๐บ๐ธ
kosada.com
2026-07-21 12:47:12
(1 day ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐ซ๐ท
sthoyer.de
2026-07-21 06:20:36
(1 day ago)
Jul 21 08:20:35 sthoyer kernel: [IPTables-Block] IN=eth0 OUT= MAC=00:50:56:43:00:af:c0:69:11:cd:10:f ...
show more
Jul 21 08:20:35 sthoyer kernel: [IPTables-Block] IN=eth0 OUT= MAC=00:50:56:43:00:af:c0:69:11:cd:10:f7:08:00 SRC=114.10.45.140 DST=173.212.223.67 LEN=52 TOS=0x00 PREC=0x20 TTL=113 ID=16317 DF PROTO=TCP SPT=46166 DPT=445 WINDOW=8192 RES=0x00 SYN URGP=0
...
show less
Port Scan
๐ซ๐ท
sthoyer.de
2026-07-21 01:58:39
(1 day ago)
Jul 21 03:58:38 sthoyer kernel: [IPTables-Block] IN=eth0 OUT= MAC=00:50:56:43:00:af:c0:69:11:cd:10:f ...
show more
Jul 21 03:58:38 sthoyer kernel: [IPTables-Block] IN=eth0 OUT= MAC=00:50:56:43:00:af:c0:69:11:cd:10:f7:08:00 SRC=114.10.45.140 DST=173.212.223.67 LEN=52 TOS=0x00 PREC=0x20 TTL=113 ID=18557 DF PROTO=TCP SPT=45170 DPT=445 WINDOW=8192 RES=0x00 SYN URGP=0
...
show less
Port Scan
๐ฎ๐ฉ
David Koswari
2026-07-20 05:10:00
(2 days ago)
REQ_BLOCKED_ACL
DDoS Attack
FTP Brute-Force
Ping of Death
Port Scan
Hacking
SQL Injection
Spoofing
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
IoT Targeted
๐ซ๐ท
security.rdmc.fr
2026-06-04 09:57:42
(1 month ago)
Port Scan Attack proto:TCP src:7767 dst:23
Port Scan
๐บ๐ธ
MPL
2026-06-04 09:48:00
(1 month ago)
tcp/23
Port Scan
๐ฉ๐ช
pltcldvlpr
2026-05-09 12:40:50
(2 months ago)
Unidentified crawler ignoring robots.txt: 114.10.45.140 - - [09/May/2026:11:27:36 +0200] "GET /proto ...
show more
Unidentified crawler ignoring robots.txt: 114.10.45.140 - - [09/May/2026:11:27:36 +0200] "GET /protocol?id=hb_17_83¶graph=4137347&seq=893 HTTP/1.1" 302 5 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" asn=4761 org="PT. INDOSAT Tbk"
114.10.45.140 - - [09/May/2026:14:40:49 +0200] "GET /protocol?id=bb_4_47&offset=500&seq=503 HTTP/1.1" 200 347713 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.3" asn=4761 org="PT. INDOSAT Tbk"
...
show less
Bad Web Bot
Anonymous
2026-04-27 23:12:58
(2 months ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
Anonymous
2026-04-17 15:39:25
(3 months ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
๐ณ๐ฑ
exxos
2025-09-10 19:03:01
(10 months ago)
Attacks with Bad user agents
Hacking
๐ฎ๐ฉ
hermawan
2025-08-07 09:57:41
(11 months ago)
[Thu Aug 07 16:57:40.158610 2025] [security2:error] [pid 249891:tid 140098778621632] [client 114.10. ...
show more
[Thu Aug 07 16:57:40.158610 2025] [security2:error] [pid 249891:tid 140098778621632] [client 114.10.45.140:57128] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "WOW64" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "228"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: WOW64 found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36 request_line = GET /pelayanan-jasa-v1.html HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/pelayanan-jasa-v1.html"] [unique_id "aJR4lORqDBIpW3RjBqyExwABURE"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[249909] [FirifIMOyXM] [aJR4lORqDBIpW3RjBqyExwABURE] keep_alive=[1] [2025-08-07 16:57:40.158614] [R:aJR4lORqDBIpW3RjBqyExwABURE] UA:'Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like
...
show less
Hacking
Web App Attack
Anonymous
2025-06-04 11:54:29
(1 year ago)
Web App Attack
Web App Attack
๐ฎ๐ฉ
hermawan
2025-06-02 20:06:29
(1 year ago)
[Tue Jun 03 03:06:28.891147 2025] [security2:error] [pid 1615946:tid 140072431118016] [client 114.10 ...
show more
[Tue Jun 03 03:06:28.891147 2025] [security2:error] [pid 1615946:tid 140072431118016] [client 114.10.45.140:41096] ModSecurity: Access denied with code 403 (phase 1). Match of "ipMatch 103.166.156.58" against "REMOTE_ADDR" required. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "350"] [id "440006"] [msg "Connection Close Header"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: close found within REMOTE_ADDR: 114.10.45.140 request_line = POST /_search?pretty HTTP/1.1 Request URI RAW = /_search?pretty Request Basename = _search"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/_search"] [unique_id "aD4ERCvHiexgHAjvzMrW6wAAAIs"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[1615989] [n3OjTET6om0] [aD4ERCvHiexgHAjvzMrW6wAAAIs] keep_alive=[0] [2025-06-03 03:06:28.891152] [R:aD4ERCvHiexgHAjvzMrW6wAAAIs] UA:'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Ch
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
Incidents Response Neptus Team
2025-06-02 15:57:00
(1 year ago)
Report Abuse IP
Hacking
Exploited Host
Web App Attack
๐ฎ๐ฉ
hermawan
2025-06-02 11:06:03
(1 year ago)
[Mon Jun 02 18:05:31.629264 2025] [security2:error] [pid 1341336:tid 140565127612096] [client 114.10 ...
show more
[Mon Jun 02 18:05:31.629264 2025] [security2:error] [pid 1341336:tid 140565127612096] [client 114.10.45.140:51960] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/wp" at REQUEST_FILENAME. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "52"] [id "448101"] [msg "BAD REQUEST FILENAME - Detected and Blocked"] [data "Matched Data: /wp found within REQUEST_FILENAME: /wp-content/plugins/advanced-text-widget/readme.txt request_line = GET /wp-content/plugins/advanced-text-widget/readme.txt HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/wp-content/plugins/advanced-text-widget/readme.txt"] [unique_id "aD2Fe-GYmHNyRPPZJ0g6IAAAAFA"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[1341385] [CCAJvozGdiA] [aD2Fe-GYmHNyRPPZJ0g6IAAAAFA] keep_alive=[0] [2025-06-02 18:05:31.629269] [R:aD2Fe-GYmHNyRPPZJ0g6IAAAAFA] UA:'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/122.0.0.0 Safa
...
show less
Hacking
Web App Attack