๐ง๐ช
madeit
2026-08-28 07:53:26
(3 days ago)
Web App Attack
๐ง๐ช
madeit
2026-08-17 02:31:07
(2 weeks ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 22:37:06
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.152.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.152.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 18:36:59.694934 2026] [security2:error] [pid 16973:tid 16973] [client 172.71.152.72:11082] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clossglobal.com"] [uri "/.git/HEAD"] [unique_id "aoI7i0z3ZbwQaFkBfkd6BgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2026-07-11 22:17:02
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
mawan
2026-07-10 01:39:52
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
Anonymous
2026-05-13 06:01:25
(3 months ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐ณ๐ฑ
i-turnradio.nl
2026-05-11 04:50:23
(3 months ago)
2026-05-11 @ 06:50:23 (CET) ~ Blocked for trying to access: /backup.sql.gz
Web App Attack
๐ฎ๐ฉ
Burayot
2026-03-20 09:06:37
(5 months ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 172.71.152.72 (SG/Singapore/-): 1 in ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 172.71.152.72 (SG/Singapore/-): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
iwle
2026-01-12 07:47:57
(7 months ago)
172.71.152.72 - - [12/Jan/2026:02:47:53 -0500] "GET //blog/wp-includes/wlwmanifest.xml HTTP/2.0" 404 ...
show more
172.71.152.72 - - [12/Jan/2026:02:47:53 -0500] "GET //blog/wp-includes/wlwmanifest.xml HTTP/2.0" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36"
...
show less
Brute-Force
๐ฎ๐ฉ
hermawan
2025-11-17 11:27:02
(9 months ago)
[Mon Nov 17 18:19:02.023970 2025] [security2:error] [pid 935932:tid 140544201189056] [client 172.71. ...
show more
[Mon Nov 17 18:19:02.023970 2025] [security2:error] [pid 935932:tid 140544201189056] [client 172.71.152.72:36089] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "CF-RAY" at REQUEST_HEADERS_NAMES:Cf-Ray. [file "/etc/modsecurity/coreruleset-4.20.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "394"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: CF-RAY found within REQUEST_HEADERS_NAMES:Cf-Ray: Cf-Ray request_line = GET /images/Klimatologi/Analisis/03-Analisis_Bulanan/Analisis_Distibusi_Curah_Hujan_Bulanan/Analisis_Distibusi_Curah_Hujan_Bulanan_Provinsi_Jawa_Timur/2024/01_Januari_2024/Analisis_Bulanan_Distribusi_Curah_Hujan_Bulan_Januari_Tahun_2024_di_Provinsi_Jawa_Timur.jpg HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/images/Klimatologi/Analisis/03-Analisis_Bulanan/Analisis_Distibusi_Curah_Hujan_Bulanan/Analisis_Distibusi_Curah_Hujan_Bulanan_Provinsi_Jawa_Timur/2024/01_Januari_2024/Analisis_
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-11-11 13:43:32
(9 months ago)
[Tue Nov 11 20:11:28.785261 2025] [security2:error] [pid 110750:tid 139672720565952] [client 172.71. ...
show more
[Tue Nov 11 20:11:28.785261 2025] [security2:error] [pid 110750:tid 139672720565952] [client 172.71.152.72:33270] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "CF-Connecting-IP" at REQUEST_HEADERS_NAMES:Cf-Connecting-Ip. [file "/etc/modsecurity/coreruleset-4.20.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "394"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: CF-Connecting-IP found within REQUEST_HEADERS_NAMES:Cf-Connecting-Ip: Cf-Connecting-Ip request_line = GET /images/Klimatologi/Infografis/Infografis-Iklim/Perubahan_Iklim/Infografis_Perubahan_Iklim_Jawa_Timur-600.jpg HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/Klimatologi/Infografis/Infografis-Iklim/Perubahan_Iklim/Infografis_Perubahan_Iklim_Jawa_Timur-600.jpg"] [unique_id "aRM2AH0hh2H0JHX20ziWXgADjgA"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[110751] [uvfEYtGo9Uc] [aRM2AH0hh2H0JHX20ziWXgADjgA] keep_al
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-11-04 08:32:24
(9 months ago)
[Tue Nov 04 15:26:44.041457 2025] [security2:error] [pid 70437:tid 139712416085696] [client 172.71.1 ...
