This IP address has been reported a total of
8
times from
5 distinct
sources.
114.5.89.183 was first reported on
September 15th 2025 , and the most recent report was
1 day ago .
In the last 60 days, the only reporter location was:
Indonesia
with 1
report.
The most common categories in these recent reports were:
Hacking
1
time;
Email Spam
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐ฎ๐ฉ
hermawan
2026-09-21 03:23:55
(1 day ago)
[Mon Sep 21 10:21:41.306881 2026] [security2:error] [pid 95488:tid 139824388363968] [client 114.5.89 ...
show more
[Mon Sep 21 10:21:41.306881 2026] [security2:error] [pid 95488:tid 139824388363968] [client 114.5.89.183:0] ModSecurity: Access denied with code 403 (phase 1). Match of "pm /gtagku-v2.js /administrator/index.php?option=com_content /swiper-v114na.js /ga-choise-v6.js /bmkg-192.png /800-600.webp /bmkg-192x192.png /ga-v5.js /favicon-16-16.png /matomo-partition-21-01-2026-5-5-0.js /script-v185.js /script-v188.js /script-v184.j ..." against "REQUEST_LINE" required. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "458"] [id "440008"] [msg "BAD REQUEST Bro"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: If-Modified-Since found within REQUEST_LINE: GET /Whatsapp_Kantor_BMKG_Malang_Stasiun_Klimatologi_Jawa_Timur_40X40.webp HTTP/1.1 request_line = GET /Whatsapp_Kantor_BMKG_Malang_Stasiun_Klimatologi_Jawa_Timur_40X40.webp HTTP/1.1 Request URI RAW = /Whatsapp_Kantor_BMKG_Malang_Stasiun_
...
show less
Email Spam
Hacking
๐ซ๐ท
Sklurk
2026-07-23 09:41:38
(1 month ago)
Web App Attack
Web App Attack
๐บ๐ธ
kosada.com
2026-07-23 06:36:28
(1 month ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐ฎ๐ฉ
penjaga BRIN
2026-07-23 03:26:16
(1 month ago)
Web application attack
Web App Attack
๐บ๐ธ
kosada.com
2026-07-14 03:40:59
(2 months ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐ฎ๐ฉ
origrata
2026-06-12 02:51:09
(3 months ago)
[OGWAF] remote_file_inclusion attack blocked | severity: critical | GET /plugins/generic/hypothesis/ ...
show more
[OGWAF] remote_file_inclusion attack blocked | severity: critical | GET /plugins/generic/hypothesis/pdf.js/viewer/web/viewer.html?file=https%3A%2F%2Fejurnal.sttdumai.ac.id%2Findex.php%2Funitek%2Farticle%2Fdownload%2F234%2F177%2F881 | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Sa | payload: https://ejurnal.sttdumai.ac.id/index.php/unitek/article/download/234/177/881
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2026-06-10 03:18:40
(3 months ago)
06/10/2026-10:18:37.405916 [Drop] [**] [1:2210054:1] SURICATA STREAM excessive retransmissions [**] ...
show more
06/10/2026-10:18:37.405916 [Drop] [**] [1:2210054:1] SURICATA STREAM excessive retransmissions [**] [Classification: Generic Protocol Command Decode] [Priority: 3] {TCP} 114.5.89.183:64498 -> 103.166.156.58:443
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2025-09-15 01:12:44
(1 year ago)
[Mon Sep 15 08:12:12.196882 2025] [security2:error] [pid 2824492:tid 140266653517504] [client 114.5. ...
show more
[Mon Sep 15 08:12:12.196882 2025] [security2:error] [pid 2824492:tid 140266653517504] [client 114.5.89.183:49284] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "%3Clink" at REQUEST_FILENAME. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "69"] [id "448101"] [msg "BAD REQUEST FILENAME - Detected and Blocked"] [data "Matched Data: %3Clink found within REQUEST_FILENAME: /index.php/component/tags/tag/%3Clink%20rel= request_line = GET /index.php/component/tags/tag/%3Clink%20rel= HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/component/tags/tag/%3Clink%20rel="] [unique_id "aMdn6PO98ml5GvWbqLKC9gABiBY"], referer https://staklim-jatim.bmkg.go.id/index.php/component/tags/tag/30 [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[2824515] [ahU3sQzQdok] [aMdn6PO98ml5GvWbqLKC9gABiBY] keep_alive=[1] [2025-09-15 08:12:12.196888] [R:aMdn6PO98ml5GvWbqLKC9gABiBY] UA:'Mozilla/5.0 (Linux; An
...
show less
Hacking
Web App Attack
Showing 1 to
8
of 8 reports