๐ฎ๐ฉ
hermawan
2026-09-25 00:58:56
(22 hours ago)
Captured JA4H: ge11n_42b839b9066e | Log: 202.164.218.34 - - [25/Sep/2026:07:58:09 +0700] "GET /index ...
show more
Captured JA4H: ge11n_42b839b9066e | Log: 202.164.218.34 - - [25/Sep/2026:07:58:09 +0700] "GET /index.php/profil/alamat-kantor/list-all-categories/555556811-mengakses-halaman-web-https-karangploso-jatim-bmkg-go-id-secara-offline-dan-menginstallnya-di-hp-android-atau-di-komputer HTTP/1.1" 200 27700 "-" "Mozilla/5.0 (Linux; Android 8.0.0; SM-J330G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Mobile Safari/537.36 EdgA/114.0.1823.74" ge11n_host,x-forwarded-scheme,x-forwarded-proto,x-forwarded-for,x-real-ip,connection,accept-language,user-agent,accept,sec-ch-ua-platform,cf-ray,sec-ch-ua,sec-ch-ua-mobile,sec-fetch-dest,accept-encoding,sec-fetch-site,sec-fetch-mode,cdn-loop,cf-connecting-ip,cf-ipcountry,cf-visitor...
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
sockominfo
2026-09-24 10:00:53
(1 day ago)
Active Response: IP 202.164.218.34 Blocked via Firewall Drop. Threat Score: 3.9/10 (LOW). Confidence ...
show more
Active Response: IP 202.164.218.34 Blocked via Firewall Drop. Threat Score: 3.9/10 (LOW). Confidence: 30%. CVSS v3.1: 0/10 (None). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N. Bayesian Probability: 40%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Very Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐ฎ๐ฉ
RemyLebeau
2026-09-24 03:02:28
(1 day ago)
Web App Attack
Port Scan
๐ฎ๐ฉ
hermawan
2026-09-23 06:10:29
(2 days ago)
Captured JA4H: ge11n_63cf1041adb5 | Log: 202.164.218.34 - - [23/Sep/2026:12:56:34 +0700] "GET /index ...
show more
Captured JA4H: ge11n_63cf1041adb5 | Log: 202.164.218.34 - - [23/Sep/2026:12:56:34 +0700] "GET /index.php/profil/arsip-artikel?catid=478&id=1270%3Aprakiraan-cuaca-daerah-malang-dan-batu-seminggu-ke-depan-berlaku-tanggal-6-12-desember-2016&start=100 HTTP/1.1" 403 3738 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_5 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/147.0.0.0 Mobile/15E148 Safari/604.1" ge11n_host,x-forwarded-scheme,x-forwarded-proto,x-forwarded-for,x-real-ip,connection,upgrade-insecure-requests,cf-ew-via,cdn-loop,sec-fetch-user,sec-fetch-site,cf-ray,accept-encoding,accept-language,accept,user-agent,cf-connecting-ip,sec-fetch-mode,cf-visitor,sec-fetch-dest,priority,cf-ipcountry...
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-09-23 01:45:45
(2 days ago)
[Wed Sep 23 08:43:18.394059 2026] [security2:error] [pid 5499:tid 140714830620352] [client 202.164.2 ...
show more
[Wed Sep 23 08:43:18.394059 2026] [security2:error] [pid 5499:tid 140714830620352] [client 202.164.218.34:0] ModSecurity: Access denied with code 403 (phase 1). Match of "pm matomo.staklim-malang.info " against "SERVER_NAME" required. [file "/etc/modsecurity/coreruleset-4.29.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "208"] [id "440235"] [msg "BAD REQUEST Bro"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: %3a found within SERVER_NAME: staklim-jatim.bmkg.go.id request_line = GET /index.php/profil/arsip-artikel?catid=472&id=1189%3Aprakiraan-cuaca-daerah-malang-dan-batu-seminggu-ke-depan-berlaku-tanggal-25-oktober-2016-1-november-2016&start=200 HTTP/1.1 Request URI RAW = /index.php/profil/arsip-artikel?catid=472&id=1189%3Aprakiraan-cuaca-daerah-malang-dan-batu-seminggu-ke-depan-berlaku-tanggal-25-oktober..."] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/profil/arsip-artikel"] [unique_id "arMutsZtbUdvP
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
sockominfo
2026-09-22 18:00:46
(3 days ago)
Reported by TangerangKota-CSIRT. Status: MALICIOUS
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-09-21 18:00:39
(4 days ago)
Reported by TangerangKota-CSIRT. Status: MALICIOUS
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-09-21 17:00:12
(4 days ago)
CRITICAL: Privileged access during non-business hours - Jakarta timezone (WIB). Threat Score: 8.6/10 ...
show more
CRITICAL: Privileged access during non-business hours - Jakarta timezone (WIB). Threat Score: 8.6/10 (HIGH). Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2026-09-19 20:58:36
(6 days ago)
[Sun Sep 20 03:58:30.799874 2026] [security2:error] [pid 120911:tid 140496148092608] [client 202.164 ...
show more
[Sun Sep 20 03:58:30.799874 2026] [security2:error] [pid 120911:tid 140496148092608] [client 202.164.218.34:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.bmkg.go.id" at REQUEST_HEADERS:referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "601"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.bmkg.go.id found within REQUEST_HEADERS:referer: https://www.bmkg.go.id/ request_line = GET /index.php/prediksi-iklim/prediksi-dasarian/deterministik-curah-hujan-provinsi-jawa-timur HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/prediksi-iklim/prediksi-dasarian/deterministik-curah-hujan-provinsi-jawa-timur"] [unique_id "aq73dhkpG24uISRwBLofiwAAAMs"], referer https://www.bmkg.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[120966] [s3WAR1wQmQk] [aq73dhkpG24uISRwBLofiwAAAMs] keep_alive=[0] [2026-09-20 03:58:30.799879] [R:aq73dhkpG24uISRwBLofiwAAAMs] UA:'M
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
sockominfo
2026-09-16 23:01:05
(1 week ago)
Reported by TangerangKota-CSIRT. Status: MALICIOUS
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-09-16 22:00:28
(1 week ago)
CRITICAL: Privileged access during non-business hours - Jakarta timezone (WIB). Threat Score: 8.6/10 ...
show more
CRITICAL: Privileged access during non-business hours - Jakarta timezone (WIB). Threat Score: 8.6/10 (HIGH). Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-09-15 04:00:09
(1 week ago)
SQL Injection Attack.. Threat Score: 6.5/10 (MEDIUM). Reported by TangerangKota-CSIRT
Hacking
Brute-Force
๐ฎ๐ฉ
sockominfo
2026-09-10 17:00:29
(2 weeks ago)
Reported by TangerangKota-CSIRT. Status: MALICIOUS
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-09-07 18:00:28
(2 weeks ago)
Reported by TangerangKota-CSIRT. Status: MALICIOUS
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-09-07 17:00:27
(2 weeks ago)
Late night login (22:00-05:30) - High risk Jakarta timezone (WIB). Threat Score: 8.6/10 (HIGH). Repo ...
show more
Late night login (22:00-05:30) - High risk Jakarta timezone (WIB). Threat Score: 8.6/10 (HIGH). Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack