๐ฎ๐ฉ
Monsieur_Zhi
2026-07-14 03:19:00
(1 week ago)
IP 180.178.103.2 generated 1,032 aggressive automated HTTP POST requests within 24 hours. The attack ...
show more
IP 180.178.103.2 generated 1,032 aggressive automated HTTP POST requests within 24 hours. The attacker attempted to bypass protections and perform parameter fuzzing/probing using unauthorized parameters (including 'g-recaptcha-response-announ'). This behavior is identified as automated web scraping/probing.
show less
Web Spam
Brute-Force
Web App Attack
Hacking
๐ฎ๐ฉ
hermawan
2026-06-30 06:39:50
(3 weeks ago)
06/30/2026-13:39:46.881480 [Drop] [**] [1:3100000062:0] Suricata match TLS ja3 scan Uniq Zeek no 62 ...
show more
06/30/2026-13:39:46.881480 [Drop] [**] [1:3100000062:0] Suricata match TLS ja3 scan Uniq Zeek no 62 with hash_004bf73563645cc1faefe99886ed32eb [**] [Classification: (null)] [Priority: 3] {TCP} 180.178.103.2:37586 -> 103.166.156.58:443
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
sockominfo
2026-06-29 20:00:52
(3 weeks ago)
Suspicious user agent detected python-httpx/0.28.1. Threat Score: 3.8/10 (LOW). Confidence: 30%. CVS ...
show more
Suspicious user agent detected python-httpx/0.28.1. Threat Score: 3.8/10 (LOW). Confidence: 30%. CVSS v3.1: 0/10 (None). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N. Bayesian Probability: 39%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-06-29 19:00:09
(3 weeks ago)
Suspicious user agent detected python-httpx/0.28.1. Threat Score: 0/10 (INFORMATIONAL). Reported by ...
show more
Suspicious user agent detected python-httpx/0.28.1. Threat Score: 0/10 (INFORMATIONAL). Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2026-06-29 01:39:28
(3 weeks ago)
[Mon Jun 29 08:39:27.960455 2026] [security2:error] [pid 929884:tid 140331824162496] [client 180.178 ...
show more
[Mon Jun 29 08:39:27.960455 2026] [security2:error] [pid 929884:tid 140331824162496] [client 180.178.103.2:34008] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Postman" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "273"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Postman found within REQUEST_HEADERS:User-Agent: PostmanRuntime/7.36.1 request_line = GET /index.php/profil/meteorologi/list-all-categories/113-meteorologi/prakiraan-meteorologi/555557336-prakiraan-harian-cuaca-wisata-di-jawa-timur-untuk-hari-ini-pada-pagi-siang-malam-dan-dini-hari-meliputi-tempat-wisata-antara-lain-kebun-binatang-surabaya-taman-safari-indonesia-prigen-pasuruan-dan-jawa-timur-jatim-park-batu HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/index.php/profil/meteorologi/list-all-categories/113-meteorologi/prakiraan-meteorologi/555557336-prakiraan-harian-cuaca
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
sockominfo
2026-06-19 23:00:09
(1 month ago)
Suspicious user agent detected python-httpx/0.28.1. Threat Score: 0/10 (INFORMATIONAL). Reported by ...
show more
Suspicious user agent detected python-httpx/0.28.1. Threat Score: 0/10 (INFORMATIONAL). Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2026-06-19 21:44:41
(1 month ago)
[Sat Jun 20 04:44:40.250459 2026] [security2:error] [pid 1520888:tid 140501192763072] [client 180.17 ...
show more
[Sat Jun 20 04:44:40.250459 2026] [security2:error] [pid 1520888:tid 140501192763072] [client 180.178.103.2:33638] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Postman" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "254"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Postman found within REQUEST_HEADERS:User-Agent: PostmanRuntime/7.36.1 request_line = GET /index.php/normal-klimatologi/198-normal-awal-musim/normal-awal-musim-kemarau/normal-awal-musim-kemarau-propinsi-jawa-timur HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/index.php/normal-klimatologi/198-normal-awal-musim/normal-awal-musim-kemarau/normal-awal-musim-kemarau-propinsi-jawa-timur"] [unique_id "ajW4SHNtDEZLIu64RbAS-QABjAg"] [staklim-malang.info] [staklim-malang.info] top=[1520897] [yPMqM2J4t18] [ajW4SHNtDEZLIu64RbAS-QABjAg] keep_alive=[1] [2026-06-20 04:44:40.250466] [R:
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-06-19 04:38:30
(1 month ago)
[Fri Jun 19 11:38:27.994078 2026] [security2:error] [pid 310463:tid 140628210923200] [client 180.178 ...
