🇺🇸
TPI-Abuse
2026-08-22 14:04:59
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 45.198.147.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.198.147.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 10:04:53.713792 2026] [security2:error] [pid 27001:tid 27001] [client 45.198.147.238:60315] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "airdeluxemusic.com"] [uri "/.git/config"] [unique_id "aomshZugMB6qa9Z7fDkc0QAAAAY"], referer: https://airdeluxemusic.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
el-brujo
2026-08-21 09:43:59
(1 day ago)
Cloudflare WAF: Request Path: / Request Query: ?3Xcf2qw37R Host: foro.elhacker.net userAgent: Mozill ...
show more
Cloudflare WAF: Request Path: / Request Query: ?3Xcf2qw37R Host: foro.elhacker.net userAgent: Mozilla/5.0 (Linux; Android 14; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Mobile Safari/537.36 Action: block Source: l7ddos ASN Description: PT. Eka Mas Republik Country: ID Method: GET Timestamp: 2026-08-21T09:43:59Z ruleId: cc5ac300fbc54ceda2944ca261bc58d5. Report generated by Cloudflare-WAF-to-AbuseIPDB.
show less
Hacking
SQL Injection
Web App Attack
🇺🇸
Vano Ganzzz
2026-08-14 15:25:57
(1 week ago)
Triggered Cloudflare WAF (l7ddos) from ID.
Action taken: BLOCK
ASN: 63859 (PT. Eka Mas Republik)
Pro ...
show more
Triggered Cloudflare WAF (l7ddos) from ID.
Action taken: BLOCK
ASN: 63859 (PT. Eka Mas Republik)
Protocol: HTTP/1.1 (GET method)
Endpoint: /
Timestamp: 2026-08-14T15:25:57Z
Ray ID: a2b0f9a0cbe8f8ef
UA: fasthttp
show less
DDoS Attack
Bad Web Bot
🇺🇸
COMPLEX
2026-07-28 19:44:18
(3 weeks ago)
Banned by Multi Agent · node …jrh1 · reason=SSH banner invalid / banner exchange invalid format · at ...
show more
Banned by Multi Agent · node …jrh1 · reason=SSH banner invalid / banner exchange invalid format · attempts=1 · SSH banner invalid / banner exchange invalid format
show less
Brute-Force
SSH
🇪🇸
el-brujo
2026-07-17 10:43:32
(1 month ago)
07/17/2026-12:32:21.503916 45.198.147.238 Protocol: 6 ET SCAN Potential SSH Scan
Port Scan
🇸🇬
pusathosting.com
2026-07-14 23:20:06
(1 month ago)
24ds22 bruteforce
Brute-Force
Web App Attack
🇮🇩
sockominfo
2026-06-14 19:00:56
(2 months ago)
User login to application during non-business hours. Threat Score: 6.5/10 (HIGH). Confidence: 40%. C ...
show more
User login to application during non-business hours. Threat Score: 6.5/10 (HIGH). Confidence: 40%. CVSS v3.1: 4.6/10 (Medium). CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L. Bayesian Probability: 87%. MITRE ATT&CK: T1046 (Network Service Scanning). Tactic: TA0001. Freshness: Very Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
🇷🇴
Fn4ticHz
2026-05-29 02:44:45
(2 months ago)
DDoS blocked via ZeroGuard.ID
DDoS Attack
Exploited Host
🇮🇹
VHosting
2026-05-27 10:52:12
(2 months ago)
Detected attack and reported by a human
Brute-Force
Web App Attack
SSH
DDoS Attack
Exploited Host
Bad Web Bot
🇫🇷
MatStef132
2026-05-22 14:04:42
(3 months ago)
MatShield L7: blocked on mathost.eu (ua-quarantined)
Bad Web Bot
Anonymous
2026-05-18 05:30:50
(3 months ago)
| [Dangerous/Indonesia] Aggressive IP 45.198.147.238 (~30 hits). Type: DoS Defender- Web server 400 ...
show more
| [Dangerous/Indonesia] Aggressive IP 45.198.147.238 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Web App Attack
Hacking
SQL Injection
🇮🇩
sockominfo
2026-05-12 18:00:39
(3 months ago)
User login to application during non-business hours, Late night login (22:00-05:30) - High risk Jaka ...
show more
User login to application during non-business hours, Late night login (22:00-05:30) - High risk Jakarta timezone (WIB). Threat Score: 8.9/10 (CRITICAL). Confidence: 70%. CVSS v3.1: 9.9/10 (Critical). CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. Bayesian Probability: 93%. MITRE ATT&CK: T1078 (Valid Accounts). Tactic: TA0001. Freshness: Fresh. Source Reputation: KNOWN_MALICIOUS. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
🇮🇩
sockominfo
2026-05-12 17:00:48
(3 months ago)
Reported by TangerangKota-CSIRT. Status: MALICIOUS
Hacking
Web App Attack
🇮🇩
sockominfo
2026-04-26 16:00:50
(3 months ago)
Reported by TangerangKota-CSIRT. Status: MALICIOUS
Hacking
Web App Attack