๐ฆ๐บ
screwlooseit.com.au
2026-09-12 17:21:11
(4 days ago)
Blocked by CSF 13 firewall - Rule: US/United States/-
Web App Attack
Anonymous
2026-07-28 16:30:02
(1 month ago)
| [Dangerous/South Africa] Aggressive IP 168.235.203.226 (~30 hits). Type: DoS Defender- Web server ...
show more
| [Dangerous/South Africa] Aggressive IP 168.235.203.226 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Web App Attack
Hacking
SQL Injection
๐ฎ๐ฉ
hermawan
2026-07-01 11:51:06
(2 months ago)
[Wed Jul 01 18:51:03.371694 2026] [security2:error] [pid 327194:tid 139636290610880] [client 168.235 ...
show more
[Wed Jul 01 18:51:03.371694 2026] [security2:error] [pid 327194:tid 139636290610880] [client 168.235.203.226:45964] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "X-Forwarded-For" at REQUEST_HEADERS_NAMES:X-Forwarded-For. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "444"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: X-Forwarded-For found within REQUEST_HEADERS_NAMES:X-Forwarded-For: X-Forwarded-For request_line = GET /index.php/profil/meteorologi/list-all-categories/4380-klimatologi/infografis/infografis-klimatologi/infografis-harian/suhu-minimum-harian-di-jawa-timur/suhu-minimum-harian-di-jawa-timur-tahun-2026/555563224-suhu-minimum-harian-di-jawa-timur-tanggal-29-juni-2026-pukul-07-01-wib-30-juni-2026-pukul-07-00-wib HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/list-all-categories/4380-klimatologi/infografis
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-06-27 08:11:50
(2 months ago)
[Sat Jun 27 15:11:49.450497 2026] [security2:error] [pid 962114:tid 139939269191360] [client 168.235 ...
show more
[Sat Jun 27 15:11:49.450497 2026] [security2:error] [pid 962114:tid 139939269191360] [client 168.235.203.226:55612] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "X-Forwarded-For" at REQUEST_HEADERS_NAMES:X-Forwarded-For. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "444"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: X-Forwarded-For found within REQUEST_HEADERS_NAMES:X-Forwarded-For: X-Forwarded-For request_line = GET /index.php/profil/meteorologi/list-of-all-tags/gempa-terkini HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/list-of-all-tags/gempa-terkini"] [unique_id "aj-FxUxetEuNUYVeY6LapwAABsI"], referer https://www.google.co.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[962143] [MkjpxndVMUc] [aj-FxUxetEuNUYVeY6LapwAABsI] keep_alive=[0] [2026-06-27 15:11:49.450506] [R:aj-FxUxetEuNUYVeY6LapwAABs
...
show less
Email Spam
Hacking
๐บ๐ธ
Werr Brassder
2026-06-23 17:33:43
(2 months ago)
Honeypot caught 2 probes: admin ร2. First 2026-06-23T17:33:25Z, last 2026-06-23T17:33:43Z. WordPress ...
show more
Honeypot caught 2 probes: admin ร2. First 2026-06-23T17:33:25Z, last 2026-06-23T17:33:43Z. WordPress + Next.js decoy endpoints on a personal site (no real CMS).
show less
Brute-Force
Web App Attack
๐ฎ๐ฉ
hermawan
2026-06-19 00:28:37
(2 months ago)
[Fri Jun 19 07:28:33.822387 2026] [security2:error] [pid 1113285:tid 140710040827584] [client 168.23 ...
