mclo
03 Nov 2022
95.108.213.55 _ - [03/Nov/2022:18:25:28 +0100] "GET /Can-day-trader-make-money.html HTTP/1.1" 404 13 ... show more 95.108.213.55 _ - [03/Nov/2022:18:25:28 +0100] "GET /Can-day-trader-make-money.html HTTP/1.1" 404 134 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)" "-" 80 - "text/html" cemuvl.duckdns.org "" "-"
... show less
Web App Attack
hermawan
03 Nov 2022
[Thu Nov 03 21:29:36.150950 2022] [-:error] [pid 22144:tid 140621498930752] [client 95.108.213.55:62 ... show more [Thu Nov 03 21:29:36.150950 2022] [-:error] [pid 22144:tid 140621498930752] [client 95.108.213.55:62352] [client 95.108.213.55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/informasi-angin-pelayaran-wilayah-jawa-timur/844-klimatologi/agroklimatologi/kalender-tanam-katam-terpadu/kalender-tanam-katam-terpadu-provinsi-jawa-timur/kalender-tanam-katam-terpadu-kabupaten-madiun/kalender-tanam-katam-terpadu-kecamatan-balerejo-kabupaten-madiun/kalender-tanam-katam-terpadu-kecamatan-balerejo-kabupaten-madiun-tahun-2016-2017/1464-kal..."] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/informasi-a
... show less
Hacking
Web App Attack
hermawan
02 Nov 2022
[Thu Nov 03 04:22:04.545850 2022] [-:error] [pid 69783:tid 140121026217536] [client 95.108.213.55:56 ... show more [Thu Nov 03 04:22:04.545850 2022] [-:error] [pid 69783:tid 140121026217536] [client 95.108.213.55:56502] [client 95.108.213.55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /robots.txt HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/robots.txt"] [unique_id "Y2LffEKVAnf3G4s2z6m4IgAAAIM"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[69811] [/YebbnMroa0] [Y2LffEKVAnf3G4s2z6m4IgAAAIM] keep_alive=[0] [2022-11-03 04:22:04.545853] [R:Y2LffEKVAnf3G4s2z6m4IgAAAIM] UA:'Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)' Host:'staklim-jatim.bmkg.go.id' ACCEPT:'*/*'
... show less
Hacking
Web App Attack
hermawan
01 Nov 2022
[Tue Nov 01 21:00:17.962926 2022] [-:error] [pid 49004:tid 140394134152768] [client 95.108.213.55:48 ... show more [Tue Nov 01 21:00:17.962926 2022] [-:error] [pid 49004:tid 140394134152768] [client 95.108.213.55:48334] [client 95.108.213.55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/analisis-bulanan/102-analisis-distribusi-hujan/analisis-distribusi-sifat-hujan/analisis-distribusi-sifat-hujan-jawa-timur-bulanan HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/index.php/analisis-bulanan/102-analisis-distribusi-hujan/analisis-distribusi-sifat-hujan/analisis-distribusi-sifat-hujan-jawa-timur-bulanan"] [unique_id "Y2EmcfLieKqHRVcyHcsYTwAAAGQ"] [staklim-malang.info] [staklim-malang.info] top=[49026] [pA3ZJBl/o
... show less
Hacking
Web App Attack
hermawan
01 Nov 2022
[Tue Nov 01 16:23:14.619488 2022] [-:error] [pid 68555:tid 139773700118080] [client 95.108.213.55:57 ... show more [Tue Nov 01 16:23:14.619488 2022] [-:error] [pid 68555:tid 139773700118080] [client 95.108.213.55:57540] [client 95.108.213.55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/profil/meteorologi/list-all-categories/3871-klimatologi HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/index.php/profil/meteorologi/list-all-categories/3871-klimatologi"] [unique_id "Y2DlguywqlaV3_egQov7vQAAAEw"] [staklim-malang.info] [staklim-malang.info] top=[68578] [XK4FRtVYVc8] [Y2DlguywqlaV3_egQov7vQAAAEw] keep_alive=[0] [2022-11-01 16:23:14.619493] [R:Y2DlguywqlaV3_egQov7vQAAAEw] UA:'Mozilla/5.0 (compatible; YandexBot
... show less
Hacking
Web App Attack
hermawan
31 Oct 2022
