hermawan
2025-05-14 13:23:59
(1 day ago)
[Wed May 14 12:42:49.649622 2025] [security2:error] [pid 567092:tid 139645394343616] [client 40.84.2 ... show more [Wed May 14 12:42:49.649622 2025] [security2:error] [pid 567092:tid 139645394343616] [client 40.84.221.222:63630] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-curah-hujan-bulanan/6-bulan-ke-depan/555561139-prakiraan-bulanan-curah-hujan-di-kabupaten-sumenep-untuk-6-bulan-ke-depan HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-curah-hujan-bulanan/6-bulan-ke-depan/555561139-prakiraan-bulanan-curah-hujan-di-kabupaten-sumenep-untuk-6-bulan-ke-depan"] [uniq
... show less
Hacking
Web App Attack
Anonymous
2025-05-14 08:31:00
(1 day ago)
"Excessive,undesired traffic against library service"
Bad Web Bot
hermawan
2025-05-13 12:54:11
(2 days ago)
[Tue May 13 18:53:21.297093 2025] [security2:error] [pid 41502:tid 139997833144000] [client 40.84.22 ... show more [Tue May 13 18:53:21.297093 2025] [security2:error] [pid 41502:tid 139997833144000] [client 40.84.221.222:11511] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /index.php/component/tags/tag/182 HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/component/tags/tag/182"] [unique_id "aCMysRCbuQgD58WDjwPCnAACIS0"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[41548] [8Vw9FFvoQww] [aCMysRCbuQgD58WDjwPCnAACIS0] keep_alive=[1] [2025-05-13 18:53:21.297099] [R:aCMysRCbuQgD58WDjwPCnAACIS0] UA:'Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compat
... show less
Hacking
Web App Attack
hermawan
2025-05-13 05:48:56
(2 days ago)
[Tue May 13 12:35:51.698044 2025] [security2:error] [pid 91660:tid 140045305136832] [client 40.84.22 ... show more [Tue May 13 12:35:51.698044 2025] [security2:error] [pid 91660:tid 140045305136832] [client 40.84.221.222:30506] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /index.php/prediksi-iklim/prediksi-bulanan/sifat-hujan/3-bulan-ke-depan/555561853-prediksi-bulanan-sifat-hujan-bulan-mei-tahun-2025-update-dari-analisis-bulan-februari-tahun-2025-di-provinsi-jawa-timur HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/prediksi-iklim/prediksi-bulanan/sifat-hujan/3-bulan-ke-depan/555561853-prediksi-bulanan-sifat-hujan-bulan-mei-tahun-2025-update-dari-analisis-bulan
... show less
Hacking
Web App Attack
Anonymous
2025-05-12 19:46:33
(2 days ago)
Action: Block, Reason: DDOS attack detected
DDoS Attack
hermawan
2025-05-12 10:50:32
(3 days ago)
[Mon May 12 17:49:33.260847 2025] [security2:error] [pid 3394:tid 140135058269888] [client 40.84.221 ... show more [Mon May 12 17:49:33.260847 2025] [security2:error] [pid 3394:tid 140135058269888] [client 40.84.221.222:28270] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /robots.txt HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/robots.txt"] [unique_id "aCHSPZDUQ_R3T8CoNLItywAAQh0"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[3424] [xuQ7EpY7xTg] [aCHSPZDUQ_R3T8CoNLItywAAQh0] keep_alive=[1] [2025-05-12 17:49:33.260851] [R:aCHSPZDUQ_R3T8CoNLItywAAQh0] UA:'Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bo
... show less
Hacking
Web App Attack
hermawan
2025-05-12 00:42:22
(3 days ago)
[Mon May 12 07:22:13.375720 2025] [security2:error] [pid 1574244:tid 139771374352064] [client 40.84. ... show more [Mon May 12 07:22:13.375720 2025] [security2:error] [pid 1574244:tid 139771374352064] [client 40.84.221.222:11579] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /index.php/profil/meteorologi/list-of-all-tags/peta-zona-musim-di-provinsi-jawa-timur HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/list-of-all-tags/peta-zona-musim-di-provinsi-jawa-timur"] [unique_id "aCE_NbO2suPpLi5SzAM9FgAA2Rs"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[1574272] [gYi4Tj3khxA] [aCE_NbO2suPpLi5SzAM9FgAA2Rs] keep_alive=[1] [2025-05-12 07:
... show less
Hacking
Web App Attack
hermawan
2025-05-10 15:01:26
(5 days ago)
[Sat May 10 20:42:15.709359 2025] [security2:error] [pid 570604:tid 140600307193536] [client 40.84.2 ... show more [Sat May 10 20:42:15.709359 2025] [security2:error] [pid 570604:tid 140600307193536] [client 40.84.221.222:44090] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /index.php/profil/meteorologi/list-of-all-tags/gempa-terkini HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/list-of-all-tags/gempa-terkini"] [unique_id "aB9Xt5mVvNGCrhOO1FUq6gAAayU"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[570642] [QIQzQFDBsZ0] [aB9Xt5mVvNGCrhOO1FUq6gAAayU] keep_alive=[1] [2025-05-10 20:42:15.709367] [R:aB9Xt5mVvNGCrhOO1FUq6gAAayU] UA:'Mo
