Anonymous
2026-07-27 13:30:38
(1 day ago)
Large-scale coordinated botnet (777+k IPs). Attacker: mikhail-smirnov-79830323 (LinkedIn/profile ID) ...
show more
Large-scale coordinated botnet (777+k IPs). Attacker: mikhail-smirnov-79830323 (LinkedIn/profile ID) employed by Angara Technologies Group (Explicitly identified himself as enemy a week before attack began) | Attack Signature Blocked: /wishlist/index/add/product/4351/form_key/0iugOuNmcLs4jprB/ | UA: Mozilla/5.0 (compatible; MSIE 8.0; Windows NT 5.2; Trident/4.1) | (Magento Site)
show less
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
pltcldvlpr
2026-07-26 06:47:09
(2 days ago)
Bogus Useragent: 103.130.18.21 - - [26/Jul/2026:08:47:08 +0200] "GET /protocol?id=he_21_55¶graph ...
show more
Bogus Useragent: 103.130.18.21 - - [26/Jul/2026:08:47:08 +0200] "GET /protocol?id=he_21_55¶graph=5712364&seq=473 HTTP/1.1" 444 0 "-" "Opera/9.41.(Windows 98; Win 9x 4.90; wa-BE) Presto/2.9.181 Version/10.00" asn=63859 org="PT. Eka Mas Republik" country=ID
...
show less
Bad Web Bot
๐ฎ๐ฉ
sockominfo
2026-07-06 22:00:30
(3 weeks ago)
Reported by TangerangKota-CSIRT. Status: MALICIOUS
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-07-06 21:00:09
(3 weeks ago)
Late night login (22:00-05:30) - High risk Jakarta timezone (WIB). Threat Score: 8.6/10 (HIGH). Repo ...
show more
Late night login (22:00-05:30) - High risk Jakarta timezone (WIB). Threat Score: 8.6/10 (HIGH). Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-07-06 16:00:52
(3 weeks ago)
Late night login (22:00-05:30) - High risk Jakarta timezone (WIB). Threat Score: 8.9/10 (CRITICAL). ...
show more
Late night login (22:00-05:30) - High risk Jakarta timezone (WIB). Threat Score: 8.9/10 (CRITICAL). Confidence: 70%. CVSS v3.1: 9.9/10 (Critical). CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. Bayesian Probability: 87%. MITRE ATT&CK: T1078 (Valid Accounts). Tactic: TA0001. Freshness: Very Fresh. Source Reputation: KNOWN_MALICIOUS. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ธ๐ช
KIDOS
2025-10-06 02:48:05
(9 months ago)
malicious activity, botnet
Web App Attack
๐ฉ๐ช
John Chrys.
2025-08-21 07:21:16
(11 months ago)
103.130.18.21 - - [21/Aug/2025:10:20:47 +0300] "POST /wp-comments-post.php HTTP/1.1" 403 6780 "-" "M ...
show more
103.130.18.21 - - [21/Aug/2025:10:20:47 +0300] "POST /wp-comments-post.php HTTP/1.1" 403 6780 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
103.130.18.21 - - [21/Aug/2025:10:20:54 +0300] "POST /wp-comments-post.php HTTP/1.1" 403 6780 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
103.130.18.21 - - [21/Aug/2025:10:21:03 +0300] "POST /wp-comments-post.php HTTP/1.1" 403 6780 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
103.130.18.21 - - [21/Aug/2025:10:21:10 +0300] "POST /wp-comments-post.php HTTP/1.1" 403 6780 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
103.130.18.21 - - [21/Aug/2025:10:21:13 +0300] "POST /wp-comments-post.php HTTP/1.1" 403 6780 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit
...
show less
Brute-Force
Web App Attack
Anonymous
2025-07-23 14:48:14
(1 year ago)
Ports: 25,2525,465,587,2525; Direction: 0; Trigger: LF_DISTATTACK
Brute-Force
SSH
Anonymous
2025-06-14 21:53:26
(1 year ago)
Unauthorized connection to SMB port 445
Port Scan
๐ง๐ท
hostseries
2025-05-13 00:04:48
(1 year ago)
Brute-force cPanel Services
Brute-Force
๐ฉ๐ช
botreporter
2025-05-12 19:19:12
(1 year ago)
botnet ignoring robots.txt
Bad Web Bot
๐ฉ๐ช
dihost
2025-05-11 20:38:09
(1 year ago)
(cpanel) Failed cPanel login from 103.130.18.21 (ID/Indonesia/host-103-130-18-21.myrepublic.co.id): ...
show more
(cpanel) Failed cPanel login from 103.130.18.21 (ID/Indonesia/host-103-130-18-21.myrepublic.co.id): 5 in the last 3600 secs
show less
Brute-Force
๐ช๐ธ
robotstxt
2025-05-11 19:30:09
(1 year ago)
103.130.18.21 - - [11/May/2025:18:28:29 +0000] "GET /mailer.php HTTP/2.0" 404 46836 "http://economip ...
show more
103.130.18.21 - - [11/May/2025:18:28:29 +0000] "GET /mailer.php HTTP/2.0" 404 46836 "http://economipedia.com/mailer.php" "Go-http-client/2.0" "-"
103.130.18.21 - - [11/May/2025:19:29:37 +0000] "GET /mailer1.php HTTP/2.0" 404 46835 "http://economipedia.com/mailer1.php" rt="0.368" "Go-http-client/2.0" "-" h="economipedia.com" sn="economipedia.com" ru="/mailer1.php" u="/index.php" ucs="-" ua="unix:/var/run/php/economipedia74.sock" us="404" uct="0.000" urt="0.368"
103.130.18.21 - - [11/May/2025:19:29:37 +0000] "GET /mailer1.php HTTP/2.0" 404 46835 "http://economipedia.com/mailer1.php" rt="0.368" "Go-http-client/2.0" "-" h="economipedia.com" sn="economipedia.com" ru="/mailer1.php" u="/index.php" ucs="-" ua="unix:/var/run/php/economipedia74.sock" us="404" uct="0.000" urt="0.368"
103.130.18.21 - - [11/May/2025:19:29:37 +0000] "GET /mailer1.php HTTP/2.0" 404 46835 "http://economipedia.com/mailer1.php" "Go-http-client/2.0" "-"
103.130.18.21 - - [11/May/2025:19:29:37 +0000] "GET /mailer1.php HTT
...
show less
Bad Web Bot
Anonymous
2025-05-11 19:01:58
(1 year ago)
Ports: 2077,2078,2079,2080,2082,2083,2086,2087,2095,2096,3306,2195; Direction: 0; Trigger: LF_CUSTOM ...
show more
Ports: 2077,2078,2079,2080,2082,2083,2086,2087,2095,2096,3306,2195; Direction: 0; Trigger: LF_CUSTOMTRIGGER
show less
Brute-Force
SSH
Anonymous
2025-05-11 18:46:48
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH