Anonymous
2026-08-15 16:30:40
(6 days ago)
Large-scale coordinated botnet (1.2M+ IPs). Ordered by Alexander Pen'kov (alexander-pen-kov-7b41aa6a ...
show more
Large-scale coordinated botnet (1.2M+ IPs). Ordered by Alexander Pen'kov (alexander-pen-kov-7b41aa6a/Shursky [yordim|LIS|MOW]); Attacker: Mikhail Smirnov (mikhail-smirnov-79830323/Aidan [MOW]) employed by Angara Technologies Group | Attack Signature Blocked: /wishlist/index/add/product/12914/form_key/NXy7Y8hBO9WE3jcE/ | UA: Mozilla/5.0 (Macintosh; PPC Mac OS X 10_6_5 rv:6.0; apn-IN) AppleWebKit/534.27.6 (KHTML, like Gecko) Version/4.0.5 Safari/534.27.6 | (Magento Site)
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-11 14:15:27
(1 week ago)
[11/Aug/2026:17:15:26 +0300] -- 118.99.123.5 Ban reason: User-Agent Python/
Bad Web Bot
Web App Attack
๐ฉ๐ช
SMARTNET
2026-05-27 06:03:53
(2 months ago)
Aisuru(Mirai variant) DDoS | Incident ID: f33ea243-b344-42fe-b994-8adedb9f85ca
DDoS Attack
๐ฎ๐ฉ
Burayot
2026-03-03 02:17:20
(5 months ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 118.99.123.5 (ID/Indonesia/-): 1 in ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 118.99.123.5 (ID/Indonesia/-): 1 in the last 3600 secs
show less
Web App Attack
Anonymous
2026-02-21 03:31:21
(6 months ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
jkhorvath.com
2025-12-27 09:02:04
(7 months ago)
Request for URL 23.239.9.178:80
Phishing
Brute-Force
Web App Attack
๐ซ๐ท
bigorre.org
2025-12-24 13:39:08
(7 months ago)
Unidentified crawling: not a self-announced bot in user-agent
Bad Web Bot
๐ฎ๐ฉ
hermawan
2025-12-23 08:53:36
(7 months ago)
[Tue Dec 23 15:52:50.710474 2025] [security2:error] [pid 337012:tid 140431657432768] [client 118.99. ...
show more
[Tue Dec 23 15:52:50.710474 2025] [security2:error] [pid 337012:tid 140431657432768] [client 118.99.123.5:19109] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "chatgpt" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.20.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "568"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: chatgpt found within REQUEST_HEADERS:Referer: https://chatgpt.com/ request_line = GET /images/Klimatologi/Prakiraan/03-Prakiraan-Bulanan/Prakiraan_Sifat_Hujan_Bulanan/Prakiraan_Sifat_Hujan_Bulanan_Provinsi_Jawa_Timur/2023/07/02_Prakiraan_Sifat_Hujan_Bulan_OKTOBER_2023_di_Provinsi_Jawa_Timur-Update_dari_Analisis_Bulan_Juli_2023.jpg HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/Klimatologi/Prakiraan/03-Prakiraan-Bulanan/Prakiraan_Sifat_Hujan_Bulanan/Prakiraan_Sifat_Hujan_Bulanan_Provinsi_Jawa_Timur/2023/07/02_Prakiraan_Sifat_Hujan_Bulan_OKTOBER_2023_di_Provinsi_Jawa_Timur-Update_dari
...
show less
Hacking
Web App Attack
๐ฉ๐ช
SMARTNET
2025-11-26 02:37:10
(8 months ago)
Aisuru(Mirai variant) DDoS
DDoS Attack
๐ณ๐ฑ
mha.fi
2025-11-03 05:57:00
(9 months ago)
Unauthorized connection attempt detected from IP address 118.99.123.5 to port 1433 (DNS-NL) [o]
Brute-Force
Exploited Host
๐ฎ๐ฉ
hermawan
2025-10-16 14:48:45
(10 months ago)
[Thu Oct 16 21:48:44.615188 2025] [security2:error] [pid 802102:tid 140597457299136] [client 118.99. ...
show more
[Thu Oct 16 21:48:44.615188 2025] [security2:error] [pid 802102:tid 140597457299136] [client 118.99.123.5:41524] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Test" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "228"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Test found within REQUEST_HEADERS:User-Agent: Test Certificate Info request_line = HEAD /https://staklim-jatim.bmkg.go.id/ HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/https://staklim-jatim.bmkg.go.id/"] [unique_id "aPEFzMNvNDOE8Kg2lxySzgAAA48"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[802144] [sH26tsfCFM8] [aPEFzMNvNDOE8Kg2lxySzgAAA48] keep_alive=[0] [2025-10-16 21:48:44.615193] [R:aPEFzMNvNDOE8Kg2lxySzgAAA48] UA:'Test Certificate Info' Host:'staklim-jatim.bmkg.go.id'
...
show less
Hacking
Web App Attack
Anonymous
2025-10-12 06:45:39
(10 months ago)
Ports: 143,993; Direction: 0; Trigger: LF_DISTATTACK
Brute-Force
SSH
๐ณ๐ฑ
i-turnradio.nl
2025-10-03 01:10:58
(10 months ago)
2025-10-03 @ 03:10:58 (CET) ~ Blocked based on risk assessment and prior abuse reports
Web App Attack
๐บ๐ธ
Rayulcifer
2025-10-01 15:40:16
(10 months ago)
118.99.123.5 - - [01/Oct/2025:10:40:15 -0500] "CONNECT 23.239.9.178:80 HTTP/1.0" 502 601 "-" "-"
118 ...
show more
118.99.123.5 - - [01/Oct/2025:10:40:15 -0500] "CONNECT 23.239.9.178:80 HTTP/1.0" 502 601 "-" "-"
118.99.123.5 - - [01/Oct/2025:10:40:15 -0500] "GET http://proxyjudge.us/ HTTP/1.0" 200 85479 "-" "-"
...
show less
Open Proxy
Port Scan
Hacking
Web App Attack
SSH
๐ฎ๐ฉ
hermawan
2025-09-14 15:26:28
(11 months ago)
[Sun Sep 14 22:21:50.936144 2025] [security2:error] [pid 2318882:tid 140266943014592] [client 118.99 ...
show more
[Sun Sep 14 22:21:50.936144 2025] [security2:error] [pid 2318882:tid 140266943014592] [client 118.99.123.5:44284] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)(?:(?:^|=)[\\\\s\\\\v]*(?:t[\\"'\\\\)\\\\[-\\\\x5c]*(?:(?:(?:\\\\|\\\\||&&)[\\\\s\\\\v]*)?\\\\$[!#\\\\(\\\\*\\\\-0-9\\\\?-@_a-\\\\{]*)?\\\\x5c?i[\\"'\\\\)\\\\[-\\\\x5c]*(?:(?:(?:\\\\|\\\\||&&)[\\\\s\\\\v]*)?\\\\$[!#\\\\(\\\\*\\\\-0-9\\\\?-@_a-\\\\{]*)?\\\\x5c?m[\\"'\\\\)\\\\[-\\\\x5c]*(?:(?:(?:\\\\|\\\\||&&)[\\\\s\\\\v]*)?\\ ..." at REQUEST_COOKIES:_cc_id. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "2272"] [id "932245"] [msg "Remote Command Execution: Unix Command Injection (command without evasion)"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: fd found within REQUEST_COOKIES:_cc_id: fd44b6f37e61103f5c127a6376dc6cde request_line = GET /index.php/prakiraan-iklim/prakiraan-bulanan/prak
...
show less
Hacking
Web App Attack