๐ฎ๐ฉ
hermawan
2025-07-13 20:35:02
(10 months ago)
[Mon Jul 14 03:34:28.612664 2025] [security2:error] [pid 256763:tid 140524787840704] [client 47.128. ...
show more
[Mon Jul 14 03:34:28.612664 2025] [security2:error] [pid 256763:tid 140524787840704] [client 47.128.126.66:61418] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Feed" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "228"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Feed found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; [email protected] ) request_line = GET /index.php/analisis-bulanan/4041-analisis-distribusi-hujan/analisis-distribusi-curah-hujan/analisis-distribusi-curah-hujan-jawa-timur-bulanan/analisis-bulanan-distribusi-curah-hujan-tahun-2020/555557893-analisis-bulanan-distribusi-curah-hujan-bulan-januari-tahun-2020-di-provinsi-j..."] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/analisis-bulanan/4041-analisi
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-10 19:26:55
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 47.128.126.66 (ec2-47-128-126-66.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.126.66 (ec2-47-128-126-66.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 10 15:26:51.604435 2025] [security2:error] [pid 28626:tid 28626] [client 47.128.126.66:31542] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.pages4you.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.pages4you.com"] [uri "/dj/graphics/Andrews/WS_FTP.LOG"] [unique_id "aHAT-w0oPrrHjlJpCK7mYwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2025-07-01 10:30:08
(11 months ago)
Detected attack by Imunify360
Brute-Force
Web App Attack
๐ฎ๐ฉ
hermawan
2025-06-30 16:26:25
(11 months ago)
[Mon Jun 30 23:25:54.690481 2025] [security2:error] [pid 20808:tid 139943467775680] [client 47.128.1 ...
show more
[Mon Jun 30 23:25:54.690481 2025] [security2:error] [pid 20808:tid 139943467775680] [client 47.128.126.66:48672] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Feed" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.15.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "225"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Feed found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; [email protected] ) request_line = GET /index.php/prakiraan-cuaca-daerah-malang-dan-batu-seminggu-ke-depan/3936-prakiraan-cuaca-daerah-malang-dan-batu-seminggu-ke-depan-tahun-2019/985-prakiraan-mingguan-cuaca-daerah-malang-dan-batu-seminggu-ke-depan-berlaku-20-26-agustus-2019 HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/prakiraan-cuaca-daerah-malang-dan-batu-seminggu-ke-depan/3936-prakir
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-27 03:01:24
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 47.128.126.66 (ec2-47-128-126-66.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.126.66 (ec2-47-128-126-66.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 26 23:01:20.993998 2025] [security2:error] [pid 1938693:tid 1938693] [client 47.128.126.66:25446] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.informativearticles.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.informativearticles.com"] [uri "/[email protected] "] [unique_id "aF4JgIAzgeDHgdXg24BCBwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-06-21 03:16:09
(11 months ago)
Excessive crawling/scraping
Hacking
Brute-Force
๐ฆ๐บ
MAGIC
2025-06-20 09:04:54
(11 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ฎ๐น
VHosting
2025-06-13 07:50:11
(11 months ago)
Detected attack by Imunify360
Brute-Force
Web App Attack
Anonymous
2025-06-11 00:45:45
(11 months ago)
Ports: 80,443; Direction: 1; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฎ๐ฉ
hermawan
2025-06-10 12:19:55
(11 months ago)
[Tue Jun 10 19:19:02.624516 2025] [security2:error] [pid 16065:tid 140091103110848] [client 47.128.1 ...
show more
[Tue Jun 10 19:19:02.624516 2025] [security2:error] [pid 16065:tid 140091103110848] [client 47.128.126.66:15888] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Feed" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Feed found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; [email protected] ) request_line = GET /index.php/profil/arsip-artikel?catid=632&id=555555602%3Aprakiraan-cuaca-daerah-malang-dan-batu-seminggu-ke-depan-berlaku-tanggal-11-17-april-2017&start=20 HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/profil/arsip-artikel"] [unique_id "aEgitr1pkZPk_x-MXprvGgAAjAQ"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[16070] [w72ps26wutg] [aEgi
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-08 09:12:51
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 47.128.126.66 (ec2-47-128-126-66.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.126.66 (ec2-47-128-126-66.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 08 05:12:44.482700 2025] [security2:error] [pid 2606574:tid 2606574] [client 47.128.126.66:55872] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.med-engineering.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.med-engineering.com"] [uri "/emoks.com"] [unique_id "aEVUDOGrLSr_BdV6KTw_fQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2025-06-07 16:09:33
(11 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Anonymous
2025-06-01 11:09:56
(1 year ago)
Excessive crawling/scraping
Hacking
Brute-Force
๐บ๐ธ
masterguru
2025-05-31 00:23:05
(1 year ago)
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:User-Agent. (1100000 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:User-Agent. (1100000-181)
show less
Bad Web Bot
๐ฆ๐บ
MAGIC
2025-05-20 16:05:14
(1 year ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot