Trueforce Threat Report
09 Aug 2022
Automated report, trolling for resource vulnerabilities
Bad Web Bot
Web App Attack
ozisp.com.au
20 Jul 2022
RU_YANDEX-MNT_<33>1658372922 [1:2032979:1] ET SCAN Yandex Webcrawler User-Agent (YandexBot) [Classif ... show more RU_YANDEX-MNT_<33>1658372922 [1:2032979:1] ET SCAN Yandex Webcrawler User-Agent (YandexBot) [Classification: Not Suspicious Traffic] [Priority: 3] {TCP} 5.45.207.153:56048 show less
Hacking
hermawan
14 Jul 2022
[Fri Jul 15 05:41:43.380420 2022] [-:error] [pid 6670:tid 140729871480576] [client 5.45.207.153:5424 ... show more [Fri Jul 15 05:41:43.380420 2022] [-:error] [pid 6670:tid 140729871480576] [client 5.45.207.153:54242] [client 5.45.207.153] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-sifat-hujan-bulanan/555559170-prakiraan-bulanan-sifat-hujan-bulan-maret-tahun-2022-update-dari-analisis-bulan-november-tahun-2021-di-provinsi-jawa-timur HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-sifat-hujan-bulanan/555559170-prakiraan-bulanan-sifat-hujan-bulan-maret-tahun-2022-update-dari-analisis-bulan-november-tahu
... show less
Hacking
Web App Attack
hermawan
14 Jul 2022
[Thu Jul 14 12:17:07.003863 2022] [-:error] [pid 126774:tid 140730332849920] [client 5.45.207.153:39 ... show more [Thu Jul 14 12:17:07.003863 2022] [-:error] [pid 126774:tid 140730332849920] [client 5.45.207.153:39426] [client 5.45.207.153] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/informasi-iklim/infografis-iklim/infografis-bulanan/infografis-bulanan-buletin/555559075-infografis-bulanan-prakiraan-hujan-bulan-november-desember-tahun-2021-bulan-januari-tahun-2022-update-dari-analisis-bulan-september-2021-di-provinsi-jawa-timur HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/index.php/informasi-iklim/infografis-iklim/infografis-bulanan/infografis-bulanan-buletin/555559075-infografis-bulanan-prakiraan-huja
... show less
Hacking
Web App Attack
hermawan
13 Jul 2022
[Thu Jul 14 02:31:22.903422 2022] [-:error] [pid 6338:tid 140732421617408] [client 5.45.207.153:5509 ... show more [Thu Jul 14 02:31:22.903422 2022] [-:error] [pid 6338:tid 140732421617408] [client 5.45.207.153:55092] [client 5.45.207.153] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php?option=com_content&view=article&id=122&catid=343&Itemid=1090 HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php"] [unique_id "Ys8dirYisYu39KPkqJWKfgAABSM"] [karangploso.jatim.bmkg.go.id] [karangploso.jatim.bmkg.go.id] top=[6933] [WnKB1FQtSLo] [Ys8dirYisYu39KPkqJWKfgAABSM] keep_alive=[0] [2022-07-14 02:31:22.903429] [R:Ys8dirYisYu39KPkqJWKfgAABSM] UA:'Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bot
... show less
Hacking
Web App Attack
hermawan
12 Jul 2022
[Wed Jul 13 10:33:05.561931 2022] [-:error] [pid 6479:tid 140727522670336] [client 5.45.207.153:5685 ... show more [Wed Jul 13 10:33:05.561931 2022] [-:error] [pid 6479:tid 140727522670336] [client 5.45.207.153:56854] [client 5.45.207.153] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/analisis-iklim/analisis-musim/perbandingan-awal-musim-hujan-dengan-normalnya HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/analisis-iklim/analisis-musim/perbandingan-awal-musim-hujan-dengan-normalnya"] [unique_id "Ys488f_4_a3xPNDnKjJaMgAABqk"] [karangploso.jatim.bmkg.go.id] [karangploso.jatim.bmkg.go.id] top=[7267] [OyJmccfiDLo] [Ys488f_4_a3xPNDnKjJaMgAABqk] keep_alive=[0] [2022-07-13 10:33:05.561936] [R:Ys
... show less
Hacking
Web App Attack
hermawan
12 Jul 2022
[Wed Jul 13 02:35:09.514698 2022] [-:error] [pid 69059:tid 140733059168000] [client 5.45.207.153:644 ... show more [Wed Jul 13 02:35:09.514698 2022] [-:error] [pid 69059:tid 140733059168000] [client 5.45.207.153:64460] [client 5.45.207.153] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/profil/meteorologi/list-all-categories/3962-klimatologi/infografis/infografis-klimatologi/infografis-dasarian/infografis-dasarian-tahun-2019/555557193-infografis-dasarian-di-provinsi-jawa-timur-update-20-maret-2019 HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/list-all-categories/3962-klimatologi/infografis/infografis-klimatologi/infografis-dasarian/infografis-dasarian-tahun-2019/5555571
... show less
Hacking
Web App Attack
hermawan
11 Jul 2022
[Tue Jul 12 06:29:00.809848 2022] [-:error] [pid 6910:tid 140727480739584] [client 5.45.207.153:3524 ... show more [Tue Jul 12 06:29:00.809848 2022] [-:error] [pid 6910:tid 140727480739584] [client 5.45.207.153:35242] [client 5.45.207.153] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/prakiraan-musim/4104-prakiraan-musim-kemarau/prakiraan-puncak-musim-kemarau/prakiraan-puncak-musim-kemarau-zona-musim-di-provinsi-jawa-timur/prakiraan-puncak-musim-kemarau-tahun-2021-zona-musim-di-provinsi-jawa-timur HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/prakiraan-musim/4104-prakiraan-musim-kemarau/prakiraan-puncak-musim-kemarau/prakiraan-puncak-musim-kemarau-zona-musim-di-provinsi-jawa-timur/prakir
... show less
Hacking
Web App Attack
hermawan
10 Jul 2022
[Mon Jul 11 10:41:36.831346 2022] [-:error] [pid 6332:tid 140727572993792] [client 5.45.207.153:4668 ... show more [Mon Jul 11 10:41:36.831346 2022] [-:error] [pid 6332:tid 140727572993792] [client 5.45.207.153:46682] [client 5.45.207.153] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/profil/meteorologi/list-of-all-tags/4398 HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/list-of-all-tags/4398"] [unique_id "Ysub8B931TcW0jUf-ti0UAAABq0"] [karangploso.jatim.bmkg.go.id] [karangploso.jatim.bmkg.go.id] top=[7270] [vHkvVB/wNbo] [Ysub8B931TcW0jUf-ti0UAAABq0] keep_alive=[0] [2022-07-11 10:41:36.831353] [R:Ysub8B931TcW0jUf-ti0UAAABq0] UA:'Mozilla/5.0 (compatible; YandexBot/3.0; +
... show less
Hacking
Web App Attack
hermawan
10 Jul 2022
[Mon Jul 11 09:11:41.590368 2022] [-:error] [pid 7139:tid 140732379686656] [client 5.45.207.153:3481 ... show more [Mon Jul 11 09:11:41.590368 2022] [-:error] [pid 7139:tid 140732379686656] [client 5.45.207.153:34816] [client 5.45.207.153] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/analisis-bulanan/3973-analisis-bulanan-tingkat-ketersediaan-air-bagi-tanaman/analisis-bulanan-tingkat-ketersediaan-air-bagi-tanaman-di-provinsi-jawa-timur HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/analisis-bulanan/3973-analisis-bulanan-tingkat-ketersediaan-air-bagi-tanaman/analisis-bulanan-tingkat-ketersediaan-air-bagi-tanaman-di-provinsi-jawa-timur"] [unique_id "YsuG3QG_CZey3pydQ1L6bAAABmI"] [karangplo
... show less
Hacking
Web App Attack
hermawan
10 Jul 2022
[Sun Jul 10 23:14:24.867019 2022] [-:error] [pid 16083:tid 140734518777600] [client 5.45.207.153:424 ... show more [Sun Jul 10 23:14:24.867019 2022] [-:error] [pid 16083:tid 140734518777600] [client 5.45.207.153:42486] [client 5.45.207.153] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/prakiraan-bulanan/3874-prakiraan-sifat-hujan-bulanan/prakiraan-sifat-hujan-bulanan-di-propinsi-jawa-timur/prakiraan-sifat-hujan-bulanan-di-propinsi-jawa-timur-tahun-2018/555556496-prakiraan-sifat-hujan-bulan-agustus-tahun-2018-jawa-timur-update-dari-analisis-bulan-mei-tahun-2018 HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/prakiraan-bulanan/3874-prakiraan-sifat-hujan-bulanan/prakiraan-sifat-hujan-bulanan-
... show less
Hacking
Web App Attack
hermawan
10 Jul 2022
[Sun Jul 10 14:34:49.801965 2022] [-:error] [pid 7460:tid 140727505884928] [client 5.45.207.153:6474 ... show more [Sun Jul 10 14:34:49.801965 2022] [-:error] [pid 7460:tid 140727505884928] [client 5.45.207.153:64746] [client 5.45.207.153] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/monitoring-hari-tanpa-hujan-berturut-turut/3881-monitoring-hari-tanpa-hujan-berturut-turut-indonesia/monitoring-hari-tanpa-hujan-berturut-turut-indonesia-tahun-2018/555556703-monitoring-hari-tanpa-hujan-berturut-turut-di-indonesia-pemutakhiran-10-september-2018 HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/monitoring-hari-tanpa-hujan-berturut-turut/3881-monitoring-hari-tanpa-hujan-berturut-turut-indonesia/m
... show less
Hacking
Web App Attack
hermawan
09 Jul 2022
[Sun Jul 10 00:05:45.559439 2022] [-:error] [pid 102188:tid 140729628223232] [client 5.45.207.153:42 ... show more [Sun Jul 10 00:05:45.559439 2022] [-:error] [pid 102188:tid 140729628223232] [client 5.45.207.153:42022] [client 5.45.207.153] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /robots.txt HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/robots.txt"] [unique_id "Ysm1acSk_WagdnSWJRznnQAAAEo"] [karangploso.jatim.bmkg.go.id] [karangploso.jatim.bmkg.go.id] top=[102390] [V8paVML5rLs] [Ysm1acSk_WagdnSWJRznnQAAAEo] keep_alive=[0] [2022-07-10 00:05:45.559447] [R:Ysm1acSk_WagdnSWJRznnQAAAEo] UA:'Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)' Host:'karangploso.jatim.bmkg.go.id' ACCEPT:'*/*'
... show less
Hacking
Web App Attack
hermawan
08 Jul 2022
[Sat Jul 09 00:00:36.655970 2022] [-:error] [pid 7105:tid 140727447136000] [client 5.45.207.153:6120 ... show more [Sat Jul 09 00:00:36.655970 2022] [-:error] [pid 7105:tid 140727447136000] [client 5.45.207.153:61204] [client 5.45.207.153] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/profil/meteorologi/list-of-all-tags/peraturan-kepala-badan-meteorologi-klimatologi-dan-geofisika-perka HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/list-of-all-tags/peraturan-kepala-badan-meteorologi-klimatologi-dan-geofisika-perka"] [unique_id "YshitCrUc1ZkXxjU0rWf8QAABXI"] [karangploso.jatim.bmkg.go.id] [karangploso.jatim.bmkg.go.id] top=[8038] [aN4ZJJ5fOLo] [YshitCrUc1ZkXxjU0rWf8QAABX
... show less
Hacking
Web App Attack
hermawan
07 Jul 2022
[Fri Jul 08 09:43:43.681662 2022] [-:error] [pid 5849:tid 140732270614272] [client 5.45.207.153:4175 ... show more [Fri Jul 08 09:43:43.681662 2022] [-:error] [pid 5849:tid 140732270614272] [client 5.45.207.153:41752] [client 5.45.207.153] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/buku/4087-buku-edisi-setiap-1-bulan-sekali/buku-analisis-dan-prakiraan-bulanan-jawa-timur/buletin-bulanan-analisis-dan-prakiraan-hujan-di-provinsi-jawa-timur-tahun-2021/555559108-buletin-bulanan-analisis-hujan-bulan-oktober-tahun-2021-dan-prakiraan-hujan-bulan-desember-tahun-2021-bulan-januari-februari-tahun-2022-provinsi-jawa-timur HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/buku/4087-buku-edisi-setiap-1
... show less
Hacking
Web App Attack