This IP address has been reported a total of
2
times from
2 distinct
sources.
113.161.52.161 was first reported on
August 16th 2026 , and the most recent report was
5 hours ago .
In the last 60 days, the top reporter locations were:
Germany
with 1
report;
Indonesia
with 1
report.
The most common categories in these recent reports were:
Hacking
2
times;
Web App Attack
1
time;
Exploited Host
1
time;
Email Spam
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐ฎ๐ฉ
hermawan
2026-10-06 00:25:57
(5 hours ago)
[Tue Oct 06 07:11:15.810157 2026] [security2:error] [pid 1126825:tid 140665522472640] [client 113.16 ...
show more
[Tue Oct 06 07:11:15.810157 2026] [security2:error] [pid 1126825:tid 140665522472640] [client 113.161.52.161:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.yahoo.go.id" at REQUEST_HEADERS:referer. [file "/etc/modsecurity/coreruleset-4.29.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "618"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.yahoo.go.id found within REQUEST_HEADERS:referer: https://www.yahoo.go.id/ request_line = GET /index.php/prediksi-iklim/prediksi-dasarian/monitoring-dan-prediksi-curah-hujan HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/prediksi-iklim/prediksi-dasarian/monitoring-dan-prediksi-curah-hujan"] [unique_id "asQ8oyj_OEmJlEka3_v5AgAAAQ0"], referer https://www.yahoo.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[1126865] [x3dK1iDRFWQ] [asQ8oyj_OEmJlEka3_v5AgAAAQ0] keep_alive=[0] [2026-10-06 07:11:15.810166] [R:asQ8oyj_OEmJlEka3_v5AgAAAQ0] UA:'Mozilla/5.0 (Wi
...
show less
Email Spam
Hacking
๐ฉ๐ช
Vegascosmetics
2026-08-16 10:29:44
(1 month ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after deep/obfuscated attack (encoding nest ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after deep/obfuscated attack (encoding nesting / CPU-drain risk). Evidence: DEEP ATTACK: Recursive currentUrl nesting detected
show less
Hacking
Exploited Host
Web App Attack
Showing 1 to
2
of 2 reports