๐ฎ๐ฉ
sockominfo
2026-07-24 10:00:53
(1 day ago)
Zimbra: Login failures from malicious IP: 188.130.129.234. Threat Score: 6.1/10 (MEDIUM). Confidence ...
show more
Zimbra: Login failures from malicious IP: 188.130.129.234. Threat Score: 6.1/10 (MEDIUM). Confidence: 40%. CVSS v3.1: 4.6/10 (Medium). CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L. Bayesian Probability: 77%. MITRE ATT&CK: T1083 (File and Directory Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-07-24 09:00:53
(1 day ago)
Zimbra: Login failures from malicious IP: 188.130.129.234. Threat Score: 6.3/10 (MEDIUM). Confidence ...
show more
Zimbra: Login failures from malicious IP: 188.130.129.234. Threat Score: 6.3/10 (MEDIUM). Confidence: 40%. CVSS v3.1: 4.6/10 (Medium). CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L. Bayesian Probability: 77%. MITRE ATT&CK: T1083 (File and Directory Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-07-24 08:00:10
(1 day ago)
Zimbra: Login failures from malicious IP: 188.130.129.234. Threat Score: 4.8/10 (MEDIUM). Reported b ...
show more
Zimbra: Login failures from malicious IP: 188.130.129.234. Threat Score: 4.8/10 (MEDIUM). Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐ท๐ด
clauss
2026-07-18 05:58:48
(1 week ago)
IP reached maximum auth failures for a one day block
Brute-Force
๐ณ๐ฑ
MM-bot
2025-03-27 08:03:45
(1 year ago)
URL-probe: HTTP/1.1 GET request on /archivarix.cms.php (2025-03-27 09:03:45 UTC+1)
Hacking
Web App Attack
๐บ๐ธ
nationaleventpros.com
2025-02-06 21:19:09
(1 year ago)
WordPress login attempt
Brute-Force
๐ฌ๐ง
Steve
2024-12-17 22:13:57
(1 year ago)
Excessive crawling - not obeying robots.txt
Bad Web Bot
Anonymous
2024-08-28 09:47:31
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฆ๐บ
MAGIC
2024-07-05 03:08:56
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Anonymous
2024-07-05 02:16:07
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2024-06-02 07:21:22
(2 years ago)
(mod_security) mod_security (id:210381) triggered by 188.130.129.234 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210381) triggered by 188.130.129.234 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 02 03:21:18.989270 2024] [security2:error] [pid 19280] [client 188.130.129.234:47737] [client 188.130.129.234] ModSecurity: Access denied with code 403 (phase 2). Invalid URL Encoding: Not enough characters at the end of input at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "82"] [id "210381"] [rev "6"] [msg "COMODO WAF: URL Encoding Abuse Attack Attempt||instagenii.com|F|4"] [data "REQUEST_URI=/__media__/js/netsoltrademark.php?d=diyiluoli3.com%2Fhome.php%3Fmod%3Dspace%26uid%3D824706%26do%3Dprofile%2"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "instagenii.com"] [uri "/__media__/js/netsoltrademark.php"] [unique_id "ZlwdbuDH0KZskWd8TuYJVgAAAAU"], referer: http://instagenii.com/__media__/js/netsoltrademark.php?d=intensedebate.com%2Fpeople%2Fwilderchu1
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2024-05-15 12:01:56
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ณ๐ฑ
mawan
2024-03-25 18:27:44
(2 years ago)
Suspected of having performed illicit activity on AMS server.
Web App Attack
๐ฆ๐บ
MAGIC
2024-03-24 11:10:34
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-03-06 10:55:22
(2 years ago)
(mod_security) mod_security (id:240950) triggered by 188.130.129.234 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240950) triggered by 188.130.129.234 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 06 05:55:15.328511 2024] [security2:error] [pid 14831] [client 188.130.129.234:37259] [client 188.130.129.234] ModSecurity: Access denied with code 403 (phase 1). Pattern match "\\\\D" at TX:1. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "4530"] [id "240950"] [rev "2"] [msg "COMODO WAF: XSS & SQL injection vulnerability in Pragyan CMS 3.0 (CVE-2015-1471)||www.contagion-game.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.contagion-game.com"] [uri "/wiki/index.php"] [unique_id "ZehLk8EO6Kjhwm-6L73JjQAAAAA"], referer: http://www.contagion-game.com/
show less
Brute-Force
Bad Web Bot
Web App Attack