๐ง๐ช
madeit
2026-09-18 14:49:04
(1 hour ago)
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-09 22:02:11
(1 week ago)
Auto-ban: >3000 req/min op 2026-09-09
Web App Attack
SSH
Hacking
๐บ๐ธ
MPL
2026-09-04 20:32:28
(1 week ago)
tcp/443 (5 or more attempts)
Port Scan
๐ง๐ช
madeit
2026-09-01 02:43:23
(2 weeks ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 05:16:47
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.152.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.152.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 01:16:40.287098 2026] [security2:error] [pid 4714:tid 4714] [client 172.71.152.50:13098] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.purlandpurr.com"] [uri "/.git/HEAD"] [unique_id "aoKZODpJQv1ZI19kA3PXtQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-12 10:48:59
(1 month ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-01 13:34:17
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.152.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.152.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 01 09:33:39.789331 2026] [security2:error] [pid 27465:tid 27472] [client 172.71.152.50:35635] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "writeonce.org"] [uri "/.env.prod"] [unique_id "akUXM5-bncdyVqNR2DB9eAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-03-30 05:54:49
(5 months ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 172.71.152.50 (SG/Singapore/-): 1 in ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 172.71.152.50 (SG/Singapore/-): 1 in the last 3600 secs
show less
Web App Attack
๐ฎ๐ฉ
hermawan
2025-11-16 08:39:18
(10 months ago)
[Sun Nov 16 15:38:43.376557 2025] [security2:error] [pid 1769583:tid 140212979099328] [client 172.71 ...
show more
[Sun Nov 16 15:38:43.376557 2025] [security2:error] [pid 1769583:tid 140212979099328] [client 172.71.152.50:40300] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "CF-RAY" at REQUEST_HEADERS_NAMES:Cf-Ray. [file "/etc/modsecurity/coreruleset-4.20.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "394"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: CF-RAY found within REQUEST_HEADERS_NAMES:Cf-Ray: Cf-Ray request_line = GET /images/Klimatologi/Prakiraan/03-Prakiraan-Bulanan/Prakiraan_Curah_Hujan_Bulanan/Prakiraan_Curah_Hujan_Bulanan_Provinsi_Jawa_Timur/2023/08/01_Prakiraan_Curah_Hujan_Bulan_OKTOBER_2023_di_Provinsi_Jawa_Timur-Update_dari_Analisis_Bulan_Agustus_2023.jpg HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/Klimatologi/Prakiraan/03-Prakiraan-Bulanan/Prakiraan_Curah_Hujan_Bulanan/Prakiraan_Curah_Hujan_Bulanan_Provinsi_Jawa_Timur/2023/08/01_Prakiraan_Curah_Hujan_Bulan_OKTOBER_202
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-11-12 01:47:29
(10 months ago)
[Wed Nov 12 08:47:29.043933 2025] [security2:error] [pid 730757:tid 139672352175808] [client 172.71. ...
show more
[Wed Nov 12 08:47:29.043933 2025] [security2:error] [pid 730757:tid 139672352175808] [client 172.71.152.50:42193] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "CF-RAY" at REQUEST_HEADERS_NAMES:Cf-Ray. [file "/etc/modsecurity/coreruleset-4.20.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "394"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: CF-RAY found within REQUEST_HEADERS_NAMES:Cf-Ray: Cf-Ray request_line = GET /images/Klimatologi/Analisis/03-Analisis_Bulanan/Analisis_Tingkat_Ketersediaan_Air_Tanah_Bulanan/Analisis_Tingkat_Ketersediaan_Air_Tanah_Bulanan_Provinsi_Jawa_Timur/2023/09/Analisis_Bulanan_Tingkat_Ketersediaan_Air_Tanah_Bulan_September_Tahun_2023_di_Provinsi_Jawa_Timur.jpg HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/Klimatologi/Analisis/03-Analisis_Bulanan/Analisis_Tingkat_Ketersediaan_Air_Tanah_Bulanan/Analisis_Tingkat_Ketersediaan_Air_Tanah_Bulanan_Provinsi_Jaw
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-11-08 00:49:25
(10 months ago)
[Sat Nov 08 07:48:54.160620 2025] [security2:error] [pid 444265:tid 140271518906048] [client 172.71. ...
show more
[Sat Nov 08 07:48:54.160620 2025] [security2:error] [pid 444265:tid 140271518906048] [client 172.71.152.50:43706] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "CF-RAY" at REQUEST_HEADERS_NAMES:Cf-Ray. [file "/etc/modsecurity/coreruleset-4.20.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "394"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: CF-RAY found within REQUEST_HEADERS_NAMES:Cf-Ray: Cf-Ray request_line = GET /images/Klimatologi/Analisis/03-Analisis_Bulanan/Analisis_Tingkat_Ketersediaan_Air_Tanah_Bulanan/Analisis_Tingkat_Ketersediaan_Air_Tanah_Bulanan_Provinsi_Jawa_Timur/2023/09/Analisis_Bulanan_Tingkat_Ketersediaan_Air_Tanah_Bulan_September_Tahun_2023_di_Provinsi_Jawa_Timur.jpg HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/Klimatologi/Analisis/03-Analisis_Bulanan/Analisis_Tingkat_Ketersediaan_Air_Tanah_Bulanan/Analisis_Tingkat_Ketersediaan_Air_Tanah_Bulanan_Provinsi_Jaw
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-09-14 07:55:48
(1 year ago)
[Sun Sep 14 14:55:17.226866 2025] [security2:error] [pid 1812415:tid 140267056244416] [client 172.71 ...
show more
[Sun Sep 14 14:55:17.226866 2025] [security2:error] [pid 1812415:tid 140267056244416] [client 172.71.152.50:48512] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "CF-Connecting-IP" at REQUEST_HEADERS_NAMES:Cf-Connecting-Ip. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "375"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: CF-Connecting-IP found within REQUEST_HEADERS_NAMES:Cf-Connecting-Ip: Cf-Connecting-Ip request_line = GET /images/Klimatologi/Infografis/Infografis-Iklim/Bulanan/2023/10/Infografis-Bulanan_Prakiraan_Hujan_Bulan_DESEMBER_Tahun_2023-JANUARI-FEBRUARI_Tahun_2024_Update_Dari_Analisis_Bulan_Oktober_2023_di_Provinsi_Jawa_Timur-600.jpg HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/Klimatologi/Infografis/Infografis-Iklim/Bulanan/2023/10/Infografis-Bulanan_Prakiraan_Hujan_Bulan_DESEMBER_Tahun_2023-JANUARI-FEBRUARI_Tahun_2024_Upda
...
show less
Hacking
Web App Attack
๐บ๐ธ
mawan
2025-07-09 17:11:01
(1 year ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2025-06-12 01:58:18
(1 year ago)
WP Admin Scan Activities
Web App Attack
๐ณ๐ฑ
mawan
2025-06-08 17:36:46
(1 year ago)
Suspected of having performed illicit activity on AMS server.
Web App Attack