Danse
25 Jun 2022
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 93.158.161.60 (RU/Ru ... show more (apache-useragents) Failed apache-useragents trigger with match [redacted] from 93.158.161.60 (RU/Russia/93-158-161-60.spider.yandex.com): (CF_ENABLE) show less
Bad Web Bot
ozisp.com.au
21 Jun 2022
RU_YANDEX-MNT_<33>1655868749 [1:2032979:1] ET SCAN Yandex Webcrawler User-Agent (YandexBot) [Classif ... show more RU_YANDEX-MNT_<33>1655868749 [1:2032979:1] ET SCAN Yandex Webcrawler User-Agent (YandexBot) [Classification: Not Suspicious Traffic] [Priority: 3] {TCP} 93.158.161.60:34838 show less
Hacking
Danse
18 Jun 2022
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 93.158.161.60 (RU/Ru ... show more (apache-useragents) Failed apache-useragents trigger with match [redacted] from 93.158.161.60 (RU/Russia/93-158-161-60.spider.yandex.com): (CF_ENABLE) show less
Bad Web Bot
ozisp.com.au
04 Jun 2022
RU_YANDEX-MNT_<33>1654356826 [1:2032979:1] ET SCAN Yandex Webcrawler User-Agent (YandexBot) [Classif ... show more RU_YANDEX-MNT_<33>1654356826 [1:2032979:1] ET SCAN Yandex Webcrawler User-Agent (YandexBot) [Classification: Not Suspicious Traffic] [Priority: 3] {TCP} 93.158.161.60:46908 show less
Hacking
Anonymous
04 Jun 2022
93.158.161.60 - - [01/Jun/2022:00:58:20 +0200] "GET /wordpress/tag/beat/ HTTP/1.1" 404 77129 "-" "Mo ... show more 93.158.161.60 - - [01/Jun/2022:00:58:20 +0200] "GET /wordpress/tag/beat/ HTTP/1.1" 404 77129 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)"
93.158.161.60 - - [01/Jun/2022:22:40:32 +0200] "GET /wordpress/ HTTP/1.1" 404 77065 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)"
93.158.161.60 - - [03/Jun/2022:05:00:29 +0200] "GET /wordpress/tag/tal/page/2/ HTTP/1.1" 404 72407 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)"
93.158.161.60 - - [04/Jun/2022:15:22:07 +0200] "GET /wordpress/sample-libraries/abstract-grooves/ HTTP/1.1" 404 77277 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)"
... show less
Hacking
Bad Web Bot
Anonymous
27 May 2022
93.158.161.60 - - [25/May/2022:17:18:19 +0200] "GET /wordpress/2016/07/07/summer-sale-has-started/ H ... show more 93.158.161.60 - - [25/May/2022:17:18:19 +0200] "GET /wordpress/2016/07/07/summer-sale-has-started/ HTTP/1.1" 404 76445 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)"
93.158.161.60 - - [25/May/2022:22:53:35 +0200] "GET /wordpress/tag/plugout/ HTTP/1.1" 404 77145 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)"
93.158.161.60 - - [27/May/2022:16:23:34 +0200] "GET /2017/09/21/modularium-occurrence-in-beat-magazine/ HTTP/1.1" 404 77321 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)"
93.158.161.60 - - [28/May/2022:04:59:31 +0200] "GET /2018/02/03/synth-motions-vol-1-released-launch-special/ HTTP/1.1" 404 77351 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)"
... show less
Hacking
Bad Web Bot
hermawan
27 May 2022
[Sat May 28 01:23:06.299595 2022] [-:error] [pid 5447:tid 140731314337536] [client 93.158.161.60:490 ... show more [Sat May 28 01:23:06.299595 2022] [-:error] [pid 5447:tid 140731314337536] [client 93.158.161.60:49050] [client 93.158.161.60] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/custom_user.conf"] [line "5"] [id "1000000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-bulanan-tingkat-ketersediaan-air-bagi-tanaman?start=35 HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-bulanan-tingkat-ketersediaan-air-bagi-tanaman"] [unique_id "YpEXCgOBSu6Y2MhzaCd2mwAAAJ8"] [karangploso.jatim.bmkg.go.id] [karangploso.jatim.bmkg.go.id] top=[6070] [tcfJZSrTMIQ] [YpEXCgOBSu6Y2MhzaCd2mwAAAJ8] keep_alive=[0] [2022-05-28 01:23
... show less
Hacking
Web App Attack
Roderic
26 May 2022
(PERMBLOCK) 93.158.161.60 (RU/Russia/93-158-161-60.spider.yandex.com) has had more than 4 temp block ... show more (PERMBLOCK) 93.158.161.60 (RU/Russia/93-158-161-60.spider.yandex.com) has had more than 4 temp blocks show less
Hacking
hermawan
25 May 2022
[Thu May 26 10:58:52.139400 2022] [-:error] [pid 5932:tid 140735250241280] [client 93.158.161.60:564 ... show more [Thu May 26 10:58:52.139400 2022] [-:error] [pid 5932:tid 140735250241280] [client 93.158.161.60:56408] [client 93.158.161.60] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/custom_user.conf"] [line "5"] [id "1000000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /robots.txt HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/robots.txt"] [unique_id "Yo76_AJWlM_Rml-xYI4F0gAAAS0"] [karangploso.jatim.bmkg.go.id] [karangploso.jatim.bmkg.go.id] top=[6371] [NV0yNQIti3s] [Yo76_AJWlM_Rml-xYI4F0gAAAS0] keep_alive=[0] [2022-05-26 10:58:52.139404] [R:Yo76_AJWlM_Rml-xYI4F0gAAAS0] UA:'Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)' Host:'karangploso.jatim.bmkg.go.id' ACCEPT:'*/*'
