🇭🇰
pengpeng
2026-09-07 14:19:59
(1 day ago)
monitor: on ser162528253480 | port: 14343 | ttl: 127 script: github.com/sefinek/UFW-AbuseIPDB-Repor ...
show more
monitor: on ser162528253480 | port: 14343 | ttl: 127 script: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
🇭🇰
pengpeng
2026-09-07 05:46:30
(2 days ago)
monitor: on ser162528253480 | port: 5976 | ttl: 245 script: github.com/sefinek/UFW-AbuseIPDB-Report ...
show more
monitor: on ser162528253480 | port: 5976 | ttl: 245 script: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
🇭🇰
pengpeng
2026-09-07 04:38:50
(2 days ago)
monitor: on ser162528253480 | port: 5503 | ttl: 245 script: github.com/sefinek/UFW-AbuseIPDB-Report ...
show more
monitor: on ser162528253480 | port: 5503 | ttl: 245 script: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
🇭🇰
pengpeng
2026-09-07 02:29:43
(2 days ago)
monitor: on ser162528253480 | port: 8917 | ttl: 245 script: github.com/sefinek/UFW-AbuseIPDB-Report ...
show more
monitor: on ser162528253480 | port: 8917 | ttl: 245 script: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
🇮🇩
Burayot
2025-06-05 10:46:43
(1 year ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 152.42.249.240 (SG/Singapore/-): 1 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 152.42.249.240 (SG/Singapore/-): 1 in the last 3600 secs
show less
Web App Attack
🇮🇩
hermawan
2025-06-02 02:32:46
(1 year ago)
[Mon Jun 02 09:32:15.092009 2025] [security2:error] [pid 1033468:tid 140565756769984] [client 152.42 ...
show more
[Mon Jun 02 09:32:15.092009 2025] [security2:error] [pid 1033468:tid 140565756769984] [client 152.42.249.240:60357] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/wp" at REQUEST_FILENAME. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "52"] [id "448101"] [msg "BAD REQUEST FILENAME - Detected and Blocked"] [data "Matched Data: /wp found within REQUEST_FILENAME: /wp-admin/ request_line = GET /wp-admin/ HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/wp-admin/"] [unique_id "aD0NLxV8MczEguG27MIJ6wAAAQI"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[1033502] [30tqkhVehGU] [aD0NLxV8MczEguG27MIJ6wAAAQI] keep_alive=[0] [2025-06-02 09:32:15.092014] [R:aD0NLxV8MczEguG27MIJ6wAAAQI] UA:'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36' Host:'staklim-jatim.bmkg.go.id' ACCEPT:'*/*' Accept-Encoding:'gzip, deflate
...
show less
Hacking
Web App Attack
🇮🇩
Burayot
2025-06-01 07:38:37
(1 year ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 152.42.249.240 (SG/Singapore/-): 1 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 152.42.249.240 (SG/Singapore/-): 1 in the last 3600 secs
show less
Web App Attack
🇮🇩
hermawan
2025-05-28 21:34:58
(1 year ago)
[Thu May 29 04:34:13.005146 2025] [security2:error] [pid 589719:tid 139774987847360] [client 152.42. ...
show more
[Thu May 29 04:34:13.005146 2025] [security2:error] [pid 589719:tid 139774987847360] [client 152.42.249.240:64772] ModSecurity: Access denied with code 403 (phase 1). Match of "pm matomo.staklim-malang.info " against "SERVER_NAME" required. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "142"] [id "440235"] [msg "BAD REQUEST Bro"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: rest_route found within SERVER_NAME: staklim-jatim.bmkg.go.id request_line = GET /?rest_route=/wp/v2/users/ HTTP/1.1 Request URI RAW = /?rest_route=/wp/v2/users/ Request Basename = "] [hostname "staklim-jatim.bmkg.go.id"] [uri "/"] [unique_id "aDeBVA2m7FUrhq7HQj0LnwAAARQ"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[589771] [HuIx8SCYX3w] [aDeBVA2m7FUrhq7HQj0LnwAAARQ] keep_alive=[0] [2025-05-29 04:34:13.005160] [R:aDeBVA2m7FUrhq7HQj0LnwAAARQ] UA:'Mozilla/5.0 (Windows NT 10.0; Win64; x64)
...
show less
Hacking
Web App Attack
🇮🇩
hermawan
2025-05-28 00:31:58
(1 year ago)
[Wed May 28 07:29:59.620058 2025] [security2:error] [pid 136391:tid 140574858397376] [client 152.42. ...
