0 Mobile/15E148 Safari/604.1" ge11n_host,x-forwarded-scheme,x-forwarded-proto,x-forwarded-for,x-real-ip,connection,user-agent,accept,accept-encoding,sec-fetch-site,cf-ray,sec-fetch-mode,sec-fetch-dest,accept-language,cdn-loop,cf-connecting-ip,cf-ipcountry,cf-visitor...
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-09-22 07:05:19
(2 weeks ago)
Captured JA4H: ge11n_4afaac0d80e2 | Log: 151.71.48.197 - - [22/Sep/2026:13:19:18 +0700] "GET /index. ...
show more
Captured JA4H: ge11n_4afaac0d80e2 | Log: 151.71.48.197 - - [22/Sep/2026:13:19:18 +0700] "GET /index.php/profil/arsip-artikel?catid=479&id=1138%3Aprakiraan-cuaca-daerah-malang-dan-batu-seminggu-ke-depan-berlaku-tanggal-14-19-september-2016&start=100 HTTP/1.1" 403 3738 "https://www.bmkg.go.id/" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_6_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/142.0.1 Mobile/15E148 Safari/605.1.15" ge11n_host,x-forwarded-scheme,x-forwarded-proto,x-forwarded-for,x-real-ip,connection,sec-fetch-user,cf-ew-via,cdn-loop,sec-fetch-site,sec-fetch-mode,cf-ray,accept-encoding,accept-language,accept,referer,user-agent,cf-connecting-ip,sec-fetch-dest,cf-visitor,cf-ipcountry...
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-09-22 06:19:40
(2 weeks ago)
[Tue Sep 22 13:19:18.602305 2026] [security2:error] [pid 110679:tid 140304367744704] [client 151.71. ...
show more
[Tue Sep 22 13:19:18.602305 2026] [security2:error] [pid 110679:tid 140304367744704] [client 151.71.48.197:0] ModSecurity: Access denied with code 403 (phase 1). Match of "pm matomo.staklim-malang.info " against "SERVER_NAME" required. [file "/etc/modsecurity/coreruleset-4.29.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "208"] [id "440235"] [msg "BAD REQUEST Bro"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: %3a found within SERVER_NAME: staklim-jatim.bmkg.go.id request_line = GET /index.php/profil/arsip-artikel?catid=479&id=1138%3Aprakiraan-cuaca-daerah-malang-dan-batu-seminggu-ke-depan-berlaku-tanggal-14-19-september-2016&start=100 HTTP/1.1 Request URI RAW = /index.php/profil/arsip-artikel?catid=479&id=1138%3Aprakiraan-cuaca-daerah-malang-dan-batu-seminggu-ke-depan-berlaku-tanggal-14-19-september-2016&..."] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/profil/arsip-artikel"] [unique_id "arId5nLwmBNL
...
show less
Email Spam
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-20 07:56:42
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 151.71.48.197 (71.151.in-addr.arpa): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 151.71.48.197 (71.151.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 03:53:53.717846 2026] [security2:error] [pid 13841:tid 13841] [client 151.71.48.197:45940] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "support.leonardodecaprio.com"] [uri "/prestashop/.env.copy"] [unique_id "aq-REXsFltTDUcWUquUdhQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
้ฌผๅฝฑ233
2026-09-19 09:16:21
(2 weeks ago)
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Sa ...
show more
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
show less
Bad Web Bot
๐ช๐ธ
el-brujo
2026-09-18 14:38:00
(2 weeks ago)
HTTP DDoS Attack Layer 7
DDoS Attack