๐ช๐ธ
librebit
2026-08-30 11:12:53
(20 hours ago)
Brute force
Brute-Force
๐ฉ๐ช
Admins@FBN
2026-08-30 08:44:22
(22 hours ago)
FW-PortScan: Traffic Blocked srcport=61011 dstport=1000
Port Scan
๐บ๐ธ
MPL
2026-08-30 08:05:38
(23 hours ago)
tcp/2000 (2 or more attempts)
Port Scan
๐ฌ๐ง
Nov
2026-08-30 07:55:26
(23 hours ago)
Unauthorized access attempt (tcp/3790)
Port Scan
๐บ๐ธ
Axel
2026-08-30 07:55:20
(23 hours ago)
Blocked by UFW on LAXHH [8089/tcp] | SPT: 61004 | TTL: 246 | LEN: 44 | TOS: 0x00 โข Reported by: gith ...
show more
Blocked by UFW on LAXHH [8089/tcp] | SPT: 61004 | TTL: 246 | LEN: 44 | TOS: 0x00 โข Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-29 07:44:10
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 143.198.97.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 143.198.97.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 03:44:06.522413 2026] [security2:error] [pid 7565:tid 7565] [client 143.198.97.139:43900] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||civilwarscout.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "civilwarscout.com"] [uri "/images/desktop.ini"] [unique_id "apKNxiWifZqrrlTZby3hMAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Cyber Crusader
2026-05-24 21:09:52
(3 months ago)
Hundreds of Attempts (at least) to Connect to and Access Firewall Ports
Port Scan
Hacking
Brute-Force
๐ซ๐ท
masterguru
2026-05-22 06:46:42
(3 months ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 143.198.97.139 (US/United States/-): ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 143.198.97.139 (US/United States/-): 1 in the last 3600 secs (0-197)
show less
Hacking
๐ฎ๐ฉ
hermawan
2025-07-02 20:09:23
(1 year ago)
[Thu Jul 03 03:08:37.909064 2025] [security2:error] [pid 86211:tid 140704982484672] [client 143.198. ...
show more
[Thu Jul 03 03:08:37.909064 2025] [security2:error] [pid 86211:tid 140704982484672] [client 143.198.97.139:38096] ModSecurity: Access denied with code 403 (phase 1). Match of "ipMatch 103.166.156.58" against "REMOTE_ADDR" required. [file "/etc/modsecurity/coreruleset-4.15.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "369"] [id "440006"] [msg "Connection Close Header"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: close found within REMOTE_ADDR: 143.198.97.139 request_line = GET /config/development.sphinx.conf HTTP/1.1 Request URI RAW = /config/development.sphinx.conf Request Basename = development.sphinx.conf"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/config/development.sphinx.conf"] [unique_id "aGWRxULaG0ctLUeX0mYCNAAAABI"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[86257] [niyO07d9Jw0] [aGWRxULaG0ctLUeX0mYCNAAAABI] keep_alive=[0] [2025-07-03 03:08:37.909081] [R:aGWRxULaG0ctLUeX0mYCNAAAABI]
...
show less
Hacking
Web App Attack
๐ฒ๐ฝ
kuro1730
2025-07-02 16:23:00
(1 year ago)
Excessive Crawling/Scraping
Bad Web Bot
๐ฎ๐ฉ
hermawan
2025-07-02 15:47:24
(1 year ago)
[Wed Jul 02 22:46:51.440644 2025] [security2:error] [pid 8917:tid 140290769790656] [client 143.198.9 ...
show more
[Wed Jul 02 22:46:51.440644 2025] [security2:error] [pid 8917:tid 140290769790656] [client 143.198.97.139:33066] ModSecurity: Access denied with code 403 (phase 1). Match of "ipMatch 103.166.156.58" against "REMOTE_ADDR" required. [file "/etc/modsecurity/coreruleset-4.15.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "369"] [id "440006"] [msg "Connection Close Header"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: close found within REMOTE_ADDR: 143.198.97.139 request_line = GET /parameters.yml HTTP/1.1 Request URI RAW = /parameters.yml Request Basename = parameters.yml"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/parameters.yml"] [unique_id "aGVUa_PQ1HZ-VLq2zoT5mwAAAQc"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[8951] [eEphK3ROpmk] [aGVUa_PQ1HZ-VLq2zoT5mwAAAQc] keep_alive=[0] [2025-07-02 22:46:51.440651] [R:aGVUa_PQ1HZ-VLq2zoT5mwAAAQc] UA:'Mozilla/5.0 (Debian; Linux x86_64; rv:125.0) Gecko/201
...
