ᴀʀᴛ
2025-07-10 08:10:36
(6 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
ASN: 8075 (MICROSOFT-CORP-MSN-AS-BLOCK)<br ... show more Triggered Cloudflare WAF (firewallCustom) from US.
ASN: 8075 (MICROSOFT-CORP-MSN-AS-BLOCK)
Protocol: HTTP/2 (GET method)
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB show less
Bad Web Bot
hermawan
2025-07-10 05:00:06
(9 hours ago)
[Thu Jul 10 11:59:18.581099 2025] [security2:error] [pid 228373:tid 140400946816704] [client 74.7.35 ... show more [Thu Jul 10 11:59:18.581099 2025] [security2:error] [pid 228373:tid 140400946816704] [client 74.7.35.60:40177] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.15.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "227"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /index.php/90-klimatologi/analisis-klimatologi/artikel-perubahan-iklim/126-arti HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/90-klimatologi/analisis-klimatologi/artikel-perubahan-iklim/126-arti"] [unique_id "aG9IpvRqp5mOCzG2PPOCbAAAFQY"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[228381] [v25LDowrQr0] [aG9IpvRqp5mOCzG2PPOCbAAAFQY] keep_alive=[1] [2025-07-10 11:59:18.581113] [R:
... show less
Hacking
Web App Attack
hermawan
2025-07-10 00:27:41
(14 hours ago)
[Thu Jul 10 07:24:00.999776 2025] [security2:error] [pid 132074:tid 140405778663104] [client 74.7.35 ... show more [Thu Jul 10 07:24:00.999776 2025] [security2:error] [pid 132074:tid 140405778663104] [client 74.7.35.60:26006] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.15.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "227"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /index.php/prediksi-iklim/prediksi-bulanan/curah-hujan/3-bulan-ke-depan/555562014-prediksi-bulanan-curah-hujan-bulan-september-tahun-2025-update-dari-analisis-bulan-mei-tahun-2025-di-provinsi-jawa-timur HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/prediksi-iklim/prediksi-bulanan/curah-hujan/3-bulan-ke-depan/555562014-prediksi-bulanan-curah-hujan-bulan-september-tahun-2025-update-dari-analisis-
... show less
Hacking
Web App Attack
hermawan
2025-07-09 12:24:18
(1 day ago)
[Wed Jul 09 19:17:34.427561 2025] [security2:error] [pid 327339:tid 140661255780032] [client 74.7.35 ... show more [Wed Jul 09 19:17:34.427561 2025] [security2:error] [pid 327339:tid 140661255780032] [client 74.7.35.60:46037] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.15.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "227"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-sifat-hujan-bulanan/3-bulan-ke-depan/555561698-prakiraan-bulanan-sifat-hujan-bulan-maret-tahun-2025-update-dari-analisis-bulan-desember-tahun-2024-di-provinsi-jawa-timur HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-sifat-hujan-bulanan/3-bulan-ke-depan/555561698-prakiraan-bulanan-sifat-hujan-bulan-mare
... show less
Hacking
Web App Attack
Step Modifications
2025-07-09 00:56:51
(1 day ago)
wiki-badbots: Fail2Ban ban
Brute-Force
hermawan
2025-07-08 21:51:44
(1 day ago)
[Wed Jul 09 04:51:21.550930 2025] [security2:error] [pid 130137:tid 140189358819008] [client 74.7.35 ... show more [Wed Jul 09 04:51:21.550930 2025] [security2:error] [pid 130137:tid 140189358819008] [client 74.7.35.60:54171] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.15.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "227"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /index.php/informasi-iklim/peta-zona-musim-di-provinsi-jawa-timur HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/index.php/informasi-iklim/peta-zona-musim-di-provinsi-jawa-timur"] [unique_id "aG2S2ddW5vLkfZKML3BG9QAAWA8"] [staklim-malang.info] [staklim-malang.info] top=[130153] [fR/89fGHXXI] [aG2S2ddW5vLkfZKML3BG9QAAWA8] keep_alive=[1] [2025-07-09 04:51:21.550936] [R:aG2S2ddW5vLkfZKML3BG9QAAWA8] UA:'Mozilla/5.
... show less
Hacking
Web App Attack
Anonymous
2025-07-08 19:13:19
(1 day ago)
Action: Block, Reason: DDOS attack detected
DDoS Attack
hermawan
2025-07-08 01:03:15
(2 days ago)
[Tue Jul 08 08:03:14.510400 2025] [security2:error] [pid 152889:tid 140478847559360] [client 74.7.35 ... show more [Tue Jul 08 08:03:14.510400 2025] [security2:error] [pid 152889:tid 140478847559360] [client 74.7.35.60:58329] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.15.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "227"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-bulanan-tingkat-ketersediaan-air-bagi-tanaman/555561479-prakiraan-bulanan-tingkat-ketersediaan-air-bagi-tanaman-di-jawa-timur-untuk-bulan-januari-tahun-2025-update-dari-analisis-bulan-september-tahun-2024 HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-bulanan-tingkat-ketersediaan-air-bagi-tanaman/555561
... show less
Hacking
Web App Attack
hermawan
2025-07-07 04:39:31
(3 days ago)
[Mon Jul 07 11:37:52.221713 2025] [security2:error] [pid 1252703:tid 140657258587840] [client 74.7.3 ... show more [Mon Jul 07 11:37:52.221713 2025] [security2:error] [pid 1252703:tid 140657258587840] [client 74.7.35.60:30635] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.15.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "227"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /index.php/prakiraan-bulanan/4261-prakiraan-bulanan-untuk-6-bulan-ke-depan-di-provinsi-jawa-timur/prakiraan-bulanan-curah-hujan-untuk-6-bulan-ke-depan-di-provinsi-jawa-timur/555561125-prakiraan-bulanan-curah-hujan-di-kota-kabupaten-madiun-untuk-6-bulan-ke-depan HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/index.php/prakiraan-bulanan/4261-prakiraan-bulanan-untuk-6-bulan-ke-depan-di-provinsi-jawa-timur/prakir
... show less
Hacking
Web App Attack
Anonymous
2025-07-05 21:41:19
(4 days ago)
Action: Block, Reason: DDOS attack detected
DDoS Attack
hermawan
2025-07-05 06:35:16
(5 days ago)
[Sat Jul 05 13:29:50.742754 2025] [security2:error] [pid 54428:tid 139643440846528] [client 74.7.35. ... show more [Sat Jul 05 13:29:50.742754 2025] [security2:error] [pid 54428:tid 139643440846528] [client 74.7.35.60:49747] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.15.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "227"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-curah-hujan-bulanan/3-bulan-ke-depan/555561625-prakiraan-bulanan-curah-hujan-bulan-januari-tahun-2025-update-dari-analisis-bulan-november-tahun-2024-di-provinsi-jawa-timur HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-curah-hujan-bulanan/3-bulan-ke-depan/555561625-prakiraan-bulanan-curah-hujan-bulan-jan
... show less
Hacking
Web App Attack
Anonymous
2025-07-04 10:02:02
(6 days ago)
Action: Block, Reason: DDOS attack detected
DDoS Attack
Anonymous
2025-07-03 19:07:33
(6 days ago)
Action: Block, Reason: DDOS attack detected
DDoS Attack
hermawan
2025-07-03 05:43:16
(1 week ago)
[Thu Jul 03 12:41:25.204862 2025] [security2:error] [pid 355135:tid 140425923864256] [client 74.7.35 ... show more [Thu Jul 03 12:41:25.204862 2025] [security2:error] [pid 355135:tid 140425923864256] [client 74.7.35.60:50949] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "User" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.15.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "227"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: User found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot request_line = GET /index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-curah-hujan-bulanan/3-bulan-ke-depan/555561390-prakiraan-bulanan-curah-hujan-bulan-november-tahun-2024-update-dari-analisis-bulan-agustus-tahun-2024-di-provinsi-jawa-timur HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-curah-hujan-bulanan/3-bulan-ke-depan/555561390-prakiraan-bulanan-curah-hujan-bulan-no
... show less
Hacking
Web App Attack
conseilgouz
2025-07-02 19:40:06
(1 week ago)
sae-88 : Bloc AI bots=>/images/Horaires%20Ligne%20J%20SNCF%20Bus%2026%20f%C3%A9vrier%20au%20vendredi ... show more sae-88 : Bloc AI bots=>/images/Horaires%20Ligne%20J%20SNCF%20Bus%2026%20f%C3%A9vrier%20au%20vendredi%202%20mars.pdf show less
Hacking