show more
[Fri Jun 19 11:38:27.994078 2026] [security2:error] [pid 310463:tid 140628210923200] [client 180.178.103.2:45106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Lynx" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "254"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Lynx found within REQUEST_HEADERS:User-Agent: Lynx/3.8.2 libwww-FM/2.15 SSL-MM/2.5 OpenSSL/1.2.8 request_line = GET /b/bulananmalangbatu.pdf HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/b/bulananmalangbatu.pdf"] [unique_id "ajTHwxC2B2f_gAindaGntQADlhM"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[310483] [xIEa3VPtH74] [ajTHwxC2B2f_gAindaGntQADlhM] keep_alive=[1] [2026-06-19 11:38:27.994081] [R:ajTHwxC2B2f_gAindaGntQADlhM] UA:'Lynx/3.8.2 libwww-FM/2.15 SSL-MM/2.5 OpenSSL/1.2.8' Host:'staklim-jatim.bmkg.go.id' COOKIE:'CONSENT=PENDING+987; SOCS=CAESHAgBEhI
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
sockominfo
2026-06-13 08:00:59
(1 month ago)
Suspicious user agent detected python-httpx/0.28.1. Threat Score: 3.8/10 (LOW). Confidence: 30%. CVS ...
show more
Suspicious user agent detected python-httpx/0.28.1. Threat Score: 3.8/10 (LOW). Confidence: 30%. CVSS v3.1: 0/10 (None). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N. Bayesian Probability: 40%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-06-13 07:00:09
(1 month ago)
Suspicious user agent detected python-httpx/0.28.1. Threat Score: 0/10 (INFORMATIONAL). Reported by ...
show more
Suspicious user agent detected python-httpx/0.28.1. Threat Score: 0/10 (INFORMATIONAL). Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2026-06-12 20:34:50
(1 month ago)
[Sat Jun 13 03:34:47.287261 2026] [security2:error] [pid 317181:tid 140091849688768] [client 180.178 ...
show more
[Sat Jun 13 03:34:47.287261 2026] [security2:error] [pid 317181:tid 140091849688768] [client 180.178.103.2:59950] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Postman" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "254"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Postman found within REQUEST_HEADERS:User-Agent: PostmanRuntime/7.36.1 request_line = GET /index.php/profil/meteorologi/list-all-categories/4247-klimatologi/infografis/infografis-klimatologi/infografis-bulanan/infografis-bulanan-iklim-ekstrim/infografis-bulanan-iklim-ekstrim-tahun-2024/555560993-infografis-bulanan-iklim-ekstrem-suhu-udara-maksimum-bulan-mei-tahun-2024-di-provinsi-jawa-timur HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/index.php/profil/meteorologi/list-all-categories/4247-klimatologi/infografis/infografis-klimatologi/infografis-bulanan/infografis-bulanan
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-06-03 22:16:42
(1 month ago)
06/04/2026-05:16:38.861790 [Drop] [**] [1:3100000062:0] Suricata match TLS ja3 scan Uniq Zeek no 62 ...
show more
06/04/2026-05:16:38.861790 [Drop] [**] [1:3100000062:0] Suricata match TLS ja3 scan Uniq Zeek no 62 with hash_004bf73563645cc1faefe99886ed32eb [**] [Classification: (null)] [Priority: 3] {TCP} 180.178.103.2:38472 -> 103.166.156.58:443
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-05-25 03:17:11
(1 month ago)
05/25/2026-10:17:10.813598 [Drop] [**] [1:2100001898:0] Suricata match TLS ja4 scan Uniq Zeek no 18 ...
show more
05/25/2026-10:17:10.813598 [Drop] [**] [1:2100001898:0] Suricata match TLS ja4 scan Uniq Zeek no 1898 with hash_t13d1812h1_85036bcba153_d41ae481755e [**] [Classification: (null)] [Priority: 3] {TCP} 180.178.103.2:57134 -> 103.166.156.58:443
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
sockominfo
2026-05-23 03:00:25
(1 month ago)
TheHive Threat Scoring assessment: 180.178.103.2
CVSS v3.1: 0/10 (None)
CVSS Vector: CVSS:3.1/AV:und ...
show more
TheHive Threat Scoring assessment: 180.178.103.2
CVSS v3.1: 0/10 (None)
CVSS Vector: CVSS:3.1/AV:undefined/AC:undefined/PR:undefined/UI:undefined/S:undefined/C:undefined/I:undefined/A:undefined
Bayesian Probability: 80%
MITRE ATT&CK: Exploit Public-Facing Application, Valid Accounts, Command and Scripting Interpreter, Application Layer Protocol, Brute Force, Account Manipulation
OWASP Risk: High (L:8, I:6)
Combined Score: 4.92/10
Confidence Interval: ยฑ0.01
Status: Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-05-23 02:00:29
(1 month ago)
Reported by TangerangKota-CSIRT. Status: MALICIOUS
Hacking
Web App Attack