show more
[Tue Nov 04 15:26:44.041457 2025] [security2:error] [pid 70437:tid 139712416085696] [client 172.71.152.72:41123] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "CF-Connecting-IP" at REQUEST_HEADERS_NAMES:Cf-Connecting-Ip. [file "/etc/modsecurity/coreruleset-4.19.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "378"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: CF-Connecting-IP found within REQUEST_HEADERS_NAMES:Cf-Connecting-Ip: Cf-Connecting-Ip request_line = GET /images/Klimatologi/Infografis/Infografis-Iklim/Perubahan_Iklim/Infografis_Perubahan_Iklim_Jawa_Timur-600.jpg HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/Klimatologi/Infografis/Infografis-Iklim/Perubahan_Iklim/Infografis_Perubahan_Iklim_Jawa_Timur-600.jpg"] [unique_id "aQm4xE0wjnQ9XwjqHvthdgAARxg"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[70462] [jM+Ml8CUnW0] [aQm4xE0wjnQ9XwjqHvthdgAARxg] keep_aliv
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-10-29 08:29:28
(10 months ago)
[Wed Oct 29 15:28:54.622140 2025] [security2:error] [pid 1147647:tid 140039519450816] [client 172.71 ...
show more
[Wed Oct 29 15:28:54.622140 2025] [security2:error] [pid 1147647:tid 140039519450816] [client 172.71.152.72:35046] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "CF-Connecting-IP" at REQUEST_HEADERS_NAMES:Cf-Connecting-Ip. [file "/etc/modsecurity/coreruleset-4.19.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "374"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: CF-Connecting-IP found within REQUEST_HEADERS_NAMES:Cf-Connecting-Ip: Cf-Connecting-Ip request_line = GET /images/Klimatologi/Infografis/Infografis-Iklim/Perubahan_Iklim/Infografis_Perubahan_Iklim_Jawa_Timur-600.jpg HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/Klimatologi/Infografis/Infografis-Iklim/Perubahan_Iklim/Infografis_Perubahan_Iklim_Jawa_Timur-600.jpg"] [unique_id "aQHQRlgVnZPjA1KAbqdeHAABBgM"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[1147651] [/IFI7Ef+VbQ] [aQHQRlgVnZPjA1KAbqdeHAABBgM] keep_
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-10-11 11:38:37
(10 months ago)
[Sat Oct 11 18:36:51.184716 2025] [security2:error] [pid 2363340:tid 139973169669824] [client 172.71 ...
show more
[Sat Oct 11 18:36:51.184716 2025] [security2:error] [pid 2363340:tid 139973169669824] [client 172.71.152.72:34618] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "CF-Connecting-IP" at REQUEST_HEADERS_NAMES:Cf-Connecting-Ip. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "375"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: CF-Connecting-IP found within REQUEST_HEADERS_NAMES:Cf-Connecting-Ip: Cf-Connecting-Ip request_line = GET /images/Klimatologi/Infografis/Infografis-Iklim/Bulanan/2018/10-Infografis-Bulanan_Prakiraan_Hujan_Bulan_Desember_2018-Januari_2019-Februari_2019_Update_Dari_Analisis_Bulan_Oktober_2018.jpg HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/Klimatologi/Infografis/Infografis-Iklim/Bulanan/2018/10-Infografis-Bulanan_Prakiraan_Hujan_Bulan_Desember_2018-Januari_2019-Februari_2019_Update_Dari_Analisis_Bulan_Oktober_2018.jpg"]
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-09-30 10:54:55
(11 months ago)
[Tue Sep 30 17:42:34.364120 2025] [security2:error] [pid 2975223:tid 140100691281600] [client 172.71 ...
show more
[Tue Sep 30 17:42:34.364120 2025] [security2:error] [pid 2975223:tid 140100691281600] [client 172.71.152.72:34468] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "CF-Connecting-IP" at REQUEST_HEADERS_NAMES:Cf-Connecting-Ip. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "375"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: CF-Connecting-IP found within REQUEST_HEADERS_NAMES:Cf-Connecting-Ip: Cf-Connecting-Ip request_line = GET /images/Klimatologi/Infografis/Infografis-Iklim/Bulanan/2018/10-Infografis-Bulanan_Prakiraan_Hujan_Bulan_Desember_2018-Januari_2019-Februari_2019_Update_Dari_Analisis_Bulan_Oktober_2018.jpg HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/Klimatologi/Infografis/Infografis-Iklim/Bulanan/2018/10-Infografis-Bulanan_Prakiraan_Hujan_Bulan_Desember_2018-Januari_2019-Februari_2019_Update_Dari_Analisis_Bulan_Oktober_2018.jpg"]
...
show less
Hacking
Web App Attack