MAGIC
2025-06-20 08:02:25
(6 hours ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
unph
2025-06-17 03:27:51
(3 days ago)
Intento de acceso sospechoso en el login de WordPress
Brute-Force
Anonymous
2025-06-16 19:03:50
(3 days ago)
Action: Block, Reason: DDOS attack detected
DDoS Attack
hermawan
2025-06-16 12:52:46
(4 days ago)
[Mon Jun 16 19:51:50.756193 2025] [security2:error] [pid 154915:tid 140535309149888] [client 52.230. ... show more [Mon Jun 16 19:51:50.756193 2025] [security2:error] [pid 154915:tid 140535309149888] [client 52.230.164.186:25313] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.15.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "205"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /robots.txt HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/robots.txt"] [unique_id "aFATZvemVF6DAkz18IPaXAAAwx0"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[154945] [NEEH3DeAmho] [aFATZvemVF6DAkz18IPaXAAAwx0] keep_alive=[1] [2025-06-16 19:51:50.756199] [R:aFATZvemVF6DAkz18IPaXAAAwx0] UA:'Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.c
... show less
Hacking
Web App Attack
construct.net
2025-06-16 09:39:28
(4 days ago)
Triggered rate limiter [PRD-VM-WEB1a]
Bad Web Bot
hermawan
2025-06-15 03:26:49
(5 days ago)
[Sun Jun 15 10:21:03.807450 2025] [security2:error] [pid 229559:tid 140215397086912] [client 52.230. ... show more [Sun Jun 15 10:21:03.807450 2025] [security2:error] [pid 229559:tid 140215397086912] [client 52.230.164.186:6732] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /robots.txt HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/robots.txt"] [unique_id "aE48H-wIpfimWvfZXhiSuwAABAk"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[229569] [GAjpxIu1H7Y] [aE48H-wIpfimWvfZXhiSuwAABAk] keep_alive=[1] [2025-06-15 10:21:03.807456] [R:aE48H-wIpfimWvfZXhiSuwAABAk] UA:'Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.co
... show less
Hacking
Web App Attack
hermawan
2025-06-13 07:56:51
(1 week ago)
[Fri Jun 13 14:55:48.929373 2025] [security2:error] [pid 75191:tid 140168437688000] [client 52.230.1 ... show more [Fri Jun 13 14:55:48.929373 2025] [security2:error] [pid 75191:tid 140168437688000] [client 52.230.164.186:23890] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /robots.txt HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/robots.txt"] [unique_id "aEvZhGiM9aYItWg5QSmr0wABBQI"] [staklim-malang.info] [staklim-malang.info] top=[75194] [T5zQX3cFiIw] [aEvZhGiM9aYItWg5QSmr0wABBQI] keep_alive=[1] [2025-06-13 14:55:48.929378] [R:aEvZhGiM9aYItWg5QSmr0wABBQI] UA:'Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot' Host:'sta
... show less
Hacking
Web App Attack
hermawan
2025-06-13 05:31:14
(1 week ago)
[Fri Jun 13 12:27:10.931363 2025] [security2:error] [pid 5645:tid 140371981665984] [client 52.230.16 ... show more [Fri Jun 13 12:27:10.931363 2025] [security2:error] [pid 5645:tid 140371981665984] [client 52.230.164.186:5754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /robots.txt HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/robots.txt"] [unique_id "aEu2rulSs8VqFOniPZA-fgACCwQ"] [staklim-malang.info] [staklim-malang.info] top=[5650] [CFpDTPVszys] [aEu2rulSs8VqFOniPZA-fgACCwQ] keep_alive=[1] [2025-06-13 12:27:10.931372] [R:aEu2rulSs8VqFOniPZA-fgACCwQ] UA:'Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot' Host:'stakli
... show less
Hacking
Web App Attack
hermawan
2025-06-12 22:14:07
(1 week ago)
[Fri Jun 13 05:14:04.801278 2025] [security2:error] [pid 134047:tid 140166544651968] [client 52.230. ... show more [Fri Jun 13 05:14:04.801278 2025] [security2:error] [pid 134047:tid 140166544651968] [client 52.230.164.186:46353] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /robots.txt HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/robots.txt"] [unique_id "aEtRLLRwtYk36g-cDw_0UQACBAA"] [staklim-malang.info] [staklim-malang.info] top=[134048] [b4ZePz9M7Qg] [aEtRLLRwtYk36g-cDw_0UQACBAA] keep_alive=[1] [2025-06-13 05:14:04.801283] [R:aEtRLLRwtYk36g-cDw_0UQACBAA] UA:'Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot' Host:'s
... show less
Hacking
Web App Attack
hermawan
2025-06-12 16:26:01
(1 week ago)
