๐ต๐ฑ
nfsec.pl
2025-08-03 01:12:45
(10 months ago)
Detected: TCP scan on port: 445 with flags: SYN
Port Scan
๐ฉ๐ช
kalof
2025-08-01 03:15:57
(10 months ago)
ports, 445/24H:2/7D:2
Port Scan
๐ฉ๐ช
Ad0lar
2025-08-01 03:15:50
(10 months ago)
ports, 445/24H:1/7D:1
Port Scan
๐ฆ๐น
HoneyPotEu-AT
2025-07-29 10:36:15
(10 months ago)
1753785374 - 07/29/2025 12:36:14 Host: 114.198.244.129/114.198.244.129 Port: 445 TCP Blocked
...
Port Scan
๐ฎ๐ฉ
amanat institute
2025-07-22 03:57:00
(10 months ago)
ddos web app
DDoS Attack
Brute-Force
๐ฉ๐ช
kalof
2025-07-08 06:36:21
(11 months ago)
ports, 445/24H:1/7D:1
Port Scan
๐บ๐ธ
sumnone
2025-07-08 01:43:58
(11 months ago)
Port probing on unauthorized port 445
Port Scan
Hacking
Exploited Host
๐ฉ๐ช
Beta
2025-07-04 06:24:54
(11 months ago)
ports, 445/24H:1/7D:1
Port Scan
๐ฎ๐ฉ
hermawan
2025-06-21 20:04:30
(11 months ago)
[Sun Jun 22 03:03:59.370453 2025] [security2:error] [pid 217318:tid 140595166168768] [client 114.198 ...
show more
[Sun Jun 22 03:03:59.370453 2025] [security2:error] [pid 217318:tid 140595166168768] [client 114.198.244.129:42624] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "myactivity.google.com" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.15.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "455"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: myactivity.google.com found within REQUEST_HEADERS:Referer: https://myactivity.google.com/ request_line = GET /b/curah_bulanankediri.jpg HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/b/curah_bulanankediri.jpg"] [unique_id "aFcQL9fT_N8zp0riNGdtUQAASAM"], referer https://myactivity.google.com/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[217335] [Mfy1elp9Ufg] [aFcQL9fT_N8zp0riNGdtUQAASAM] keep_alive=[1] [2025-06-22 03:03:59.370463] [R:aFcQL9fT_N8zp0riNGdtUQAASAM] UA:'Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Mob
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-06-05 03:11:26
(1 year ago)
[Thu Jun 05 09:51:59.623343 2025] [security2:error] [pid 51554:tid 140562553317056] [client 114.198. ...
show more
[Thu Jun 05 09:51:59.623343 2025] [security2:error] [pid 51554:tid 140562553317056] [client 114.198.244.129:56636] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "myactivity.google.com" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "439"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: myactivity.google.com found within REQUEST_HEADERS:Referer: https://myactivity.google.com/ request_line = GET /b/curah_bulanankediri.jpg HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/b/curah_bulanankediri.jpg"] [unique_id "aEEGT_clZdunRQ3HLxyQ7wAAXA4"], referer https://myactivity.google.com/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[51569] [o+2LMtJB8Vc] [aEEGT_clZdunRQ3HLxyQ7wAAXA4] keep_alive=[1] [2025-06-05 09:51:59.623350] [R:aEEGT_clZdunRQ3HLxyQ7wAAXA4] UA:'Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Mobil
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-06-03 21:26:21
(1 year ago)
[Wed Jun 04 04:25:35.613847 2025] [security2:error] [pid 141464:tid 140142518941376] [client 114.198 ...
show more
[Wed Jun 04 04:25:35.613847 2025] [security2:error] [pid 141464:tid 140142518941376] [client 114.198.244.129:37404] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "myactivity.google.com" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "439"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: myactivity.google.com found within REQUEST_HEADERS:Referer: https://myactivity.google.com/ request_line = GET /b/curah_bulanankediri.jpg HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/b/curah_bulanankediri.jpg"] [unique_id "aD9oT0S7sfEqjJEjPOWttAAAgAw"], referer https://myactivity.google.com/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[141477] [T4ZnhWmkY7w] [aD9oT0S7sfEqjJEjPOWttAAAgAw] keep_alive=[1] [2025-06-04 04:25:35.613850] [R:aD9oT0S7sfEqjJEjPOWttAAAgAw] UA:'Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Mob
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-05-21 18:06:48
(1 year ago)
[Thu May 22 01:06:02.355908 2025] [security2:error] [pid 221533:tid 140246768211648] [client 114.198 ...
show more
[Thu May 22 01:06:02.355908 2025] [security2:error] [pid 221533:tid 140246768211648] [client 114.198.244.129:41860] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "myactivity.google.com" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "439"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: myactivity.google.com found within REQUEST_HEADERS:Referer: https://myactivity.google.com/ request_line = GET /b/curah_bulanankediri.jpg HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/b/curah_bulanankediri.jpg"] [unique_id "aC4WChUg6XKDL4SSDm0ScQAAWzE"], referer https://myactivity.google.com/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[221583] [Lp3ON3HsjqI] [aC4WChUg6XKDL4SSDm0ScQAAWzE] keep_alive=[1] [2025-05-22 01:06:02.355916] [R:aC4WChUg6XKDL4SSDm0ScQAAWzE] UA:'Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Mob
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-05-19 04:15:26
(1 year ago)
[Mon May 19 10:06:03.191428 2025] [security2:error] [pid 633491:tid 140017025427136] [client 114.198 ...
show more
[Mon May 19 10:06:03.191428 2025] [security2:error] [pid 633491:tid 140017025427136] [client 114.198.244.129:57180] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "myactivity.google.com" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "439"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: myactivity.google.com found within REQUEST_HEADERS:Referer: https://myactivity.google.com/ request_line = GET /b/curah_bulanankediri.jpg HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/b/curah_bulanankediri.jpg"] [unique_id "aCqgGyRTVUXBrx5w6oOinwAARB4"], referer https://myactivity.google.com/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[633525] [QwaGaaxHy1o] [aCqgGyRTVUXBrx5w6oOinwAARB4] keep_alive=[1] [2025-05-19 10:06:03.191438] [R:aCqgGyRTVUXBrx5w6oOinwAARB4] UA:'Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Mob
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-05-18 02:05:06
(1 year ago)
[Sun May 18 09:05:05.887863 2025] [security2:error] [pid 715203:tid 140050293552832] [client 114.198 ...
show more
[Sun May 18 09:05:05.887863 2025] [security2:error] [pid 715203:tid 140050293552832] [client 114.198.244.129:37068] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "myactivity.google.com" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "439"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: myactivity.google.com found within REQUEST_HEADERS:Referer: https://myactivity.google.com/ request_line = GET /b/curah_bulanankediri.jpg HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/b/curah_bulanankediri.jpg"] [unique_id "aClAUdt0OSA-tCMkdKKELQAAXgY"], referer https://myactivity.google.com/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[715210] [biewcUeTZBA] [aClAUdt0OSA-tCMkdKKELQAAXgY] keep_alive=[1] [2025-05-18 09:05:05.887867] [R:aClAUdt0OSA-tCMkdKKELQAAXgY] UA:'Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Mob
...
show less
Hacking
Web App Attack
๐จ๐ฆ
Largnet SOC
2025-02-27 10:20:03
(1 year ago)
114.198.244.129 triggered Icarus honeypot on port 445. Check us out on github.
Port Scan
Hacking