๐บ๐ธ
mawan
2026-06-20 14:44:07
(14 hours ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
mawan
2026-06-14 06:14:54
(6 days ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
chrisj
2026-05-08 21:17:38
(1 month ago)
[Fri May 08 21:17:36.990894 2026] [proxy_fcgi:error] [pid 213978:tid 213978] [client 172.70.142.181: ...
show more
[Fri May 08 21:17:36.990894 2026] [proxy_fcgi:error] [pid 213978:tid 213978] [client 172.70.142.181:11008] AH01071: Got error 'Primary script unknown'
[Fri May 08 21:17:37.514881 2026] [proxy_fcgi:error] [pid 213978:tid 213978] [client 172.70.142.181:11008] AH01071: Got error 'Primary script unknown'
[Fri May 08 21:17:37.775964 2026] [proxy_fcgi:error] [pid 213978:tid 213978] [client 172.70.142.181:11008] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
๐บ๐ธ
chrisj
2026-04-18 15:35:19
(2 months ago)
[Sat Apr 18 15:35:18.759778 2026] [proxy_fcgi:error] [pid 319412:tid 319412] [client 172.70.142.181: ...
show more
[Sat Apr 18 15:35:18.759778 2026] [proxy_fcgi:error] [pid 319412:tid 319412] [client 172.70.142.181:10675] AH01071: Got error 'Primary script unknown'
[Sat Apr 18 15:35:19.335201 2026] [proxy_fcgi:error] [pid 319412:tid 319412] [client 172.70.142.181:10675] AH01071: Got error 'Primary script unknown'
[Sat Apr 18 15:35:19.610653 2026] [proxy_fcgi:error] [pid 319412:tid 319412] [client 172.70.142.181:10675] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
๐ฒ๐พ
Rizzy
2026-04-03 19:23:00
(2 months ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฎ๐ฉ
Burayot
2026-03-19 23:08:35
(3 months ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 172.70.142.181 (SG/Singapore/-): 1 i ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 172.70.142.181 (SG/Singapore/-): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
chrisj
2026-03-05 01:17:32
(3 months ago)
[Thu Mar 05 01:17:31.401323 2026] [proxy_fcgi:error] [pid 1194407:tid 1194407] [client 172.70.142.18 ...
show more
[Thu Mar 05 01:17:31.401323 2026] [proxy_fcgi:error] [pid 1194407:tid 1194407] [client 172.70.142.181:11911] AH01071: Got error 'Primary script unknown'
[Thu Mar 05 01:17:31.665194 2026] [proxy_fcgi:error] [pid 1194407:tid 1194407] [client 172.70.142.181:11911] AH01071: Got error 'Primary script unknown'
[Thu Mar 05 01:17:31.934483 2026] [proxy_fcgi:error] [pid 1194407:tid 1194407] [client 172.70.142.181:11911] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
๐จ๐ณ
ThreatBook.io
2025-12-29 22:08:04
(5 months ago)
2025-12-29 15:17:20 /hdocs.tar
Web App Attack
๐ฎ๐ฉ
hermawan
2025-11-28 12:29:01
(6 months ago)
[Fri Nov 28 19:21:33.152692 2025] [security2:error] [pid 170702:tid 140466243757760] [client 172.70. ...
show more
[Fri Nov 28 19:21:33.152692 2025] [security2:error] [pid 170702:tid 140466243757760] [client 172.70.142.181:29979] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "CF-RAY" at REQUEST_HEADERS_NAMES:Cf-Ray. [file "/etc/modsecurity/coreruleset-4.20.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "399"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: CF-RAY found within REQUEST_HEADERS_NAMES:Cf-Ray: Cf-Ray request_line = GET /images/Klimatologi/Infografis/Infografis-Iklim/Bulanan/Ekstrim/2025/10_Oktober_2025/Infografis_Bulanan_Suhu_Udara_Minimum_Bulan_Oktober_2025-600.webp HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/images/Klimatologi/Infografis/Infografis-Iklim/Bulanan/Ekstrim/2025/10_Oktober_2025/Infografis_Bulanan_Suhu_Udara_Minimum_Bulan_Oktober_2025-600.webp"] [unique_id "aSmTza9P4RFSxGhLt_ezQAADkgE"] [staklim-malang.info] [staklim-malang.info] top=[170704] [376Eqyac7hc] [aSmTza9P4RFSxGhLt_
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-11-01 00:22:38
(7 months ago)
[Sat Nov 01 07:22:00.824144 2025] [security2:error] [pid 374758:tid 139716935542464] [client 172.70. ...
show more
[Sat Nov 01 07:22:00.824144 2025] [security2:error] [pid 374758:tid 139716935542464] [client 172.70.142.181:43768] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "CF-Connecting-IP" at REQUEST_HEADERS_NAMES:Cf-Connecting-Ip. [file "/etc/modsecurity/coreruleset-4.19.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "374"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: CF-Connecting-IP found within REQUEST_HEADERS_NAMES:Cf-Connecting-Ip: Cf-Connecting-Ip request_line = GET /images/Klimatologi/Infografis/Infografis-Iklim/Bulanan/2025/08_Agustus_2025/Infografis-Bulanan_Prediksi_Hujan_Bulan_OKTOBER-NOVEMBER-DESEMBER_Tahun_2025_Update_Dari_Analisis_Bulan_Agustus_2025_di_Provinsi_Jawa_Timur-600.webp HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/images/Klimatologi/Infografis/Infografis-Iklim/Bulanan/2025/08_Agustus_2025/Infografis-Bulanan_Prediksi_Hujan_Bulan_OKTOBER-NOVEMBER-DESEMBER_Tahun_2025_Update
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-10-28 13:16:11
(7 months ago)
[Tue Oct 28 20:15:25.198909 2025] [security2:error] [pid 2772754:tid 139675002971840] [client 172.70 ...
show more
[Tue Oct 28 20:15:25.198909 2025] [security2:error] [pid 2772754:tid 139675002971840] [client 172.70.142.181:48075] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "CF-Connecting-IP" at REQUEST_HEADERS_NAMES:Cf-Connecting-Ip. [file "/etc/modsecurity/coreruleset-4.19.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "374"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: CF-Connecting-IP found within REQUEST_HEADERS_NAMES:Cf-Connecting-Ip: Cf-Connecting-Ip request_line = GET /images/Klimatologi/Infografis/Infografis-Iklim/Bulanan/2025/08_Agustus_2025/Infografis-Bulanan_Prediksi_Hujan_Bulan_OKTOBER-NOVEMBER-DESEMBER_Tahun_2025_Update_Dari_Analisis_Bulan_Agustus_2025_di_Provinsi_Jawa_Timur-600.webp HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/images/Klimatologi/Infografis/Infografis-Iklim/Bulanan/2025/08_Agustus_2025/Infografis-Bulanan_Prediksi_Hujan_Bulan_OKTOBER-NOVEMBER-DESEMBER_Tahun_2025_Updat
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-10-26 09:53:34
(7 months ago)
[Sun Oct 26 16:52:17.970570 2025] [security2:error] [pid 717100:tid 140451022530240] [client 172.70. ...
show more
[Sun Oct 26 16:52:17.970570 2025] [security2:error] [pid 717100:tid 140451022530240] [client 172.70.142.181:40849] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "CF-Connecting-IP" at REQUEST_HEADERS_NAMES:Cf-Connecting-Ip. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "375"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: CF-Connecting-IP found within REQUEST_HEADERS_NAMES:Cf-Connecting-Ip: Cf-Connecting-Ip request_line = GET /images/Klimatologi/Infografis/Infografis-Iklim/Bulanan/2025/08_Agustus_2025/Infografis-Bulanan_Prediksi_Hujan_Bulan_OKTOBER-NOVEMBER-DESEMBER_Tahun_2025_Update_Dari_Analisis_Bulan_Agustus_2025_di_Provinsi_Jawa_Timur-600.webp HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/images/Klimatologi/Infografis/Infografis-Iklim/Bulanan/2025/08_Agustus_2025/Infografis-Bulanan_Prediksi_Hujan_Bulan_OKTOBER-NOVEMBER-DESEMBER_Tahun_2025_Update
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-10-18 14:36:11
(8 months ago)
[Sat Oct 18 21:20:29.213025 2025] [security2:error] [pid 299907:tid 140210674329280] [client 172.70. ...