show more
[Fri Jun 19 07:28:33.822387 2026] [security2:error] [pid 1113285:tid 140710040827584] [client 168.235.203.226:5188] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "X-Forwarded-For" at REQUEST_HEADERS_NAMES:X-Forwarded-For. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "425"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: X-Forwarded-For found within REQUEST_HEADERS_NAMES:X-Forwarded-For: X-Forwarded-For request_line = GET /index.php/prediksi-iklim/prediksi-bulanan/curah-hujan/3-bulan-ke-depan/555563196-prediksi-bulanan-curah-hujan-bulan-juli-tahun-2026-update-dari-analisis-bulan-mei-tahun-2026-di-provinsi-jawa-timur HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/prediksi-iklim/prediksi-bulanan/curah-hujan/3-bulan-ke-depan/555563196-prediksi-bulanan-curah-hujan-bulan-juli-tahun-2026-update-dari-analisis-bulan-mei-tahun-2026-di-provinsi-
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-06-03 22:05:19
(3 months ago)
[Thu Jun 04 05:05:19.054235 2026] [security2:error] [pid 249687:tid 140147643369152] [client 168.235 ...
show more
[Thu Jun 04 05:05:19.054235 2026] [security2:error] [pid 249687:tid 140147643369152] [client 168.235.203.226:56810] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "X-Forwarded-For" at REQUEST_HEADERS_NAMES:X-Forwarded-For. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "425"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: X-Forwarded-For found within REQUEST_HEADERS_NAMES:X-Forwarded-For: X-Forwarded-For request_line = GET /index.php/prediksi-iklim/prediksi-bulanan/curah-hujan/3-bulan-ke-depan/555563119-prediksi-bulanan-curah-hujan-bulan-juni-tahun-2026-update-dari-analisis-bulan-april-tahun-2026-di-provinsi-jawa-timur HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/prediksi-iklim/prediksi-bulanan/curah-hujan/3-bulan-ke-depan/555563119-prediksi-bulanan-curah-hujan-bulan-juni-tahun-2026-update-dari-analisis-bulan-april-tahun-2026-di-provi
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
sockominfo
2026-05-18 23:00:19
(3 months ago)
User login to application from malicious IP 168.235.203.226.. Threat Score: 0/10 (INFORMATIONAL). Re ...
show more
User login to application from malicious IP 168.235.203.226.. Threat Score: 0/10 (INFORMATIONAL). Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-05-08 09:00:39
(4 months ago)
User login to application from malicious IP 168.235.203.226.. Threat Score: 3.7/10 (LOW). Confidence ...
show more
User login to application from malicious IP 168.235.203.226.. Threat Score: 3.7/10 (LOW). Confidence: 30%. CVSS v3.1: 0/10 (None). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:N. Bayesian Probability: 40%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-05-08 08:00:40
(4 months ago)
User login to application from malicious IP 168.235.203.226.. Threat Score: 3.8/10 (LOW). Confidence ...
show more
User login to application from malicious IP 168.235.203.226.. Threat Score: 3.8/10 (LOW). Confidence: 30%. CVSS v3.1: 0/10 (None). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:N. Bayesian Probability: 40%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-05-08 07:00:15
(4 months ago)
User login to application from malicious IP 168.235.203.226.. Threat Score: 0/10 (INFORMATIONAL). Re ...
show more
User login to application from malicious IP 168.235.203.226.. Threat Score: 0/10 (INFORMATIONAL). Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2025-12-27 08:06:23
(8 months ago)
[WAZUH] SUPPRESSED: IP 168.235.203.226 blocked - 8 times fired in 6 hour
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2025-12-15 17:05:20
(9 months ago)
[WAZUH] SUPPRESSED: IP 168.235.203.226 blocked - 8 times fired in 6 hour
Hacking
Web App Attack
Anonymous
2025-11-21 20:24:32
(9 months ago)
Ports: *; Direction: 0; Trigger: CT_LIMIT
Brute-Force
SSH
๐จ๐ณ
ThreatBook.io
2025-11-05 22:31:28
(10 months ago)
ThreatBook Intelligence: Zombie,Spam more details on https://threatbook.io/ip/168.235.203.226
2025-1 ...
show more
ThreatBook Intelligence: Zombie,Spam more details on https://threatbook.io/ip/168.235.203.226
2025-11-05 09:04:26 /cc.gif
2025-11-05 09:04:33 /cc.gif
show less
Web App Attack