๐ง๐ท
noconex
2026-08-28 10:18:04
(12 hours ago)
Wazuh Alert | Rule ID: 100199 | Desc: Suricata: (ET SCAN Potential SSH Scan) detectado de 119.152.24 ...
show more
Wazuh Alert | Rule ID: 100199 | Desc: Suricata: (ET SCAN Potential SSH Scan) detectado de 119.152.245.205
show less
Port Scan
Brute-Force
SSH
Anonymous
2026-08-28 07:32:18
(15 hours ago)
suricata IPS/IDS detection, ruleset ET SCAN Potential SSH Scan
Port Scan
Anonymous
2026-08-27 04:02:22
(1 day ago)
denied SSH access attempt. destination port 22.
Port Scan
Brute-Force
SSH
๐ง๐ท
noconex
2026-08-25 05:57:10
(3 days ago)
Wazuh Alert | Rule ID: 100199 | Desc: Suricata: (ET SCAN Potential SSH Scan) detectado de 119.152.24 ...
show more
Wazuh Alert | Rule ID: 100199 | Desc: Suricata: (ET SCAN Potential SSH Scan) detectado de 119.152.245.205
show less
Port Scan
Brute-Force
SSH
๐บ๐ธ
MPL
2026-08-25 02:31:41
(3 days ago)
tcp/22 (5 or more attempts)
Port Scan
๐น๐ผ
kk_it_man
2026-08-23 12:00:01
(5 days ago)
honey catch
Port Scan
Anonymous
2026-08-22 01:38:03
(6 days ago)
denied traffic to a honeypot network. destination port 22.
Port Scan
Hacking
๐ฎ๐ฉ
sockominfo
2026-08-12 09:00:53
(2 weeks ago)
Zimbra: Login failures from malicious IP: 119.152.245.205. Threat Score: 6.2/10 (MEDIUM). Confidence ...
show more
Zimbra: Login failures from malicious IP: 119.152.245.205. Threat Score: 6.2/10 (MEDIUM). Confidence: 40%. CVSS v3.1: 4.6/10 (Medium). CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L. Bayesian Probability: 77%. MITRE ATT&CK: T1083 (File and Directory Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-08-12 08:00:53
(2 weeks ago)
Zimbra: Login failures from malicious IP: 119.152.245.205. Threat Score: 6.4/10 (MEDIUM). Confidence ...
show more
Zimbra: Login failures from malicious IP: 119.152.245.205. Threat Score: 6.4/10 (MEDIUM). Confidence: 40%. CVSS v3.1: 4.6/10 (Medium). CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L. Bayesian Probability: 77%. MITRE ATT&CK: T1083 (File and Directory Discovery). Tactic: TA0001. Freshness: Very Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-08-12 07:00:53
(2 weeks ago)
Zimbra: Login failures from malicious IP: 119.152.245.205. Threat Score: 6.5/10 (HIGH). Confidence: ...
show more
Zimbra: Login failures from malicious IP: 119.152.245.205. Threat Score: 6.5/10 (HIGH). Confidence: 40%. CVSS v3.1: 4.6/10 (Medium). CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L. Bayesian Probability: 77%. MITRE ATT&CK: T1083 (File and Directory Discovery). Tactic: TA0001. Freshness: Very Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฌ๐ง
Andrew
2026-08-11 11:21:34
(2 weeks ago)
2026-08-11T11:21:27.706071+00:00 Debian sshd[492695]: error: kex_exchange_identification: Connection ...
show more
2026-08-11T11:21:27.706071+00:00 Debian sshd[492695]: error: kex_exchange_identification: Connection closed by remote host
2026-08-11T11:21:27.706331+00:00 Debian sshd[492695]: Connection closed by 119.152.245.205 port 36930
...
show less
Port Scan
Hacking
Brute-Force
SSH
๐บ๐ธ
kosada.com
2026-07-29 06:46:45
(4 weeks ago)
Web bot: DDoS
DDoS Attack
Bad Web Bot
๐บ๐ธ
stechusa
2026-07-02 11:40:10
(1 month ago)
ELEVATED_THREAT | country=PK | ASN=Pakistan Telecommunication Company Limited | 246 IPs targeting /c ...
show more
ELEVATED_THREAT | country=PK | ASN=Pakistan Telecommunication Company Limited | 246 IPs targeting /category/light-bulbs.html | Facet request during elevated threat (facet_ratio=0.73, unique_ips=658) | HTTP/1.1 over TLS (elevated=True)
show less
Bad Web Bot
DDoS Attack
๐ฐ๐ท
zlhIcd
2026-06-15 09:19:00
(2 months ago)
119.152.245.205 - - [15/Jun/2026:17:14:07 +0900] "GET /pcwiki/index.php?days=30&from=20251205042714& ...
show more
119.152.245.205 - - [15/Jun/2026:17:14:07 +0900] "GET /pcwiki/index.php?days=30&from=20251205042714&hideminor=0&hidemyself=1&title=%ED%8A%B9%EC%88%98%EA%B8%B0%EB%8A%A5:%EB%A7%81%ED%81%AC%EC%B5%9C%EA%B7%BC%EB%B0%94%EB%80%9C HTTP/1.1" 404 460 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 15_4_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.6998.88 Safari/537.36"
...
show less
Web Spam
SQL Injection
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Purple
2026-04-18 11:00:00
(4 months ago)
Scraping attack (2000IPs+) not respecting robots.txt - Spoofed browser header chrome win10
Bad Web Bot