hermawan
2025-05-17 03:45:07
(4 hours ago)
[Sat May 17 10:11:44.893119 2025] [security2:error] [pid 42780:tid 140057711179456] [client 52.230.1 ... show more [Sat May 17 10:11:44.893119 2025] [security2:error] [pid 42780:tid 140057711179456] [client 52.230.164.182:56978] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /b/bulanansurabaya.pdf HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/b/bulanansurabaya.pdf"] [unique_id "aCf-cGh5UyvePKPxz4sKugAA6gg"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[42790] [pI8yQpShEJ4] [aCf-cGh5UyvePKPxz4sKugAA6gg] keep_alive=[1] [2025-05-17 10:11:44.893124] [R:aCf-cGh5UyvePKPxz4sKugAA6gg] UA:'Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.
... show less
Hacking
Web App Attack
hermawan
2025-05-15 23:06:37
(1 day ago)
[Fri May 16 06:05:28.277853 2025] [security2:error] [pid 55192:tid 140683010447040] [client 52.230.1 ... show more [Fri May 16 06:05:28.277853 2025] [security2:error] [pid 55192:tid 140683010447040] [client 52.230.164.182:19807] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /index.php/component/tags/tag/182-prakiraan-awal-musim-hujan HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/component/tags/tag/182-prakiraan-awal-musim-hujan"] [unique_id "aCZzOFKSLTQW7z-akhKuawAAES4"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[55291] [r8iZsyzOkI4] [aCZzOFKSLTQW7z-akhKuawAAES4] keep_alive=[1] [2025-05-16 06:05:28.277860] [R:aCZzOFKSLTQW7z-akhKuawAAES4] UA:'Moz
... show less
Hacking
Web App Attack
MAGIC
2025-05-15 21:21:59
(1 day ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Anonymous
2025-05-14 09:57:00
(2 days ago)
"Excessive,undesired traffic against library service"
Bad Web Bot
rsa
2025-05-13 17:41:00
(3 days ago)
excessive crawling/scraping
DDoS Attack
Bad Web Bot
Web App Attack
hermawan
2025-05-13 10:51:12
(3 days ago)
[Tue May 13 17:47:55.857078 2025] [security2:error] [pid 4198:tid 139997885609664] [client 52.230.16 ... show more [Tue May 13 17:47:55.857078 2025] [security2:error] [pid 4198:tid 139997885609664] [client 52.230.164.182:22159] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-curah-hujan-bulanan/3-bulan-ke-depan/555561744-prakiraan-bulanan-curah-hujan-bulan-maret-tahun-2025-update-dari-analisis-bulan-januari-tahun-2025-di-provinsi-jawa-timur HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-curah-hujan-bulanan/3-bulan-ke-depan/555561744-prakiraan-bulanan-curah-hujan-bulan-mar
... show less
Hacking
Web App Attack
hermawan
2025-05-13 05:45:39
(4 days ago)
[Tue May 13 12:31:49.436030 2025] [security2:error] [pid 89848:tid 140045170853568] [client 52.230.1 ... show more [Tue May 13 12:31:49.436030 2025] [security2:error] [pid 89848:tid 140045170853568] [client 52.230.164.182:16661] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-sifat-hujan-bulanan/prakiraan-sifat-hujan-untuk-6-bulan-ke-depan/555561211-prakiraan-bulanan-sifat-hujan-di-kabupaten-tulungagung-untuk-6-bulan-ke-depan-2 HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-sifat-hujan-bulanan/prakiraan-sifat-hujan-untuk-6-bulan-ke-depan/555561211-prakiraan-bulanan-sifat-
... show less
Hacking
Web App Attack
hermawan
2025-05-12 11:16:49
(4 days ago)
[Mon May 12 18:00:28.687737 2025] [security2:error] [pid 8016:tid 140134863165120] [client 52.230.16 ... show more [Mon May 12 18:00:28.687737 2025] [security2:error] [pid 8016:tid 140134863165120] [client 52.230.164.182:26399] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-sifat-hujan-bulanan/prakiraan-sifat-hujan-untuk-6-bulan-ke-depan/555561183-prakiraan-bulanan-sifat-hujan-di-kabupaten-nganjuk-untuk-6-bulan-ke-depan-2 HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-sifat-hujan-bulanan/prakiraan-sifat-hujan-untuk-6-bulan-ke-depan/555561183-prakiraan-bulanan-sifat-hujan
