rh24
10 Feb 2023
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 95.108.213.55 (RU/Ru ... show more (apache-useragents) Failed apache-useragents trigger with match [redacted] from 95.108.213.55 (RU/Russia/95-108-213-55.spider.yandex.com) show less
Bad Web Bot
mclo
02 Feb 2023
95.108.213.55 - - [02/Feb/2023:19:15:45 +0100] "GET /robots.txt HTTP/1.1" 404 162 "-" "Mozilla/5.0 ( ... show more 95.108.213.55 - - [02/Feb/2023:19:15:45 +0100] "GET /robots.txt HTTP/1.1" 404 162 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)"
... show less
Web App Attack
ozisp.com.au
15 Jan 2023
RU_YANDEX-MNT_<33>1673816779 [1:2032979:1] ET SCAN Yandex Webcrawler User-Agent (YandexBot) [Classif ... show more RU_YANDEX-MNT_<33>1673816779 [1:2032979:1] ET SCAN Yandex Webcrawler User-Agent (YandexBot) [Classification: Not Suspicious Traffic] [Priority: 3] {TCP} 95.108.213.55:38466 show less
Hacking
mclo
15 Jan 2023
95.108.213.55 _ - [15/Jan/2023:21:24:50 +0100] "GET /What%27s-the-easiest-way-to-make-money-on-secon ... show more 95.108.213.55 _ - [15/Jan/2023:21:24:50 +0100] "GET /What%27s-the-easiest-way-to-make-money-on-secone-life.html HTTP/1.1" 404 134 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)" "-" 80 - "text/html" jbgrvwpy.duckdns.org "" "-"
... show less
Web App Attack
hermawan
26 Dec 2022
[Mon Dec 26 19:30:46.349900 2022] [-:error] [pid 45050:tid 140052778272320] [client 95.108.213.55:39 ... show more [Mon Dec 26 19:30:46.349900 2022] [-:error] [pid 45050:tid 140052778272320] [client 95.108.213.55:39684] [client 95.108.213.55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-3.3.4/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/buku/3918-buku-edisi-setiap-6-bulan-sekali/buku-prakiraan-musim/buku-prakiraan-musim-hujan/buletin-prakiraan-musim-hujan-tahun-2018-2019-di-provinsi-jawa-timur/555556690-buletin-prakiraan-musim-hujan-tahun-2018-2019-di-provinsi-jawa-timur HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/buku/3918-buku-edisi-setiap-6-bulan-sekali/buku-prakiraan-musim/buku-prakiraan-musim-hujan/buletin-prakiraan-musim-hujan-tahun
... show less
Hacking
Web App Attack
rh24
17 Dec 2022
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 95.108.213.55 (RU/Ru ... show more (apache-useragents) Failed apache-useragents trigger with match [redacted] from 95.108.213.55 (RU/Russia/95-108-213-55.spider.yandex.com) show less
Bad Web Bot
rh24
15 Dec 2022
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 95.108.213.55 (RU/Ru ... show more (apache-useragents) Failed apache-useragents trigger with match [redacted] from 95.108.213.55 (RU/Russia/95-108-213-55.spider.yandex.com): (CF_ENABLE) show less
Bad Web Bot
ozisp.com.au
10 Dec 2022
RU_YANDEX-MNT_<33>1670722352 [1:2032979:1] ET SCAN Yandex Webcrawler User-Agent (YandexBot) [Classif ... show more RU_YANDEX-MNT_<33>1670722352 [1:2032979:1] ET SCAN Yandex Webcrawler User-Agent (YandexBot) [Classification: Not Suspicious Traffic] [Priority: 3] {TCP} 95.108.213.55:37444 show less
Hacking
hermawan
23 Nov 2022
[Wed Nov 23 12:47:08.805266 2022] [-:error] [pid 122353:tid 140374489253440] [client 95.108.213.55:4 ... show more [Wed Nov 23 12:47:08.805266 2022] [-:error] [pid 122353:tid 140374489253440] [client 95.108.213.55:41416] [client 95.108.213.55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /robots.txt HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/robots.txt"] [unique_id "Y32z3PQTp_ThShTdf91ORAAAAic"] [staklim-malang.info] [staklim-malang.info] top=[122570] [jaG00aQk6vU] [Y32z3PQTp_ThShTdf91ORAAAAic] keep_alive=[0] [2022-11-23 12:47:08.805269] [R:Y32z3PQTp_ThShTdf91ORAAAAic] UA:'Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)' Host:'staklim-malang.info' ACCEPT:'*/*'
... show less
Hacking
Web App Attack
hermawan
22 Nov 2022
[Wed Nov 23 04:16:06.158115 2022] [-:error] [pid 116804:tid 139837884835392] [client 95.108.213.55:6 ... show more [Wed Nov 23 04:16:06.158115 2022] [-:error] [pid 116804:tid 139837884835392] [client 95.108.213.55:61474] [client 95.108.213.55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /b/bulanankediri.pdf HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/b/bulanankediri.pdf"] [unique_id "Y308Fl8SlRTw5JMBKNm22wAAAM4"] [karangploso.jatim.bmkg.go.id] [karangploso.jatim.bmkg.go.id] top=[117023] [Au0Rrm3lOwI] [Y308Fl8SlRTw5JMBKNm22wAAAM4] keep_alive=[0] [2022-11-23 04:16:06.158118] [R:Y308Fl8SlRTw5JMBKNm22wAAAM4] UA:'Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)' Host:'karangploso.jatim.bmkg.go