show less
Hacking
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2025-07-02 05:03:42
(1 year ago)
143.198.97.139 - - [02/Jul/2025:08:03:40 +0300] "GET /wp-config.php-backup HTTP/1.1" 404 2841 "-" "M ...
show more
143.198.97.139 - - [02/Jul/2025:08:03:40 +0300] "GET /wp-config.php-backup HTTP/1.1" 404 2841 "-" "Mozilla/5.0 (Kubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ฎ๐ฉ
hermawan
2025-07-01 23:42:35
(1 year ago)
[Wed Jul 02 06:42:04.627384 2025] [security2:error] [pid 262538:tid 140268305106624] [client 143.198 ...
show more
[Wed Jul 02 06:42:04.627384 2025] [security2:error] [pid 262538:tid 140268305106624] [client 143.198.97.139:58278] ModSecurity: Access denied with code 403 (phase 1). Match of "ipMatch 103.166.156.58" against "REMOTE_ADDR" required. [file "/etc/modsecurity/coreruleset-4.15.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "369"] [id "440006"] [msg "Connection Close Header"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: close found within REMOTE_ADDR: 143.198.97.139 request_line = GET /db/robomongo.json HTTP/1.1 Request URI RAW = /db/robomongo.json Request Basename = robomongo.json"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/db/robomongo.json"] [unique_id "aGRyTEgqhlNEENuDbJbe2gAAAIo"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[262575] [lcsNsaZG+Ac] [aGRyTEgqhlNEENuDbJbe2gAAAIo] keep_alive=[0] [2025-07-02 06:42:04.627394] [R:aGRyTEgqhlNEENuDbJbe2gAAAIo] UA:'Mozilla/5.0 (X11; Linux x86_64; rv:109.0)
...
show less
Hacking
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2025-07-01 10:51:40
(1 year ago)
143.198.97.139 - - [01/Jul/2025:13:51:36 +0300] "GET /.env HTTP/1.1" 404 2840 "-" "Mozilla/5.0 (Maci ...
show more
143.198.97.139 - - [01/Jul/2025:13:51:36 +0300] "GET /.env HTTP/1.1" 404 2840 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.4 Safari/605.1.15"
...
show less
Web App Attack
๐ฎ๐ฉ
hermawan
2025-07-01 09:00:40
(1 year ago)
[Tue Jul 01 16:00:39.428047 2025] [security2:error] [pid 362254:tid 139941929522880] [client 143.198 ...
show more
[Tue Jul 01 16:00:39.428047 2025] [security2:error] [pid 362254:tid 139941929522880] [client 143.198.97.139:47062] ModSecurity: Access denied with code 403 (phase 1). Match of "ipMatch 103.166.156.58" against "REMOTE_ADDR" required. [file "/etc/modsecurity/coreruleset-4.15.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "369"] [id "440006"] [msg "Connection Close Header"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: close found within REMOTE_ADDR: 143.198.97.139 request_line = GET /.msmtprc HTTP/1.1 Request URI RAW = /.msmtprc Request Basename = .msmtprc"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/.msmtprc"] [unique_id "aGOjt9lIOKCFtRSUANJxqQAAAJc"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[362304] [+KLaYFqBxjk] [aGOjt9lIOKCFtRSUANJxqQAAAJc] keep_alive=[0] [2025-07-01 16:00:39.428053] [R:aGOjt9lIOKCFtRSUANJxqQAAAJc] UA:'Mozilla/5.0 (CentOS; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko)
...
show less
Hacking
Web App Attack