๐ฎ๐ฉ
sockominfo
2026-06-26 23:00:53
(3 weeks ago)
User access to sensitive menu during non-business hours, Weekend login - Suspicious for Government. ...
show more
User access to sensitive menu during non-business hours, Weekend login - Suspicious for Government. Threat Score: 7.5/10 (HIGH). Confidence: 50%. CVSS v3.1: 6.3/10 (Medium). CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L. Bayesian Probability: 93%. MITRE ATT&CK: T1071 (Application Layer Protocol). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-06-26 22:00:53
(3 weeks ago)
User access to sensitive menu during non-business hours, Weekend login - Suspicious for Government. ...
show more
User access to sensitive menu during non-business hours, Weekend login - Suspicious for Government. Threat Score: 7.5/10 (HIGH). Confidence: 50%. CVSS v3.1: 6.3/10 (Medium). CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L. Bayesian Probability: 93%. MITRE ATT&CK: T1071 (Application Layer Protocol). Tactic: TA0001. Freshness: Very Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-06-11 19:00:54
(1 month ago)
User login to application during non-business hours. Threat Score: 6.5/10 (HIGH). Confidence: 40%. C ...
show more
User login to application during non-business hours. Threat Score: 6.5/10 (HIGH). Confidence: 40%. CVSS v3.1: 4.6/10 (Medium). CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L. Bayesian Probability: 87%. MITRE ATT&CK: T1046 (Network Service Scanning). Tactic: TA0001. Freshness: Very Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-06-08 23:00:32
(1 month ago)
Reported by TangerangKota-CSIRT. Status: MALICIOUS
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-06-08 22:00:08
(1 month ago)
Late night login (22:00-05:30) - High risk Jakarta timezone (WIB). Threat Score: 8.6/10 (HIGH). Repo ...
show more
Late night login (22:00-05:30) - High risk Jakarta timezone (WIB). Threat Score: 8.6/10 (HIGH). Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-06-07 22:00:34
(1 month ago)
Reported by TangerangKota-CSIRT. Status: MALICIOUS
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-06-04 23:00:26
(1 month ago)
TheHive Threat Scoring assessment: 103.18.34.179
CVSS v3.1: 0/10 (None)
CVSS Vector: CVSS:3.1/AV:und ...
show more
TheHive Threat Scoring assessment: 103.18.34.179
CVSS v3.1: 0/10 (None)
CVSS Vector: CVSS:3.1/AV:undefined/AC:undefined/PR:undefined/UI:undefined/S:undefined/C:undefined/I:undefined/A:undefined
Bayesian Probability: 80%
MITRE ATT&CK: Exploit Public-Facing Application, Valid Accounts, Command and Scripting Interpreter, Application Layer Protocol, Brute Force, Account Manipulation
OWASP Risk: High (L:8, I:6)
Combined Score: 4.92/10
Confidence Interval: ยฑ0.01
Status: Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-06-04 22:00:29
(1 month ago)
Reported by TangerangKota-CSIRT. Status: MALICIOUS
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2026-05-30 17:38:43
(1 month ago)
[Sun May 31 00:38:40.556723 2026] [security2:error] [pid 520796:tid 140573674538688] [client 103.18. ...
show more
[Sun May 31 00:38:40.556723 2026] [security2:error] [pid 520796:tid 140573674538688] [client 103.18.34.179:47298] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.yahoo.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "582"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.yahoo.go.id found within REQUEST_HEADERS:Referer: https://www.yahoo.go.id/ request_line = GET /TableFilter/system-v173.css HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/TableFilter/system-v173.css"] [unique_id "ahsgoMLCDwehz_ZMbXwjOQAACwY"], referer https://www.yahoo.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[520803] [NBSUbswscfE] [ahsgoMLCDwehz_ZMbXwjOQAACwY] keep_alive=[1] [2026-05-31 00:38:40.556727] [R:ahsgoMLCDwehz_ZMbXwjOQAACwY] UA:'Mozilla/5.0 (Linux; U; Android 12; SM-G975U1 Build/SP1A.210812.016; wv) AppleWebKit/537.36 (KHTML, like Gecko) Versi
...
show less
Email Spam
Hacking
๐บ๐ธ
MPL
2026-05-29 15:57:57
(1 month ago)
tcp/443 (7 or more attempts)
Port Scan
Anonymous
2026-05-28 08:41:06
(1 month ago)
2026-05-28 10:41:05 ERROR util.AccessViolations - 103.18.34.179 report to fail2ban - action: block
. ...
show more
2026-05-28 10:41:05 ERROR util.AccessViolations - 103.18.34.179 report to fail2ban - action: block
...
show less
Hacking
Brute-Force
Bad Web Bot
๐ฉ๐ช
SMARTNET
2026-05-27 06:03:53
(1 month ago)
Aisuru(Mirai variant) DDoS | Incident ID: fd8a75e9-7ad9-4605-bec7-39ad26683952
DDoS Attack
๐ฎ๐ฉ
sockominfo
2026-04-28 17:00:28
(2 months ago)
SIMASN Account Signin during non bussiness hour.. Threat Score: 6.8/10 (MEDIUM). Reported by Tangera ...
show more
SIMASN Account Signin during non bussiness hour.. Threat Score: 6.8/10 (MEDIUM). Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-04-08 21:00:33
(3 months ago)
SIMASN Account Signin during non bussiness hour., User login to application during non-business hour ...
show more
SIMASN Account Signin during non bussiness hour., User login to application during non-business hours. Threat Score: 7.5/10 (HIGH). Confidence: 50%. CVSS v3.1: 6.3/10 (Medium). CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L. Bayesian Probability: 93%. MITRE ATT&CK: T1071 (Application Layer Protocol). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-04-08 18:46:29
(3 months ago)
[WAZUH] User login to application during non-business hours
Hacking
Web App Attack