... show less
Hacking
Web App Attack
hermawan
22 Nov 2022
[Tue Nov 22 23:00:25.119126 2022] [-:error] [pid 46715:tid 140449186121280] [client 95.108.213.55:51 ... show more [Tue Nov 22 23:00:25.119126 2022] [-:error] [pid 46715:tid 140449186121280] [client 95.108.213.55:51358] [client 95.108.213.55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/prakiraan-bulanan/3874-prakiraan-sifat-hujan-bulanan/prakiraan-sifat-hujan-bulanan-di-propinsi-jawa-timur/prakiraan-sifat-hujan-bulanan-di-propinsi-jawa-timur-tahun-2018/553-prakiraan-sifat-hujan-bulan-februari-tahun-2019-update-dari-analisis-bulan-oktober-2018 HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/prakiraan-bulanan/3874-prakiraan-sifat-hujan-bulanan/prakiraan-sifat-hujan-bulanan-di-propinsi-jawa
... show less
Hacking
Web App Attack
hermawan
22 Nov 2022
[Tue Nov 22 19:34:03.310714 2022] [-:error] [pid 211139:tid 140036921501248] [client 95.108.213.55:5 ... show more [Tue Nov 22 19:34:03.310714 2022] [-:error] [pid 211139:tid 140036921501248] [client 95.108.213.55:54822] [client 95.108.213.55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /robots.txt HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/robots.txt"] [unique_id "Y3zBuzlU-EG84COGK9JgZwAAAR4"] [karangploso.jatim.bmkg.go.id] [karangploso.jatim.bmkg.go.id] top=[211297] [k1oVY3ZoF0Q] [Y3zBuzlU-EG84COGK9JgZwAAAR4] keep_alive=[0] [2022-11-22 19:34:03.310718] [R:Y3zBuzlU-EG84COGK9JgZwAAAR4] UA:'Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)' Host:'karangploso.jatim.bmkg.go.id' ACCEPT:'*/*'
... show less
Hacking
Web App Attack
hermawan
21 Nov 2022
[Tue Nov 22 11:16:00.421894 2022] [-:error] [pid 385940:tid 140083596334656] [client 95.108.213.55:5 ... show more [Tue Nov 22 11:16:00.421894 2022] [-:error] [pid 385940:tid 140083596334656] [client 95.108.213.55:59438] [client 95.108.213.55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/component/tags/tag/analisis-bulanan HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/component/tags/tag/analisis-bulanan"] [unique_id "Y3xNAKNwRBXKd3c1KkhsPgAAAT0"] [karangploso.jatim.bmkg.go.id] [karangploso.jatim.bmkg.go.id] top=[386130] [9kftbT+nATg] [Y3xNAKNwRBXKd3c1KkhsPgAAAT0] keep_alive=[0] [2022-11-22 11:16:00.421897] [R:Y3xNAKNwRBXKd3c1KkhsPgAAAT0] UA:'Mozilla/5.0 (compatible; YandexBot/3.0; +http
... show less
Hacking
Web App Attack
hermawan
21 Nov 2022
[Tue Nov 22 01:32:08.189562 2022] [-:error] [pid 93798:tid 139716298425920] [client 95.108.213.55:40 ... show more [Tue Nov 22 01:32:08.189562 2022] [-:error] [pid 93798:tid 139716298425920] [client 95.108.213.55:40564] [client 95.108.213.55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/profil/meteorologi/list-all-categories/555557755-prakiraan-bulanan-tingkat-ketersediaan-air-bagi-tanaman-di-jawa-timur-untuk-bulan-maret-2020-update-dari-analisis-bulan-november-2019 HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/list-all-categories/555557755-prakiraan-bulanan-tingkat-ketersediaan-air-bagi-tanaman-di-jawa-timur-untuk-bulan-maret-2020-update-dari-analisis-bulan-november-
... show less
Hacking
Web App Attack
hermawan
21 Nov 2022
[Mon Nov 21 20:34:45.625835 2022] [-:error] [pid 94592:tid 140232688617024] [client 95.108.213.55:56 ... show more [Mon Nov 21 20:34:45.625835 2022] [-:error] [pid 94592:tid 140232688617024] [client 95.108.213.55:56000] [client 95.108.213.55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexMetrika/2.0; +http://yandex.com/bots yabs01) request_line = GET / HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/"] [unique_id "Y3t-dWC7ezxqynHqPedloAAAABw"] [karangploso.jatim.bmkg.go.id] [karangploso.jatim.bmkg.go.id] top=[94732] [WVFeHgNt09E] [Y3t-dWC7ezxqynHqPedloAAAABw] keep_alive=[0] [2022-11-21 20:34:45.625838] [R:Y3t-dWC7ezxqynHqPedloAAAABw] UA:'Mozilla/5.0 (compatible; YandexMetrika/2.0; +http://yandex.com/bots yabs01)' Host:'karangploso.jatim.bmkg.go.id' ACCEPT:'*/*'
... show less
Hacking
Web App Attack