๐ฎ๐ฉ
hermawan
2026-06-20 10:45:39
(6 days ago)
[Sat Jun 20 17:45:34.874293 2026] [security2:error] [pid 406143:tid 140602015385280] [client 31.132. ...
show more
[Sat Jun 20 17:45:34.874293 2026] [security2:error] [pid 406143:tid 140602015385280] [client 31.132.54.23:15184] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.google.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "582"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.google.go.id found within REQUEST_HEADERS:Referer: https://www.google.go.id/ request_line = GET /index.php/profil/meteorologi/geofisika/555558585-poster-antisipasi-gempa HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/geofisika/555558585-poster-antisipasi-gempa"] [unique_id "ajZvTvQhC6pTmH4hcMS-bQAAARg"], referer https://www.google.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[406169] [QPLnG23aZJ8] [ajZvTvQhC6pTmH4hcMS-bQAAARg] keep_alive=[1] [2026-06-20 17:45:34.874297] [R:ajZvTvQhC6pTmH4hcMS-bQAAARg] UA:'Mozilla/5.0 (Linux; And
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-06-11 23:30:46
(2 weeks ago)
[Fri Jun 12 06:30:41.947422 2026] [security2:error] [pid 2062965:tid 139768487728832] [client 31.132 ...
show more
[Fri Jun 12 06:30:41.947422 2026] [security2:error] [pid 2062965:tid 139768487728832] [client 31.132.54.23:47804] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.bing.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "582"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.bing.go.id found within REQUEST_HEADERS:Referer: https://www.bing.go.id/ request_line = GET /index.php/informasi-iklim/infografis-iklim/infografis-tahunan HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/informasi-iklim/infografis-iklim/infografis-tahunan"] [unique_id "aitFIckY-1sq3XUplO1B1gAATgE"], referer https://www.bing.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[2062967] [7Q6MvwIE+I0] [aitFIckY-1sq3XUplO1B1gAATgE] keep_alive=[1] [2026-06-12 06:30:41.947440] [R:aitFIckY-1sq3XUplO1B1gAATgE] UA:'Mozilla/5.0 (Linux; Android 14; Pixel 6 Pro) AppleW
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-06-05 09:23:40
(3 weeks ago)
[Fri Jun 05 16:23:36.482616 2026] [authz_core:error] [pid 898952:tid 140021874792128] [client 31.132 ...
show more
[Fri Jun 05 16:23:36.482616 2026] [authz_core:error] [pid 898952:tid 140021874792128] [client 31.132.54.23:41752] AH01630: client denied by server configuration: /var/www/index.php, referer https://staklim-jatim.bmkg.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[898981] [Ti0gN/6fB2s] [aiKVmPL9Nslg9TnXscOd-wABTAA] keep_alive=[1] [2026-06-05 16:23:36.482623] [R:aiKVmPL9Nslg9TnXscOd-wABTAA] UA:'Mozilla/5.0 (iPhone; CPU iPhone OS 18_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.0 Mobile/15E148 Safari/604.1' Host:'staklim-jatim.bmkg.go.id:443' ACCEPT:'text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8' Referer:'https://staklim-jatim.bmkg.go.id/ Accept-Encoding:'gzip, deflate, br Accept-Language:'en-US,en;q=0.8
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-06-04 10:20:55
(3 weeks ago)
[Thu Jun 04 17:20:51.021699 2026] [security2:error] [pid 156593:tid 140506634806976] [client 31.132. ...
show more
[Thu Jun 04 17:20:51.021699 2026] [security2:error] [pid 156593:tid 140506634806976] [client 31.132.54.23:53338] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.google.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "582"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.google.go.id found within REQUEST_HEADERS:Referer: https://www.google.go.id/ request_line = GET /images/Klimatologi/Konferensi_Pers/2024/SIARAN_PERS_BMKG_Waspada_Bencana_Hidrometeorologi_La_Nina_Berlangsung_Hingga_April_2025.webp HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/Klimatologi/Konferensi_Pers/2024/SIARAN_PERS_BMKG_Waspada_Bencana_Hidrometeorologi_La_Nina_Berlangsung_Hingga_April_2025.webp"] [unique_id "aiFRg0vWumO63qUvTsDklgABTxg"], referer https://www.google.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[156618] [MAgA5qoGT2Q] [aiFRg0vWumO6
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-06-02 05:32:16
(3 weeks ago)
[Tue Jun 02 12:32:10.386187 2026] [security2:error] [pid 168823:tid 139858080089792] [client 31.132. ...
show more
[Tue Jun 02 12:32:10.386187 2026] [security2:error] [pid 168823:tid 139858080089792] [client 31.132.54.23:11736] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.bmkg.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "582"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.bmkg.go.id found within REQUEST_HEADERS:Referer: https://www.bmkg.go.id/ request_line = GET /index.php/e-buletin-untuk-kota-dan-kabupaten-di-provinsi-jawa-timur HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/e-buletin-untuk-kota-dan-kabupaten-di-provinsi-jawa-timur"] [unique_id "ah5q2nl5KbkE_8rZoWTR9gABQxU"], referer https://www.bmkg.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[168845] [tW/toT5GVFw] [ah5q2nl5KbkE_8rZoWTR9gABQxU] keep_alive=[1] [2026-06-02 12:32:10.386192] [R:ah5q2nl5KbkE_8rZoWTR9gABQxU] UA:'Mozilla/5.0 (Linux; Android 12; SM-S901B)
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-05-31 00:23:27
(3 weeks ago)
[Sun May 31 07:23:26.693988 2026] [security2:error] [pid 734619:tid 140573603210944] [client 31.132. ...
show more
[Sun May 31 07:23:26.693988 2026] [security2:error] [pid 734619:tid 140573603210944] [client 31.132.54.23:41602] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.yandex.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "582"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.yandex.go.id found within REQUEST_HEADERS:Referer: https://www.yandex.go.id/ request_line = GET /index.php/informasi-iklim/infografis-iklim/infografis-bulanan/infografis-bulanan-buletin HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/informasi-iklim/infografis-iklim/infografis-bulanan/infografis-bulanan-buletin"] [unique_id "aht_fjJPASWlEnZBdxg7jwAAzww"], referer https://www.yandex.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[734632] [RQwlFlI9cvc] [aht_fjJPASWlEnZBdxg7jwAAzww] keep_alive=[1] [2026-05-31 07:23:26.693993] [R:aht_fjJPASWlEnZBdxg7jwAA
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-05-26 03:57:00
(1 month ago)
[Tue May 26 10:56:55.885723 2026] [security2:error] [pid 541112:tid 140291049768640] [client 31.132. ...
show more
[Tue May 26 10:56:55.885723 2026] [security2:error] [pid 541112:tid 140291049768640] [client 31.132.54.23:9542] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.bmkg.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "624"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.bmkg.go.id found within REQUEST_HEADERS:Referer: https://www.bmkg.go.id/ request_line = GET /index.php/profil/meteorologi/geofisika/555558585-poster-antisipasi-gempa HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/geofisika/555558585-poster-antisipasi-gempa"] [unique_id "ahUaB-eCwPxM-WlR6F0RcQABCAI"], referer https://www.bmkg.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[541115] [zaVtfDDpmCw] [ahUaB-eCwPxM-WlR6F0RcQABCAI] keep_alive=[1] [2026-05-26 10:56:55.885729] [R:ahUaB-eCwPxM-WlR6F0RcQABCAI] UA:'Mozilla/5.0 (Linux; Android 8.0.
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-05-22 04:33:01
(1 month ago)
05/22/2026-11:32:57.835146 [Drop] [**] [1:2100000124:0] Suricata match TLS ja4 scan Uniq Zeek no 12 ...
show more
05/22/2026-11:32:57.835146 [Drop] [**] [1:2100000124:0] Suricata match TLS ja4 scan Uniq Zeek no 124 with hash_t12d1516h2_8daaf6152771_ea2cbcd64924 [**] [Classification: (null)] [Priority: 3] {TCP} 31.132.54.23:33872 -> 103.166.156.58:443
...
show less
Email Spam
Hacking