[Thu Jun 12 23:25:59.382340 2025] [security2:error] [pid 27386:tid 139972433581760] [client 52.230.1 ... show more [Thu Jun 12 23:25:59.382340 2025] [security2:error] [pid 27386:tid 139972433581760] [client 52.230.164.186:25735] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /robots.txt HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/robots.txt"] [unique_id "aEr_l3a2RYYt5iBoizVCUgAAnRk"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[27412] [AUmAYjrHrkE] [aEr_l3a2RYYt5iBoizVCUgAAnRk] keep_alive=[1] [2025-06-12 23:25:59.382343] [R:aEr_l3a2RYYt5iBoizVCUgAAnRk] UA:'Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com
... show less
Hacking
Web App Attack
hermawan
2025-06-12 13:06:04
(1 week ago)
[Thu Jun 12 20:06:00.271307 2025] [security2:error] [pid 25484:tid 139783178237632] [client 52.230.1 ... show more [Thu Jun 12 20:06:00.271307 2025] [security2:error] [pid 25484:tid 139783178237632] [client 52.230.164.186:8828] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /robots.txt HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/robots.txt"] [unique_id "aErQuOcpoVWhhc99LarYYwAAmQ8"] [staklim-malang.info] [staklim-malang.info] top=[25501] [KbtJl4ejPCA] [aErQuOcpoVWhhc99LarYYwAAmQ8] keep_alive=[1] [2025-06-12 20:06:00.271312] [R:aErQuOcpoVWhhc99LarYYwAAmQ8] UA:'Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot' Host:'stak
... show less
Hacking
Web App Attack
hermawan
2025-06-11 07:37:59
(1 week ago)
[Wed Jun 11 14:37:15.325041 2025] [security2:error] [pid 124563:tid 140474038802112] [client 52.230. ... show more [Wed Jun 11 14:37:15.325041 2025] [security2:error] [pid 124563:tid 140474038802112] [client 52.230.164.186:6748] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /robots.txt HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/robots.txt"] [unique_id "aEkyK-l-lXFfUtrY31L-_wAAxRI"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[124582] [vR/C4R7BJQQ] [aEkyK-l-lXFfUtrY31L-_wAAxRI] keep_alive=[1] [2025-06-11 14:37:15.325047] [R:aEkyK-l-lXFfUtrY31L-_wAAxRI] UA:'Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.co
... show less
Hacking
Web App Attack
hermawan
2025-06-10 12:37:04
(1 week ago)
[Tue Jun 10 19:36:33.410281 2025] [security2:error] [pid 20916:tid 140215430616768] [client 52.230.1 ... show more [Tue Jun 10 19:36:33.410281 2025] [security2:error] [pid 20916:tid 140215430616768] [client 52.230.164.186:18910] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /robots.txt HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/robots.txt"] [unique_id "aEgm0Wh_dtuTYD8EJ92V-wAAxBE"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[20934] [WIlN8i4W7tE] [aEgm0Wh_dtuTYD8EJ92V-wAAxBE] keep_alive=[1] [2025-06-10 19:36:33.410284] [R:aEgm0Wh_dtuTYD8EJ92V-wAAxBE] UA:'Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com
... show less
Hacking
Web App Attack
hermawan
2025-06-10 03:45:53
(1 week ago)
[Tue Jun 10 10:27:48.114319 2025] [security2:error] [pid 75436:tid 139652764706496] [client 52.230.1 ... show more [Tue Jun 10 10:27:48.114319 2025] [security2:error] [pid 75436:tid 139652764706496] [client 52.230.164.186:44427] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /robots.txt HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/robots.txt"] [unique_id "aEemNCIcgjjknmc1eQCgHgAAUBU"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[75463] [u2bNR/c8fpU] [aEemNCIcgjjknmc1eQCgHgAAUBU] keep_alive=[1] [2025-06-10 10:27:48.114322] [R:aEemNCIcgjjknmc1eQCgHgAAUBU] UA:'Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com
... show less
Hacking
Web App Attack
hermawan
2025-06-09 12:18:32
(1 week ago)
[Mon Jun 09 19:13:54.570070 2025] [security2:error] [pid 1082133:tid 139881547232960] [client 52.230 ... show more [Mon Jun 09 19:13:54.570070 2025] [security2:error] [pid 1082133:tid 139881547232960] [client 52.230.164.186:53973] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "206"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /robots.txt HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/robots.txt"] [unique_id "aEbQAscnqWI4Eig6vHzoPQAARg8"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[1082149] [XIp3g/oW/gk] [aEbQAscnqWI4Eig6vHzoPQAARg8] keep_alive=[1] [2025-06-09 19:13:54.570074] [R:aEbQAscnqWI4Eig6vHzoPQAARg8] UA:'Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai
... show less
Hacking
Web App Attack