... show less
Hacking
Web App Attack
hermawan
2025-05-12 09:18:34
(4 days ago)
[Mon May 12 16:08:30.581287 2025] [security2:error] [pid 37397:tid 139817885001408] [client 52.230.1 ... show more [Mon May 12 16:08:30.581287 2025] [security2:error] [pid 37397:tid 139817885001408] [client 52.230.164.182:21764] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /index.php/normal-klimatologi/198-normal-awal-musim/normal-awal-musim-kemarau/normal-awal-musim-kemarau-propinsi-jawa-timur HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/index.php/normal-klimatologi/198-normal-awal-musim/normal-awal-musim-kemarau/normal-awal-musim-kemarau-propinsi-jawa-timur"] [unique_id "aCG6jh5odntCu1pN0ULvgAAALxk"] [staklim-malang.info] [staklim-malang.info] top=[37423] [Z3TeqPT7Jl8] [a
... show less
Hacking
Web App Attack
hermawan
2025-05-12 02:26:20
(5 days ago)
[Mon May 12 09:15:56.231889 2025] [security2:error] [pid 1619479:tid 139771502753472] [client 52.230 ... show more [Mon May 12 09:15:56.231889 2025] [security2:error] [pid 1619479:tid 139771502753472] [client 52.230.164.182:64216] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /index.php/prakiraan-bulanan/4293-prakiraan-curah-hujan-bulanan/prakiraan-curah-hujan-bulanan-di-propinsi-jawa-timur/prakiraan-bulanan-curah-hujan-di-propinsi-jawa-timur-tahun-2025/555561746-prakiraan-bulanan-curah-hujan-bulan-mei-tahun-2025-update-dari-analisis-bulan-januari-tahun-2025-di-provinsi-jawa-timur HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/index.php/prakiraan-bulanan/4293-prakiraan-curah-h
... show less
Hacking
Web App Attack
Anonymous
2025-05-11 09:10:43
(5 days ago)
Action: Block, Reason: DDOS attack detected
DDoS Attack
masterguru
2025-05-11 04:15:59
(6 days ago)
BAD BOT - Detected and Blocked.. Matched phrase "ChatGPT-User" at REQUEST_HEADERS:User-Agent. (11000 ... show more BAD BOT - Detected and Blocked.. Matched phrase "ChatGPT-User" at REQUEST_HEADERS:User-Agent. (1100000-173) show less
Bad Web Bot
Pingu
2025-05-11 03:00:02
(6 days ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/2 ... show more Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot show less
Bad Web Bot
hermawan
2025-05-10 16:34:23
(6 days ago)
[Sat May 10 22:24:53.927234 2025] [security2:error] [pid 621526:tid 140600261015232] [client 52.230. ... show more [Sat May 10 22:24:53.927234 2025] [security2:error] [pid 621526:tid 140600261015232] [client 52.230.164.182:50546] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /index.php/profil/meteorologi/list-of-all-tags/prakiraan-puncak-musim-hujan-musim-hujan-di-provinsi-jawa-timur HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/list-of-all-tags/prakiraan-puncak-musim-hujan-musim-hujan-di-provinsi-jawa-timur"] [unique_id "aB9vxbHQNdYRdgj0DdhstgAASTA"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[621575] [HudBrzHe+oY] [aB9vxbHQNd
... show less
Hacking
Web App Attack
hermawan
2025-05-10 10:38:03
(6 days ago)
[Sat May 10 17:22:48.335805 2025] [security2:error] [pid 481634:tid 140585704736448] [client 52.230. ... show more [Sat May 10 17:22:48.335805 2025] [security2:error] [pid 481634:tid 140585704736448] [client 52.230.164.182:8955] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /index.php/profil/meteorologi/list-of-all-tags/infografis-dasarian HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/list-of-all-tags/infografis-dasarian"] [unique_id "aB8o-Idn-O0zzgadnreGzQAA0iI"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[481669] [Nujjdt2lkyA] [aB8o-Idn-O0zzgadnreGzQAA0iI] keep_alive=[1] [2025-05-10 17:22:48.335810] [R:aB8o-Idn-O0zzgadnreGzQA
... show less
Hacking
Web App Attack