๐จ๐ฆ
polycoda
2026-06-13 12:02:54
(4 days ago)
๐ฅถ Part of massive botnet scraping campaign that nearly turned into a DDoS on 2025-11-27
DDoS Attack
๐บ๐ธ
anon333
2026-06-04 13:33:07
(1 week ago)
Hacker syslog review 1780579986
Hacking
๐ฉ๐ช
iNetWorker
2026-06-03 08:21:39
(2 weeks ago)
firewall-block, port(s): 27015/udp
Port Scan
Anonymous
2026-06-02 10:27:38
(2 weeks ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
๐ฉ๐ช
SMARTNET
2026-05-27 06:03:53
(3 weeks ago)
Aisuru(Mirai variant) DDoS | Incident ID: 0a9278f2-ffb8-4472-8b4f-87e634c16433
DDoS Attack
๐ฎ๐น
A000Z
2026-05-06 13:37:46
(1 month ago)
Fail2Ban: 103.88.169.157 was banned for Aggressive Bad Bot detected by Nginx/Fail2Ban. UA: Mozilla/5 ...
show more
Fail2Ban: 103.88.169.157 was banned for Aggressive Bad Bot detected by Nginx/Fail2Ban. UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/57.0.3068.1566 Safari/537.36
show less
Bad Web Bot
Anonymous
2026-04-27 23:32:16
(1 month ago)
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to ...
show more
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to bypass firewall/robots.txt restrictions in thread-skip.asp
show less
Exploited Host
Bad Web Bot
๐ณ๐ฑ
EGP Abuse Dept
2026-01-17 02:49:27
(5 months ago)
Unauthorized connection to Telnet port 23
Port Scan
Hacking
๐ฎ๐ฉ
securejdprop
2025-12-29 14:23:48
(5 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ET CINS Active Thr ...
show more
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ET CINS Active Threat Intelligence Poor Reputation IP group 131). Ip 103.88.169.157 performed 'crowdsecurity/suricata-major-severity' (1 events over 0s) at 2025-12-29 14:23:47.553479497 +0000 UTC
show less
Web App Attack
๐ฎ๐ฉ
hermawan
2025-07-06 01:40:38
(11 months ago)
[Sun Jul 06 08:39:20.602399 2025] [security2:error] [pid 492043:tid 139641625749184] [client 103.88. ...
show more
[Sun Jul 06 08:39:20.602399 2025] [security2:error] [pid 492043:tid 139641625749184] [client 103.88.169.157:60449] ModSecurity: Access denied with code 403 (phase 1). Match of "pm googlebot " against "REQUEST_HEADERS:From" required. [file "/etc/modsecurity/coreruleset-4.15.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "97"] [id "448105"] [msg "BAD REQUEST Header From "] [data "Matched Data: found within REQUEST_HEADERS:From: bingbot(at)microsoft.com request_line = GET /index.php/profil/meteorologi/list-all-categories/121-peralatan-observasi-klimatologi/actinograph/78-actinograph HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/list-all-categories/121-peralatan-observasi-klimatologi/actinograph/78-actinograph"] [unique_id "aGnTyCTIzBvu8YGteLMCUwAAABg"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[492094] [fXTNy/iF9FU] [aGnTyCTIzBvu8YGteLMCUwAAABg] keep_alive=[0] [2025-07-06 08:39:20.602403] [R:aGnTyCTIzBvu8YG
...
show less
Hacking
Web App Attack
๐ซ๐ฎ
000rosiu
2025-06-02 02:34:03
(1 year ago)
Triggered Cloudflare WAF (firewallCustom) from ID.
Action taken: MANAGED_CHALLENGE
ASN: 136093 (FAZN ...
show more
Triggered Cloudflare WAF (firewallCustom) from ID.
Action taken: MANAGED_CHALLENGE
ASN: 136093 (FAZNET-AS-ID PT Mitra Lintas Multimedia)
Protocol: HTTP/1.1 (GET method)
Endpoint: /
Timestamp: 2025-06-02T02:27:21Z
Ray ID: 949382d8fc56f8fe
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0 Safari/537.36
Report generated by Cloudflare-WAF-To-AbuseIPDB:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2025-05-27 01:48:38
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ซ๐ฎ
000rosiu
2025-05-26 20:07:15
(1 year ago)
Triggered Cloudflare WAF (firewallCustom) from ID.
Action taken: MANAGED_CHALLENGE
ASN: 136093 (FAZN ...
show more
Triggered Cloudflare WAF (firewallCustom) from ID.
Action taken: MANAGED_CHALLENGE
ASN: 136093 (FAZNET-AS-ID PT Mitra Lintas Multimedia)
Protocol: HTTP/1.1 (GET method)
Endpoint: /wp-login.php
Timestamp: 2025-05-26T20:02:35Z
Ray ID: 945fdefcea71b00b
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.1.1 Safari/605.1.15
Report generated by Cloudflare-WAF-To-AbuseIPDB:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฎ๐ฉ
hermawan
2025-05-16 10:53:10
(1 year ago)
[Fri May 16 17:52:39.909037 2025] [security2:error] [pid 435270:tid 140675496515264] [client 103.88. ...
show more
[Fri May 16 17:52:39.909037 2025] [security2:error] [pid 435270:tid 140675496515264] [client 103.88.169.157:60053] ModSecurity: Access denied with code 403 (phase 1). Match of "pm matomo.staklim-malang.info " against "SERVER_NAME" required. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "142"] [id "440235"] [msg "BAD REQUEST Bro"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: /index.php?id= found within SERVER_NAME: staklim-jatim.bmkg.go.id request_line = GET /index.php?id=2377 HTTP/1.1 Request URI RAW = /index.php?id=2377 Request Basename = index.php"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php"] [unique_id "aCcY9z_ImeJYPw4lPa8ajwAAAG8"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[435369] [8mG6lKbp6Z8] [aCcY9z_ImeJYPw4lPa8ajwAAAG8] keep_alive=[0] [2025-05-16 17:52:39.909043] [R:aCcY9z_ImeJYPw4lPa8ajwAAAG8] UA:'Mozilla/5.0 (Windows NT 10.0; Win64
...
show less
Hacking
Web App Attack
Anonymous
2025-05-11 17:19:18
(1 year ago)
Malicious activity detected
Hacking
Web App Attack