... show less
Hacking
Web App Attack
Roderic
25 May 2022
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 93.158.161.60 (RU/Ru ... show more (apache-useragents) Failed apache-useragents trigger with match [redacted] from 93.158.161.60 (RU/Russia/93-158-161-60.spider.yandex.com) show less
Bad Web Bot
hermawan
25 May 2022
[Wed May 25 21:18:55.824848 2022] [-:error] [pid 158807:tid 140729619797760] [client 93.158.161.60:6 ... show more [Wed May 25 21:18:55.824848 2022] [-:error] [pid 158807:tid 140729619797760] [client 93.158.161.60:64056] [client 93.158.161.60] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/custom_user.conf"] [line "5"] [id "1000000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/profil/meteorologi/list-all-categories/3935-klimatologi/offline-artikel/452-artikel-offline-internet-tugas-dan-wilayah-kerja-stasiun-klimatologi-kelas-ii-karangploso-malang HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/list-all-categories/3935-klimatologi/offline-artikel/452-artikel-offline-internet-tugas-dan-wilayah-kerja-stasiun-klimatologi-kelas-ii-karangploso-malang"] [unique_id "Yo46z6o_Vyujjp0YehcK
... show less
Hacking
Web App Attack
hermawan
25 May 2022
[Wed May 25 12:29:53.758172 2022] [-:error] [pid 5729:tid 140733033989888] [client 93.158.161.60:474 ... show more [Wed May 25 12:29:53.758172 2022] [-:error] [pid 5729:tid 140733033989888] [client 93.158.161.60:47490] [client 93.158.161.60] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/custom_user.conf"] [line "5"] [id "1000000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/108-akar/sumber-daya-manusia/struktur-organisasi/963-struktur-organisasi-stasiun-klimatologi-kelas-ii HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/108-akar/sumber-daya-manusia/struktur-organisasi/963-struktur-organisasi-stasiun-klimatologi-kelas-ii"] [unique_id "Yo2-0b84S8XJzQFNNcv2LgAAAec"] [karangploso.jatim.bmkg.go.id] [karangploso.jatim.bmkg.go.id] top=[6236] [plbKXCcpCHg] [Yo2-0b84S8XJzQFNNcv2LgAAAec] keep_alive=[0] [2
... show less
Hacking
Web App Attack
hermawan
24 May 2022
[Wed May 25 04:37:19.025694 2022] [-:error] [pid 36261:tid 140734728496896] [client 93.158.161.60:54 ... show more [Wed May 25 04:37:19.025694 2022] [-:error] [pid 36261:tid 140734728496896] [client 93.158.161.60:54956] [client 93.158.161.60] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/custom_user.conf"] [line "5"] [id "1000000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /robots.txt HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/robots.txt"] [unique_id "Yo1QDxFEDFoP-BsH5DwPugAAATo"] [staklim-malang.info] [staklim-malang.info] top=[36597] [ndHRwuCId7c] [Yo1QDxFEDFoP-BsH5DwPugAAATo] keep_alive=[0] [2022-05-25 04:37:19.025699] [R:Yo1QDxFEDFoP-BsH5DwPugAAATo] UA:'Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)' Host:'staklim-malang.info' ACCEPT:'*/*'
... show less
Hacking
Web App Attack
hermawan
24 May 2022
[Tue May 24 11:04:54.157596 2022] [-:error] [pid 200989:tid 140735257962240] [client 93.158.161.60:6 ... show more [Tue May 24 11:04:54.157596 2022] [-:error] [pid 200989:tid 140735257962240] [client 93.158.161.60:61370] [client 93.158.161.60] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/custom_user.conf"] [line "13"] [id "1000000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/profil/arsip-artikel HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/profil/arsip-artikel"] [unique_id "YoxZZkKHiQyW0p7S_evGyAAAASw"] [karangploso.jatim.bmkg.go.id] [karangploso.jatim.bmkg.go.id] top=[201325] [51gYDxr8Fbs] [YoxZZkKHiQyW0p7S_evGyAAAASw] keep_alive=[0] [2022-05-24 11:04:54.157600] [R:YoxZZkKHiQyW0p7S_evGyAAAASw] UA:'Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)' Host:'karangploso.jatim.bmkg
... show less
Hacking
Web App Attack
hermawan
23 May 2022
[Mon May 23 21:11:23.926120 2022] [-:error] [pid 242465:tid 140735257630464] [client 93.158.161.60:6 ... show more [Mon May 23 21:11:23.926120 2022] [-:error] [pid 242465:tid 140735257630464] [client 93.158.161.60:65174] [client 93.158.161.60] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/custom_user.conf"] [line "13"] [id "1000000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/profil/meteorologi/list-all-categories/582-meteorologi/prakiraan-meteorologi/prakiraan-cuaca-pasuruan HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/list-all-categories/582-meteorologi/prakiraan-meteorologi/prakiraan-cuaca-pasuruan"] [unique_id "YouWC_oFPedF5Jv6XP_BHwAAAJY"] [karangploso.jatim.bmkg.go.id] [karangploso.jatim.bmkg.go.id] top=[242673] [obhAag6wTbQ] [YouWC_oFPedF5Jv6XP_BHwAAAJY] keep_alive=[
... show less
Hacking
Web App Attack