Anonymous
2026-07-15 10:02:17
(1 month ago)
Web attack
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-06-08 09:00:53
(2 months ago)
User login to application from malicious IP 168.235.206.68.. Threat Score: 4.1/10 (MEDIUM). Confiden ...
show more
User login to application from malicious IP 168.235.206.68.. Threat Score: 4.1/10 (MEDIUM). Confidence: 40%. CVSS v3.1: 0/10 (None). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:N. Bayesian Probability: 57%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-06-08 08:00:08
(2 months ago)
User login to application from malicious IP 168.235.206.68.. Threat Score: 0/10 (INFORMATIONAL). Rep ...
show more
User login to application from malicious IP 168.235.206.68.. Threat Score: 0/10 (INFORMATIONAL). Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-05-31 15:00:11
(3 months ago)
User login to application from malicious IP 168.235.206.68.. Threat Score: 0/10 (INFORMATIONAL). Rep ...
show more
User login to application from malicious IP 168.235.206.68.. Threat Score: 0/10 (INFORMATIONAL). Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-05-14 14:00:12
(3 months ago)
User login to application from malicious IP 168.235.206.68.. Threat Score: 0/10 (INFORMATIONAL). Rep ...
show more
User login to application from malicious IP 168.235.206.68.. Threat Score: 0/10 (INFORMATIONAL). Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2026-04-25 11:55:47
(4 months ago)
[Sat Apr 25 18:54:52.539297 2026] [security2:error] [pid 525398:tid 140699345340096] [client 168.235 ...
show more
[Sat Apr 25 18:54:52.539297 2026] [security2:error] [pid 525398:tid 140699345340096] [client 168.235.206.68:39552] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "X-Forwarded-For" at REQUEST_HEADERS_NAMES:X-Forwarded-For. [file "/etc/modsecurity/coreruleset-4.25.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "466"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: X-Forwarded-For found within REQUEST_HEADERS_NAMES:X-Forwarded-For: X-Forwarded-For request_line = GET / HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/"] [unique_id "aeyrjCRe7pdql0euGtTlEwAAANI"], referer https://www.google.co.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[525443] [kkSbjAdws4w] [aeyrjCRe7pdql0euGtTlEwAAANI] keep_alive=[0] [2026-04-25 18:54:52.539301] [R:aeyrjCRe7pdql0euGtTlEwAAANI] UA:'Mozilla/5.0 (Linux; U; Android 13; en-US; RMX3834 Build/TP1A.220624.014) AppleWebKit/534.30 (KHTML, like Gecko)
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-04-20 10:27:22
(4 months ago)
[Mon Apr 20 17:27:21.985817 2026] [security2:error] [pid 162283:tid 140651379287744] [client 168.235 ...
show more
[Mon Apr 20 17:27:21.985817 2026] [security2:error] [pid 162283:tid 140651379287744] [client 168.235.206.68:20760] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "X-Forwarded-For" at REQUEST_HEADERS_NAMES:X-Forwarded-For. [file "/etc/modsecurity/coreruleset-4.25.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "466"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: X-Forwarded-For found within REQUEST_HEADERS_NAMES:X-Forwarded-For: X-Forwarded-For request_line = GET / HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/"] [unique_id "aeX_iQlfHBrC9GUjKg6MJQAAAEE"], referer https://www.google.co.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[162339] [X2JwvuGWxiI] [aeX_iQlfHBrC9GUjKg6MJQAAAEE] keep_alive=[0] [2026-04-20 17:27:21.985820] [R:aeX_iQlfHBrC9GUjKg6MJQAAAEE] UA:'Mozilla/5.0 (Linux; U; Android 13; en-US; RMX3834 Build/TP1A.220624.014) AppleWebKit/534.30 (KHTML, like Gecko)
...
show less
Email Spam
Hacking
๐จ๐ณ
ThreatBook.io
2026-04-15 00:03:23
(4 months ago)
ThreatBook Intelligence: Zombie more details on http://threatbook.io/ip/168.235.206.68
2026-04-14 03 ...