show more
[Wed May 28 07:29:59.620058 2025] [security2:error] [pid 136391:tid 140574858397376] [client 152.42.249.240:53559] ModSecurity: Access denied with code 403 (phase 1). Match of "pm matomo.staklim-malang.info " against "SERVER_NAME" required. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "142"] [id "440235"] [msg "BAD REQUEST Bro"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: rest_route found within SERVER_NAME: staklim-jatim.bmkg.go.id request_line = GET /?rest_route=/wp/v2/users/ HTTP/1.1 Request URI RAW = /?rest_route=/wp/v2/users/ Request Basename = "] [hostname "staklim-jatim.bmkg.go.id"] [uri "/"] [unique_id "aDZZBz-3BrLB4B5OdtF6KAAAANU"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[136444] [KRL8R3/IE8o] [aDZZBz-3BrLB4B5OdtF6KAAAANU] keep_alive=[0] [2025-05-28 07:29:59.620063] [R:aDZZBz-3BrLB4B5OdtF6KAAAANU] UA:'Mozilla/5.0 (Windows NT 10.0; Win64; x64)
...
show less
Hacking
Web App Attack
🇮🇩
BPS-StatisticsIndonesia
2025-05-18 23:29:30
(1 year ago)
WP Login Scan Activities
Web App Attack
🇮🇩
hermawan
2025-05-18 03:06:46
(1 year ago)
[Sun May 18 10:06:00.916234 2025] [security2:error] [pid 722729:tid 140049773467328] [client 152.42. ...
show more
[Sun May 18 10:06:00.916234 2025] [security2:error] [pid 722729:tid 140049773467328] [client 152.42.249.240:59590] ModSecurity: Access denied with code 403 (phase 1). Match of "pm matomo.staklim-malang.info " against "SERVER_NAME" required. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "142"] [id "440235"] [msg "BAD REQUEST Bro"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: rest_route found within SERVER_NAME: staklim-jatim.bmkg.go.id request_line = GET /?rest_route=/wp/v2/users/ HTTP/1.1 Request URI RAW = /?rest_route=/wp/v2/users/ Request Basename = "] [hostname "staklim-jatim.bmkg.go.id"] [uri "/"] [unique_id "aClOmLN3AA06pjOTMZiRzAAAAAY"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[722787] [jl6LSxgSROs] [aClOmLN3AA06pjOTMZiRzAAAAAY] keep_alive=[0] [2025-05-18 10:06:00.916240] [R:aClOmLN3AA06pjOTMZiRzAAAAAY] UA:'Mozilla/5.0 (Windows NT 10.0; Win64; x64)
...
show less
Hacking
Web App Attack
🇮🇩
satpam.bsn
2025-05-16 01:42:00
(1 year ago)
Suspicious File Access Attempt - 1
Web App Attack
🇮🇩
hermawan
2025-05-15 22:43:47
(1 year ago)
[Fri May 16 05:43:06.104593 2025] [security2:error] [pid 7704:tid 140682400421568] [client 152.42.24 ...
show more
[Fri May 16 05:43:06.104593 2025] [security2:error] [pid 7704:tid 140682400421568] [client 152.42.249.240:51370] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/tinymce" at REQUEST_FILENAME. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "52"] [id "448101"] [msg "BAD REQUEST FILENAME - Detected and Blocked"] [data "Matched Data: /tinymce found within REQUEST_FILENAME: /asset/tinymce4x/tinymce/plugins/filemanager/dialog.php request_line = GET //asset/tinymce4x/tinymce/plugins/filemanager/dialog.php HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/asset/tinymce4x/tinymce/plugins/filemanager/dialog.php"] [unique_id "aCZt-qAZHHioEjTl3EsSSgAAAEk"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[7765] [8oycYwwyoNo] [aCZt-qAZHHioEjTl3EsSSgAAAEk] keep_alive=[0] [2025-05-16 05:43:06.104598] [R:aCZt-qAZHHioEjTl3EsSSgAAAEk] UA:'Go-http-client/1.1' Host:'staklim-jatim.bmkg.go.id' Accept-Encod
...
show less
Hacking
Web App Attack
🇮🇩
BPS-StatisticsIndonesia
2025-05-15 19:10:12
(1 year ago)
TinyMCE Scan Activities
Web App Attack
🇮🇩
hermawan
2025-05-15 12:26:12
(1 year ago)
[Thu May 15 19:25:10.523039 2025] [security2:error] [pid 1530586:tid 139634340046528] [client 152.42 ...
show more
[Thu May 15 19:25:10.523039 2025] [security2:error] [pid 1530586:tid 139634340046528] [client 152.42.249.240:61580] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/fileman" at REQUEST_FILENAME. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "52"] [id "448101"] [msg "BAD REQUEST FILENAME - Detected and Blocked"] [data "Matched Data: /fileman found within REQUEST_FILENAME: /filemanager/dialog.php request_line = GET //filemanager/dialog.php HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/filemanager/dialog.php"] [unique_id "aCXdJvxK9EK2Y0_y7n2shwAAAEA"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[1530638] [SuOvwdMTpfA] [aCXdJvxK9EK2Y0_y7n2shwAAAEA] keep_alive=[0] [2025-05-15 19:25:10.523044] [R:aCXdJvxK9EK2Y0_y7n2shwAAAEA] UA:'Go-http-client/1.1' Host:'staklim-jatim.bmkg.go.id' Accept-Encoding:'gzip
...
show less
Hacking
Web App Attack