show more
[Sat Oct 18 21:20:29.213025 2025] [security2:error] [pid 299907:tid 140210674329280] [client 172.70.142.181:40627] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "CF-Connecting-IP" at REQUEST_HEADERS_NAMES:Cf-Connecting-Ip. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "375"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: CF-Connecting-IP found within REQUEST_HEADERS_NAMES:Cf-Connecting-Ip: Cf-Connecting-Ip request_line = GET /images/Klimatologi/Infografis/Infografis-Iklim/Bulanan/2025/08_Agustus_2025/Infografis-Bulanan_Prediksi_Hujan_Bulan_OKTOBER-NOVEMBER-DESEMBER_Tahun_2025_Update_Dari_Analisis_Bulan_Agustus_2025_di_Provinsi_Jawa_Timur-600.webp HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/images/Klimatologi/Infografis/Infografis-Iklim/Bulanan/2025/08_Agustus_2025/Infografis-Bulanan_Prediksi_Hujan_Bulan_OKTOBER-NOVEMBER-DESEMBER_Tahun_2025_Update
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-10-13 05:04:48
(8 months ago)
[Mon Oct 13 12:03:06.837034 2025] [security2:error] [pid 1079283:tid 139978316080832] [client 172.70 ...
show more
[Mon Oct 13 12:03:06.837034 2025] [security2:error] [pid 1079283:tid 139978316080832] [client 172.70.142.181:44878] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "CF-RAY" at REQUEST_HEADERS_NAMES:Cf-Ray. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "375"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: CF-RAY found within REQUEST_HEADERS_NAMES:Cf-Ray: Cf-Ray request_line = GET /b/curah_bulananpacitan.jpg HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/b/curah_bulananpacitan.jpg"] [unique_id "aOyICtdT3aOMVU_4Vw0dmAABwRg"] [staklim-malang.info] [staklim-malang.info] top=[1079308] [LYnTLsNz03I] [aOyICtdT3aOMVU_4Vw0dmAABwRg] keep_alive=[1] [2025-10-13 12:03:06.837040] [R:aOyICtdT3aOMVU_4Vw0dmAABwRg] Host:'staklim-malang.info' ACCEPT:'image/jpeg,image/png,image/gif;q=0.1,image/*;q=0.1' Accept-Encoding:'gzip
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-10-06 22:44:07
(8 months ago)
[Tue Oct 07 05:42:50.802450 2025] [security2:error] [pid 123121:tid 140449602762432] [client 172.70. ...
show more
[Tue Oct 07 05:42:50.802450 2025] [security2:error] [pid 123121:tid 140449602762432] [client 172.70.142.181:45746] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "CF-Connecting-IP" at REQUEST_HEADERS_NAMES:Cf-Connecting-Ip. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "375"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: CF-Connecting-IP found within REQUEST_HEADERS_NAMES:Cf-Connecting-Ip: Cf-Connecting-Ip request_line = GET /images/Klimatologi/Prakiraan/03-Prakiraan-Bulanan/Prakiraan_Curah_Hujan_Bulanan/Prakiraan_Curah_Hujan_Bulanan_Provinsi_Jawa_Timur/2024/04_April_2024/01_Prakiraan_Curah_Hujan_Bulan_JUNI_2024_di_Provinsi_Jawa_Timur-Update_dari_Analisis_Bulan_April_2024.jpg HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/Klimatologi/Prakiraan/03-Prakiraan-Bulanan/Prakiraan_Curah_Hujan_Bulanan/Prakiraan_Curah_Hujan_Bulanan_Provinsi_Jawa_
...
show less
Hacking
Web App Attack