[Tue Nov 01 00:05:19.257145 2022] [-:error] [pid 40804:tid 139932146234944] [client 95.108.213.55:61 ... show more [Tue Nov 01 00:05:19.257145 2022] [-:error] [pid 40804:tid 139932146234944] [client 95.108.213.55:61186] [client 95.108.213.55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/animasi-prakiraan-cuaca-indonesia/1309-klimatologi/agroklimatologi/kalender-tanam-katam-terpadu/kalender-tanam-katam-terpadu-provinsi-jawa-timur/kalender-tanam-katam-terpadu-kabupaten-ponorogo/kalender-tanam-katam-terpadu-kecamatan-kauman-kabupaten-ponorogo/kalender-tanam-katam-terpadu-kecamatan-kauman-kabupaten-ponorogo-tahun-2016-2017/1563-kalender-ta..."] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/animasi-pra
... show less
Hacking
Web App Attack
hermawan
30 Oct 2022
[Sun Oct 30 18:56:53.179399 2022] [-:error] [pid 68511:tid 140444184737344] [client 95.108.213.55:39 ... show more [Sun Oct 30 18:56:53.179399 2022] [-:error] [pid 68511:tid 140444184737344] [client 95.108.213.55:39664] [client 95.108.213.55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/profil/meteorologi HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/index.php/profil/meteorologi"] [unique_id "Y15mhfhQYwM1zQWjO3ZDqwAAAFY"] [staklim-malang.info] [staklim-malang.info] top=[68544] [drXOLw8hj9M] [Y15mhfhQYwM1zQWjO3ZDqwAAAFY] keep_alive=[0] [2022-10-30 18:56:53.179402] [R:Y15mhfhQYwM1zQWjO3ZDqwAAAFY] UA:'Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)' Host:'staklim-malang.info' ACCEPT:'*/*' Ac
... show less
Hacking
Web App Attack
hermawan
29 Oct 2022
[Sun Oct 30 01:00:58.280684 2022] [-:error] [pid 54198:tid 140434646926912] [client 95.108.213.55:41 ... show more [Sun Oct 30 01:00:58.280684 2022] [-:error] [pid 54198:tid 140434646926912] [client 95.108.213.55:41074] [client 95.108.213.55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/profil/meteorologi/list-all-categories/3990-galeri-kegiatan/galeri-kegiatan-tahun-2018/12-galeri-kegiatan-bulan-desember-tahun-2018/555557260-galeri-kegiatan-bmkg-stasiun-klimatologi-malang-periode-18-21-desember-2018 HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/list-all-categories/3990-galeri-kegiatan/galeri-kegiatan-tahun-2018/12-galeri-kegiatan-bulan-desember-tahun-2018/555557260-g
... show less
Hacking
Web App Attack
hermawan
29 Oct 2022
[Sat Oct 29 22:01:44.887427 2022] [-:error] [pid 94858:tid 140606971975232] [client 95.108.213.55:42 ... show more [Sat Oct 29 22:01:44.887427 2022] [-:error] [pid 94858:tid 140606971975232] [client 95.108.213.55:42600] [client 95.108.213.55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/analisis-kondisi-dinamika-atmosfer-laut-dasarian HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/analisis-kondisi-dinamika-atmosfer-laut-dasarian"] [unique_id "Y11AWCedgEEr5_HKsDSBiAAAAAk"] [karangploso.jatim.bmkg.go.id] [karangploso.jatim.bmkg.go.id] top=[94889] [tLIVp50nAtM] [Y11AWCedgEEr5_HKsDSBiAAAAAk] keep_alive=[0] [2022-10-29 22:01:44.887431] [R:Y11AWCedgEEr5_HKsDSBiAAAAAk] UA:'Mozilla/5.0 (compatib
... show less
Hacking
Web App Attack
hermawan
28 Oct 2022
[Sat Oct 29 03:28:17.451607 2022] [-:error] [pid 32907:tid 140517738157632] [client 95.108.213.55:63 ... show more [Sat Oct 29 03:28:17.451607 2022] [-:error] [pid 32907:tid 140517738157632] [client 95.108.213.55:63884] [client 95.108.213.55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/2015-04-16-10-15-17/960-klimatologi/agroklimatologi/kalender-tanam-katam-terpadu/kalender-tanam-katam-terpadu-provinsi-jawa-timur/kalender-tanam-katam-terpadu-kabupaten-pacitan HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/2015-04-16-10-15-17/960-klimatologi/agroklimatologi/kalender-tanam-katam-terpadu/kalender-tanam-katam-terpadu-provinsi-jawa-timur/kalender-tanam-katam-terpadu-kabupaten-pacitan"] [uniq
... show less
Hacking
Web App Attack
hermawan
27 Oct 2022
[Fri Oct 28 10:30:49.438301 2022] [-:error] [pid 22885:tid 140408061310528] [client 95.108.213.55:40 ... show more [Fri Oct 28 10:30:49.438301 2022] [-:error] [pid 22885:tid 140408061310528] [client 95.108.213.55:40314] [client 95.108.213.55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/citra-satelit-bmkg/1687-kalender-tanam-katam-terpadu/kalender-tanam-katam-terpadu-provinsi-jawa-timur/kalender-tanam-katam-terpadu-kabupaten-kediri/kalender-tanam-katam-terpadu-kecamatan-gurah-kabupaten-kediri HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/citra-satelit-bmkg/1687-kalender-tanam-katam-terpadu/kalender-tanam-katam-terpadu-provinsi-jawa-timur/kalender-tanam-katam-terpadu-kabupaten-kediri/kal
... show less
Hacking
Web App Attack
rh24
27 Oct 2022
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 95.108.213.55 (RU/Ru ... show more (apache-useragents) Failed apache-useragents trigger with match [redacted] from 95.108.213.55 (RU/Russia/95-108-213-55.spider.yandex.com) show less
Bad Web Bot
hermawan
26 Oct 2022
[Thu Oct 27 10:02:01.271463 2022] [-:error] [pid 39275:tid 139910772074048] [client 95.108.213.55:54 ... show more [Thu Oct 27 10:02:01.271463 2022] [-:error] [pid 39275:tid 139910772074048] [client 95.108.213.55:54462] [client 95.108.213.55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET / HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/"] [unique_id "Y1n0qXznMmPJpv1pzpm4mAAAARM"] [karangploso.jatim.bmkg.go.id] [karangploso.jatim.bmkg.go.id] top=[39297] [Nd57XYuvjLQ] [Y1n0qXznMmPJpv1pzpm4mAAAARM] keep_alive=[0] [2022-10-27 10:02:01.271466] [R:Y1n0qXznMmPJpv1pzpm4mAAAARM] UA:'Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)' Host:'karangploso.jatim.bmkg.go.id' ACCEPT:'*/*' Accept-Encoding:'gzip,
... show less
Hacking
Web App Attack
hermawan
26 Oct 2022
[Thu Oct 27 01:11:39.807117 2022] [-:error] [pid 64767:tid 140561038063168] [client 95.108.213.55:56 ... show more [Thu Oct 27 01:11:39.807117 2022] [-:error] [pid 64767:tid 140561038063168] [client 95.108.213.55:56218] [client 95.108.213.55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/article-categories/851-klimatologi/agroklimatologi/kalender-tanam-katam-terpadu/kalender-tanam-katam-terpadu-provinsi-jawa-timur/kalender-tanam-katam-terpadu-kabupaten-bojonegoro/kalender-tanam-katam-terpadu-kecamatan-padangan-kabupaten-bojonegoro/kalender-tanam-katam-terpadu-kecamatan-padangan-kabupaten-bojonegoro-tahun-2016-2017/2301-kalender-tanam-ka..."] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/article-cat
... show less
Hacking
Web App Attack
hermawan
26 Oct 2022
[Wed Oct 26 13:32:41.082599 2022] [-:error] [pid 56610:tid 140427533350464] [client 95.108.213.55:62 ... show more [Wed Oct 26 13:32:41.082599 2022] [-:error] [pid 56610:tid 140427533350464] [client 95.108.213.55:62386] [client 95.108.213.55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "5"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots) request_line = GET /index.php/analisis-iklim/analisis-bulanan/indeks-presipitasi-terstandarisasi-spi-3-bulanan/555558673-analisis-bulanan-indeks-kekeringan-dan-kebasahan-meteorologis-3-bulanan-untuk-bulan-januari-februari-maret-tahun-2021-di-provinsi-jawa-timur HTTP/1.1"] [severity "NOTICE"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/index.php/analisis-iklim/analisis-bulanan/indeks-presipitasi-terstandarisasi-spi-3-bulanan/555558673-analisis-bulanan-indeks-kekeringan-dan
... show less
Hacking
Web App Attack