๐ฉ๐ช
EGP Abuse Dept
2026-06-17 02:29:39
(2 days ago)
Scanning for port/service exploits on tpc-005.mach3builders.nl
Port Scan
Hacking
๐ฎ๐ฉ
hermawan
2026-06-14 00:50:43
(5 days ago)
[Sun Jun 14 07:50:38.936465 2026] [security2:error] [pid 1374580:tid 139664380446400] [client 103.13 ...
show more
[Sun Jun 14 07:50:38.936465 2026] [security2:error] [pid 1374580:tid 139664380446400] [client 103.139.26.42:60914] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.baidu.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "582"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.baidu.go.id found within REQUEST_HEADERS:Referer: http://www.baidu.go.id/ request_line = GET /pdfjs/web/viewer.html?file=/images/Klimatologi/Analisis/02-Analisis_Dasarian/Monitoring_dan_Prakiraan_Curah_Hujan-Dasarian/Monitoring_dan_Prakiraan_Curah_Hujan-Dasarian_di_Provinsi_Jawa_Timur/2026/06_Juni_2026/Das-I/Monitoring_dan_Prediksi_Curah_Hujan-Dasarian_di_Provinsi_Jawa_Timur_Update_10_Juni_2026.pdf HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/pdfjs/web/viewer.html"] [unique_id "ai363qqPa7PnXcSJuJgCoQAASRY"], referer http://www.baidu.go.id/ [staklim-jatim.bmkg.go.id] [stakli
...
show less
Email Spam
Hacking
๐จ๐ญ
ALPHANET
2026-05-24 06:30:03
(3 weeks ago)
Botnet or web spider not respecting robots.txt
DDoS Attack
Exploited Host
๐ฉ๐ช
EGP Abuse Dept
2026-05-13 06:04:37
(1 month ago)
Scraping webshop URLs (www.creall.com), likely botnet drone
Bad Web Bot
Exploited Host
๐ฉ๐ช
filstal.org
2026-04-30 11:53:55
(1 month ago)
Bad web bot: Spoofed/obsolete UA (Opera/9.74.(X11; Linux x86_64; my-MM) Presto/2.9.172 Version/12.00 ...
show more
Bad web bot: Spoofed/obsolete UA (Opera/9.74.(X11; Linux x86_64; my-MM) Presto/2.9.172 Version/12.00). Mass-scanning WordPress plugin. Coordinated large-scale bot attack.
show less
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-04-26 16:15:56
(1 month ago)
Detected attack and reported by a human
Brute-Force
Web App Attack
SSH
DDoS Attack
Exploited Host
Bad Web Bot
๐ฎ๐ฉ
hermawan
2026-04-13 08:28:06
(2 months ago)
Captured JA4H: ge20n_28a3c8db2b22 | Log: 103.139.26.42 - - [13/Apr/2026:14:56:09 +0700] "GET /index. ...
show more
Captured JA4H: ge20n_28a3c8db2b22 | Log: 103.139.26.42 - - [13/Apr/2026:14:56:09 +0700] "GET /index.php/analisis-iklim/analisis-bulanan/analisis-distribusi-hujan/analisis-distribusi-curah-hujan HTTP/2.0" 403 16976 "http://www.baidu.go.id/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Mobile Safari/537.36 EdgA/127.0.0.0" ge20n_sec-ch-ua,sec-ch-ua-mobile,sec-ch-ua-platform,upgrade-insecure-requests,user-agent,accept,sec-fetch-site,sec-fetch-mode,sec-fetch-user,sec-fetch-dest,accept-encoding,accept-language,priority,referer,host...
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-04-13 07:56:09
(2 months ago)
[Mon Apr 13 14:56:09.167970 2026] [security2:error] [pid 13989:tid 140450110322368] [client 103.139. ...
show more
[Mon Apr 13 14:56:09.167970 2026] [security2:error] [pid 13989:tid 140450110322368] [client 103.139.26.42:38482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.baidu.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.25.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "617"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.baidu.go.id found within REQUEST_HEADERS:Referer: http://www.baidu.go.id/ request_line = GET /index.php/analisis-iklim/analisis-bulanan/analisis-distribusi-hujan/analisis-distribusi-curah-hujan HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/analisis-iklim/analisis-bulanan/analisis-distribusi-hujan/analisis-distribusi-curah-hujan"] [unique_id "adyhmd3wcD2TOxrxBJYc8QAAjhA"], referer http://www.baidu.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[14006] [1a3F0FJ/azU] [adyhmd3wcD2TOxrxBJYc8QAAjhA] keep_alive=[1] [2026-04-13 14:56:09.167975] [R:adyhmd3wc
...
show less
Email Spam
Hacking
๐ซ๐ท
Sklurk
2026-03-21 02:30:35
(2 months ago)
Web App Attack
Web App Attack
Anonymous
2026-03-08 21:19:39
(3 months ago)
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to ...
show more
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to bypass firewall/robots.txt restrictions in thread-skip.asp
show less
Exploited Host
Bad Web Bot
๐ซ๐ท
Sklurk
2026-03-05 13:13:11
(3 months ago)
Web App Attack
Web App Attack
๐บ๐ธ
matt
2026-03-04 01:56:57
(3 months ago)
DDOS attack with query parameters attempting to overload WordPress site.
DDoS Attack
๐บ๐ธ
SiliSoftware
2026-02-02 22:46:26
(4 months ago)
/phpBB3/viewforum.php?f=12&sid=e1939a5c2693ade2c2461923a1df5108
Web App Attack
Anonymous
2025-11-29 01:44:51
(6 months ago)
wordpress-trap
Web App Attack
๐ท๐ด
INTEQ
2025-10-29 21:06:49
(7 months ago)
Web attack from 103.139.26.42
Web App Attack