๐ฐ๐ญ
202.124.43.163
03 Jul 2026
[Sat Jul 04 03:36:31.022026 2026] [security2:error] [pid 593912:tid 140643564164800] [client 202.124 ...
show more
[Sat Jul 04 03:36:31.022026 2026] [security2:error] [pid 593912:tid 140643564164800] [client 202.124.43.163:63731] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.bmkg.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "601"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.bmkg.go.id found within REQUEST_HEADERS:Referer: https://www.bmkg.go.id/ request_line = GET /index.php/e-buletin-untuk-kota-dan-kabupaten-di-provinsi-jawa-timur HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/e-buletin-untuk-kota-dan-kabupaten-di-provinsi-jawa-timur"] [unique_id "akgdTrSIGBFk5NvAFGW53wABUBY"], referer https://www.bmkg.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[593982] [erkx4To4mEo] [akgdTrSIGBFk5NvAFGW53wABUBY] keep_alive=[1] [2026-07-04 03:36:31.022039] [R:akgdTrSIGBFk5NvAFGW53wABUBY] UA:'Mozilla/5.0 (iPhone; CPU iPhone OS 15_6
...
show less
Email Spam
Hacking
๐ป๐ณ
125.234.117.250
03 Jul 2026
1783110958.337817 125.234.117.250 103.166.156.58 65535_2-4-8-1-3_1386_9 2026-07-04 03:35:58 WIB
...
Email Spam
Hacking
๐ป๐ณ
14.238.81.118
03 Jul 2026
1783110957.439058 14.238.81.118 103.166.156.58 65535_2-4-8-1-3_1386_9 2026-07-04 03:35:57 WIB
...
Email Spam
Hacking
๐ฌ๐ง
45.82.76.125
03 Jul 2026
1783110949.179237 45.82.76.125 103.166.156.58 64240_2_1460_0 2026-07-04 03:35:49 WIB
...
Email Spam
Hacking
๐บ๐ธ
200.10.45.36
03 Jul 2026
1783110931.312918 200.10.45.36 103.166.156.58 64240_2-4-8-1-3_1200_7 2026-07-04 03:35:31 WIB
...
Email Spam
Hacking
๐ธ๐ช
189.81.165.28
03 Jul 2026
[Sat Jul 04 03:34:55.078492 2026] [security2:error] [pid 593912:tid 140643597735616] [client 189.81. ...
show more
[Sat Jul 04 03:34:55.078492 2026] [security2:error] [pid 593912:tid 140643597735616] [client 189.81.165.28:22364] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.yahoo.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "601"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.yahoo.go.id found within REQUEST_HEADERS:Referer: https://www.yahoo.go.id/ request_line = GET /index.php/informasi-iklim/infografis-iklim/infografis-bulanan/infografis-bulanan-iklim-ekstrim HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/informasi-iklim/infografis-iklim/infografis-bulanan/infografis-bulanan-iklim-ekstrim"] [unique_id "akgc77SIGBFk5NvAFGW53AABSRI"], referer https://www.yahoo.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[593978] [+UJ123o+mEo] [akgc77SIGBFk5NvAFGW53AABSRI] keep_alive=[1] [2026-07-04 03:34:55.078502] [R:akgc77SIGBFk5Nv
...
show less
Email Spam
Hacking
๐ง๐ท
186.235.63.91
03 Jul 2026
Captured JA4H: ge11n_d86aa6b45b47 | Log: 186.235.63.91 - - [04/Jul/2026:03:30:54 +0700] "GET /index. ...
show more
Captured JA4H: ge11n_d86aa6b45b47 | Log: 186.235.63.91 - - [04/Jul/2026:03:30:54 +0700] "GET /index.php/prediksi-iklim/prediksi-dasarian/monitoring-dan-prediksi-curah-hujan HTTP/1.1" 200 43203 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/120.0.6099.119 Mobile/15E148 Safari/604.1" ge11n_host,connection,accept-language,user-agent,sec-fetch-site,sec-fetch-dest,accept,accept-encoding,sec-fetch-mode...
...
show less
Email Spam
Hacking
๐บ๐ธ
99.97.108.2
03 Jul 2026
1783110866.626296 99.97.108.2 103.166.156.58 65535_2-4-8-1-3_1390_8 2026-07-04 03:34:26 WIB
...
Email Spam
Hacking
๐ฎ๐ณ
101.0.41.134
03 Jul 2026
1783110862.541253 101.0.41.134 103.166.156.58 65535_2-1-3-4-8_1412_8 2026-07-04 03:34:22 WIB
...
Email Spam
Hacking
๐ฒ๐พ
103.97.142.5
03 Jul 2026
07/04/2026-03:34:15.671844 [Drop] [**] [1:839644:1] Suricata NF - SCAN NMAP -sS 1024 Window [**] [C ...
show more
07/04/2026-03:34:15.671844 [Drop] [**] [1:839644:1] Suricata NF - SCAN NMAP -sS 1024 Window [**] [Classification: Detection of a Network Scan] [Priority: 3] {TCP} 103.97.142.5:44326 -> 103.166.156.58:5432
...
show less
Email Spam
Hacking
๐ฌ๐ง
5.252.83.220
03 Jul 2026
07/04/2026-03:34:05.784310 [Drop] [**] [1:921373:1] Suricata Dibuat Gemini TCP SYN port scanner - W ...
show more
07/04/2026-03:34:05.784310 [Drop] [**] [1:921373:1] Suricata Dibuat Gemini TCP SYN port scanner - Win 65535 [**] [Classification: (null)] [Priority: 3] {TCP} 5.252.83.220:51521 -> 103.166.156.58:59792
...
show less
Email Spam
Hacking
๐ง๐ท
45.232.162.129
03 Jul 2026
07/04/2026-03:33:51.621191 [Drop] [**] [1:920621:1] Suricata Local: Ubiquiti Discovery (5678) [**] ...
show more
07/04/2026-03:33:51.621191 [Drop] [**] [1:920621:1] Suricata Local: Ubiquiti Discovery (5678) [**] [Classification: (null)] [Priority: 3] {UDP} 45.232.162.129:26154 -> 103.166.156.58:21071
...
show less
Email Spam
Hacking
๐ฌ๐ง
213.249.252.186
03 Jul 2026
[Sat Jul 04 03:33:31.845458 2026] [security2:error] [pid 593912:tid 140643971724992] [client 213.249 ...
show more
[Sat Jul 04 03:33:31.845458 2026] [security2:error] [pid 593912:tid 140643971724992] [client 213.249.252.186:44832] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.yandex.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "601"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.yandex.go.id found within REQUEST_HEADERS:Referer: https://www.yandex.go.id/ request_line = GET / HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/"] [unique_id "akgcm7SIGBFk5NvAFGW52QABWAA"], referer https://www.yandex.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[593960] [ok951vo6mEo] [akgcm7SIGBFk5NvAFGW52QABWAA] keep_alive=[1] [2026-07-04 03:33:31.845470] [R:akgcm7SIGBFk5NvAFGW52QABWAA] UA:'Mozilla/5.0 (Linux; Android 8; SM-S901B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Mobile Safari/537.36' Host:'staklim-jatim.bmkg.go.id' ACCEPT:'text/
...
show less
Email Spam
Hacking
๐ธ๐ช
192.36.22.47
03 Jul 2026
07/04/2026-03:32:48.907203 [Drop] [**] [1:921747:0] Suricata Dibuat Gemini GRE Tunnel Traffic Detec ...
show more
07/04/2026-03:32:48.907203 [Drop] [**] [1:921747:0] Suricata Dibuat Gemini GRE Tunnel Traffic Detected [**] [Classification: Potential Corporate Privacy Violation] [Priority: 1] {GRE} 192.36.22.47:0 -> 103.166.156.58:0
...
show less
Email Spam
Hacking
๐ฎ๐ณ
152.59.175.47
03 Jul 2026
1783110621.008846 152.59.175.47 103.166.156.58 64240_2-4-8-1-3_1262_7 2026-07-04 03:30:21 WIB
...
Email Spam
Hacking
๐ป๐ณ
103.1.210.25
03 Jul 2026
07/04/2026-03:30:18.737731 [Drop] [**] [1:741481:3] Suricata ETๆซๆNMAP-sS็ชๅฃ1024 [**] [Classification ...
show more
07/04/2026-03:30:18.737731 [Drop] [**] [1:741481:3] Suricata ETๆซๆNMAP-sS็ชๅฃ1024 [**] [Classification: Attempted Information Leak] [Priority: 3] {TCP} 103.1.210.25:48781 -> 103.166.156.58:3389
...
show less
Email Spam
Hacking
๐ฌ๐ง
94.197.243.210
03 Jul 2026
1783110581.328529 94.197.243.210 103.166.156.58 65535_2-1-3-4-8_1320_12 2026-07-04 03:29:41 WIB
...
Email Spam
Hacking
๐ธ๐ช
189.81.164.205
03 Jul 2026
[Sat Jul 04 03:29:37.623526 2026] [security2:error] [pid 593854:tid 140643589342912] [client 189.81. ...
show more
[Sat Jul 04 03:29:37.623526 2026] [security2:error] [pid 593854:tid 140643589342912] [client 189.81.164.205:2130] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.yandex.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "601"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.yandex.go.id found within REQUEST_HEADERS:Referer: https://www.yandex.go.id/ request_line = GET /index.php/informasi-iklim/infografis-iklim/infografis-klimat-story/555561581-mengenal-fenomena-la-nina-si-pembawa-hujan HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/informasi-iklim/infografis-iklim/infografis-klimat-story/555561581-mengenal-fenomena-la-nina-si-pembawa-hujan"] [unique_id "akgbseEuCpDgW8hc88jkqAABBRM"], referer https://www.yandex.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[593893] [A66MyLp4mEo] [akgbseEuCpDgW8hc88jkqAABBRM] keep_ali
...
show less
Email Spam
Hacking
๐จ๐ท
190.7.207.125
03 Jul 2026
Captured JA4H: ge20n_aa3d46969283 | Log: 190.7.207.125 - - [04/Jul/2026:03:27:40 +0700] "GET /index. ...
show more
Captured JA4H: ge20n_aa3d46969283 | Log: 190.7.207.125 - - [04/Jul/2026:03:27:40 +0700] "GET /index.php/profil/meteorologi/list-all-categories/551-klimatologi/prakiraan-klimatologi/peringatan-dini/555562843-press-release-kewaspadaan-cuaca-ekstrim-di-jawa-timur-11-20-maret-2026 HTTP/2.0" 403 0 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_4 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/124.0.6367.88 Mobile/15E148 Safari/604.1" ge20n_accept,sec-fetch-mode,accept-encoding,user-agent,sec-fetch-site,sec-fetch-dest,accept-language,host...
...
show less
Email Spam
Hacking
๐น๐ณ
102.105.44.189
03 Jul 2026
1783110551.910319 102.105.44.189 103.166.156.58 65535_2-3-1-4-8_1400_12 2026-07-04 03:29:11 WIB
...
Email Spam
Hacking
๐ฆ๐ด
193.163.125.57
03 Jul 2026
07/04/2026-03:29:13.590435 [Drop] [**] [1:921830:0] Suricata Dibuat Gemini Inbound Kerberos Port 88 ...
show more
07/04/2026-03:29:13.590435 [Drop] [**] [1:921830:0] Suricata Dibuat Gemini Inbound Kerberos Port 88 Traffic Dropped (TCP) [**] [Classification: Potential Corporate Privacy Violation] [Priority: 1] {TCP} 193.163.125.57:57505 -> 103.166.156.58:88
...
show less
Email Spam
Hacking
๐ณ๐ฑ
45.198.224.5
03 Jul 2026
07/04/2026-03:27:51.481592 [Drop] [**] [1:921373:1] Suricata Dibuat Gemini TCP SYN port scanner - W ...
show more
07/04/2026-03:27:51.481592 [Drop] [**] [1:921373:1] Suricata Dibuat Gemini TCP SYN port scanner - Win 65535 [**] [Classification: (null)] [Priority: 3] {TCP} 45.198.224.5:34978 -> 103.166.156.58:2375
...
show less
Email Spam
Hacking
๐ฒ๐พ
103.47.154.169
03 Jul 2026
07/04/2026-03:27:27.351103 [Drop] [**] [1:384:8] Suricata PROTOCOL-ICMP PING [**] [Classification: ...
show more
07/04/2026-03:27:27.351103 [Drop] [**] [1:384:8] Suricata PROTOCOL-ICMP PING [**] [Classification: Misc activity] [Priority: 3] {ICMP} 103.47.154.169:8 -> 103.166.156.58:0
...
show less
Email Spam
Hacking
๐ฆ๐ท
38.7.39.10
03 Jul 2026
1783110433.635000 38.7.39.10 103.166.156.58 65535_2-4-8-1-3_1372_6 2026-07-04 03:27:13 WIB
...
Email Spam
Hacking
๐ฒ๐ฆ
105.190.163.177
03 Jul 2026
1783110355.604664 105.190.163.177 103.166.156.58 65535_2-4-8-1-3_1000_6 2026-07-04 03:25:55 WIB
...
Email Spam
Hacking