show more
ThreatBook Intelligence: Zombie more details on http://threatbook.io/ip/168.235.206.68
2026-04-14 03:01:25 /cc.gif
show less
Web App Attack
Anonymous
2025-12-20 03:48:26
(8 months ago)
Ports: *; Direction: 0; Trigger: CT_LIMIT
Brute-Force
SSH
๐ฎ๐ฉ
hermawan
2025-12-09 16:26:26
(8 months ago)
[Tue Dec 09 23:25:41.137837 2025] [security2:error] [pid 31235:tid 140673248384704] [client 168.235. ...
show more
[Tue Dec 09 23:25:41.137837 2025] [security2:error] [pid 31235:tid 140673248384704] [client 168.235.206.68:49680] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "X-Forwarded-For" at REQUEST_HEADERS_NAMES:X-Forwarded-For. [file "/etc/modsecurity/coreruleset-4.20.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "399"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: X-Forwarded-For found within REQUEST_HEADERS_NAMES:X-Forwarded-For: X-Forwarded-For request_line = GET /index.php/profil/meteorologi/list-of-all-tags/gempa-terkini HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/list-of-all-tags/gempa-terkini"] [unique_id "aThNhbD4na4lnqD6ippXVQAAAAI"], referer https://staklim-jatim.bmkg.go.id/index.php/profil/meteorologi/list-of-all-tags/gempa-terkini [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[31264] [iLjWXMd0gC4] [aThNhbD4na4lnqD6ippXVQAAAAI] keep_aliv
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-12-04 19:53:11
(8 months ago)
[Fri Dec 05 02:52:40.840168 2025] [security2:error] [pid 144465:tid 140118940604096] [client 168.235 ...
show more
[Fri Dec 05 02:52:40.840168 2025] [security2:error] [pid 144465:tid 140118940604096] [client 168.235.206.68:42938] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "X-Forwarded-For" at REQUEST_HEADERS_NAMES:X-Forwarded-For. [file "/etc/modsecurity/coreruleset-4.20.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "399"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: X-Forwarded-For found within REQUEST_HEADERS_NAMES:X-Forwarded-For: X-Forwarded-For request_line = GET /index.php/prediksi-iklim/prediksi-bulanan/curah-hujan/3-bulan-ke-depan/555561950-prediksi-bulanan-curah-hujan-bulan-juni-tahun-2025-update-dari-analisis-bulan-april-tahun-2025-di-provinsi-jawa-timur HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/prediksi-iklim/prediksi-bulanan/curah-hujan/3-bulan-ke-depan/555561950-prediksi-bulanan-curah-hujan-bulan-juni-tahun-2025-update-dari-analisis-bulan-april-tahun-2025-di-provin
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2025-12-03 23:31:48
(8 months ago)
[WAZUH] SUPPRESSED: IP 168.235.206.68 blocked - 8 times fired in 6 hour
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-11-21 19:35:49
(9 months ago)
[Sat Nov 22 02:35:18.796428 2025] [security2:error] [pid 376899:tid 139908535432896] [client 168.235 ...
show more
[Sat Nov 22 02:35:18.796428 2025] [security2:error] [pid 376899:tid 139908535432896] [client 168.235.206.68:64742] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "X-Forwarded-For" at REQUEST_HEADERS_NAMES:X-Forwarded-For. [file "/etc/modsecurity/coreruleset-4.20.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "394"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: X-Forwarded-For found within REQUEST_HEADERS_NAMES:X-Forwarded-For: X-Forwarded-For request_line = GET /index.php/prakiraan-bulanan/4261-prakiraan-bulanan-untuk-6-bulan-ke-depan-di-provinsi-jawa-timur/prakiraan-bulanan-curah-hujan-untuk-6-bulan-ke-depan-di-provinsi-jawa-timur/555561117-prakiraan-bulanan-curah-hujan-di-kabupaten-bojonegoro-untuk-6-bulan-ke-depan HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/index.php/prakiraan-bulanan/4261-prakiraan-bulanan-untuk-6-bulan-ke-depan-di-provinsi-jawa-timur/prakiraan-bulanan-curah-hujan-un
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2025-11-19 21:27:33
(9 months ago)
[WAZUH] SUPPRESSED: IP 168.235.206.68 blocked - 8 times fired in 6 hour
Hacking
Web App Attack
Anonymous
2025-11-12 20:52:31
(9 months ago)
Ports: *; Direction: 0; Trigger: CT_LIMIT
Brute-Force
SSH