... show less
Hacking
Web App Attack
hermawan
2025-05-10 12:16:12
(5 days ago)
[Sat May 10 18:16:11.787179 2025] [security2:error] [pid 504488:tid 140584996714176] [client 40.84.2 ... show more [Sat May 10 18:16:11.787179 2025] [security2:error] [pid 504488:tid 140584996714176] [client 40.84.221.222:20159] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /index.php/profil/meteorologi/list-of-all-tags/prakiraan-awal-musim-kemarau HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/list-of-all-tags/prakiraan-awal-musim-kemarau"] [unique_id "aB81e8ly9N9wUW7il44XygAA7Bg"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[504513] [U+zTNR7FPvY] [aB81e8ly9N9wUW7il44XygAA7Bg] keep_alive=[1] [2025-05-10 18:16:11.787185] [R:aB81e
... show less
Hacking
Web App Attack
MAGIC
2025-05-09 18:08:44
(6 days ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
hermawan
2025-05-09 14:18:07
(6 days ago)
[Fri May 09 20:46:58.039097 2025] [security2:error] [pid 24782:tid 140586319337152] [client 40.84.22 ... show more [Fri May 09 20:46:58.039097 2025] [security2:error] [pid 24782:tid 140586319337152] [client 40.84.221.222:40172] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /index.php/analisis-iklim/analisis-musim/perbandingan/perbandingan-awal-musim-hujan-dengan-normalnya HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/index.php/analisis-iklim/analisis-musim/perbandingan/perbandingan-awal-musim-hujan-dengan-normalnya"] [unique_id "aB4HUgnoPuCyJo-85z-kAQAACQE"] [staklim-malang.info] [staklim-malang.info] top=[24784] [uiYwM8x3GU4] [aB4HUgnoPuCyJo-85z-kAQAACQE] keep_alive=[1] [202
... show less
Hacking
Web App Attack
hermawan
2025-05-09 10:49:08
(6 days ago)
[Fri May 09 17:19:39.534388 2025] [security2:error] [pid 19315:tid 139842314540736] [client 40.84.22 ... show more [Fri May 09 17:19:39.534388 2025] [security2:error] [pid 19315:tid 139842314540736] [client 40.84.221.222:19062] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /index.php/profil/meteorologi/list-of-all-tags/normal-awal-musim-kemarau-propinsi-jawa-timur HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/list-of-all-tags/normal-awal-musim-kemarau-propinsi-jawa-timur"] [unique_id "aB3Wu8e2iacXdVT0Ii_wOQAAiCk"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[19357] [wo3LTcnpVUQ] [aB3Wu8e2iacXdVT0Ii_wOQAAiCk] keep_alive=[1] [2025
... show less
Hacking
Web App Attack
hermawan
2025-05-09 09:31:32
(6 days ago)
[Fri May 09 16:07:50.450637 2025] [security2:error] [pid 810354:tid 139902362457792] [client 40.84.2 ... show more [Fri May 09 16:07:50.450637 2025] [security2:error] [pid 810354:tid 139902362457792] [client 40.84.221.222:9893] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /index.php/profil/meteorologi/list-of-all-tags/normal-awal-musim-kemarau-propinsi-jawa-timur HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/index.php/profil/meteorologi/list-of-all-tags/normal-awal-musim-kemarau-propinsi-jawa-timur"] [unique_id "aB3F5vIinYTCJnDbZyOYqgAAYTE"] [staklim-malang.info] [staklim-malang.info] top=[810404] [Ua/zTGjj3vk] [aB3F5vIinYTCJnDbZyOYqgAAYTE] keep_alive=[1] [2025-05-09 16:07:5
... show less
Hacking
Web App Attack
hermawan
2025-05-09 03:52:12
(6 days ago)
[Fri May 09 10:42:25.492828 2025] [security2:error] [pid 599481:tid 139687491487424] [client 40.84.2 ... show more [Fri May 09 10:42:25.492828 2025] [security2:error] [pid 599481:tid 139687491487424] [client 40.84.221.222:33541] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-curah-hujan-bulanan/3-bulan-ke-depan/555561555-prakiraan-bulanan-curah-hujan-bulan-februari-tahun-2025-update-dari-analisis-bulan-oktober-tahun-2024-di-provinsi-jawa-timur HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-curah-hujan-bulanan/3-bulan-ke-depan/555561555-prakiraan-bulanan-curah-hujan-
... show less
Hacking
Web App Attack
hermawan
2025-05-08 07:37:44
(1 week ago)
[Thu May 08 14:03:10.613535 2025] [security2:error] [pid 52042:tid 140057243530944] [client 40.84.22 ... show more [Thu May 08 14:03:10.613535 2025] [security2:error] [pid 52042:tid 140057243530944] [client 40.84.221.222:64064] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /b/bulanansurabaya.pdf HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/b/bulanansurabaya.pdf"] [unique_id "aBxXLgCpuNHORChlhO4GTAAAggQ"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[52047] [sopHcQLEdQY] [aBxXLgCpuNHORChlhO4GTAAAggQ] keep_alive=[1] [2025-05-08 14:03:10.613539] [R:aBxXLgCpuNHORChlhO4GTAAAggQ] UA:'Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0
... show less
Hacking
Web App Attack