๐บ๐ธ
bigscoots.com
2026-01-12 20:17:46
(7 months ago)
66.96.225.106 (ID/Indonesia/host-66-96-225-106.myrepublic.co.id), 5 distributed sshd attacks on acco ...
show more
66.96.225.106 (ID/Indonesia/host-66-96-225-106.myrepublic.co.id), 5 distributed sshd attacks on account [admin] in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_DISTATTACK; Logs: Jan 12 14:17:37 13966 sshd[27223]: Invalid user admin from 103.47.133.111 port 36198
Jan 12 14:15:29 13966 sshd[26968]: Invalid user admin from 66.96.225.106 port 35938
Jan 12 14:15:32 13966 sshd[26968]: Failed password for invalid user admin from 66.96.225.106 port 35938 ssh2
Jan 12 14:13:59 13966 sshd[26773]: Invalid user admin from 103.47.133.114 port 40198
Jan 12 14:14:01 13966 sshd[26773]: Failed password for invalid user admin from 103.47.133.114 port 40198 ssh2
IP Addresses Blocked:
103.47.133.111 (ID/Indonesia/host-103-47-133-111.myrepublic.co.id)
show less
Brute-Force
SSH
๐บ๐ธ
ipblock.com
2025-10-27 06:55:00
(10 months ago)
IPBlock protected site ID [4055-d][s=07].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
ipblock.com
2025-10-27 04:35:00
(10 months ago)
IPBlock protected site ID [4055-d][s=07].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
hermawan
2025-02-13 13:26:27
(1 year ago)
[Thu Feb 13 20:26:27.357849 2025] [security2:error] [pid 212785:tid 140429251684032] [client 66.96.2 ...
show more
[Thu Feb 13 20:26:27.357849 2025] [security2:error] [pid 212785:tid 140429251684032] [client 66.96.225.106:35454] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "ms" at REQUEST_HEADERS:Accept-Language. [file "/etc/modsecurity/coreruleset-4.10.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "167"] [id "440001"] [msg "Seperti Ddos bahasa Rusia ada di ip vietnam 2.59.0.188 "] [data "Matched Data: ms found within REQUEST_HEADERS:Accept-Language: en-US,en;q=0.9,id;q=0.8,ar;q=0.7,ms;q=0.6 request_line = GET /index.php/prakiraan-iklim/prakiraan-musim/prakiraan-musim-hujan/prakiraan-durasi-musim-hujan HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/prakiraan-iklim/prakiraan-musim/prakiraan-musim-hujan/prakiraan-durasi-musim-hujan"] [unique_id "Z63zA9OMUXXaMSeOgjixnAAAJjE"], referer https://www.google.com/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[212835] [XMtFAQ4rSf8] [Z63zA9OMUXXaMSeOgjixnAAAJjE] keep_alive=[1] [
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
Ridwan Na'im
2024-12-19 01:55:10
(1 year ago)
Multiple web server 400 error codes from same source ip. - Vulnerability Scanning
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2024-09-18 12:27:26
(1 year ago)
[Wed Sep 18 04:00:28.583060 2024] [security2:error] [pid 290266:tid 138906724992704] [client 66.96.2 ...
show more
[Wed Sep 18 04:00:28.583060 2024] [security2:error] [pid 290266:tid 138906724992704] [client 66.96.225.106:57002] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "300" at REQUEST_HEADERS:Keep-Alive. [file "/etc/modsecurity/coreruleset-4.5.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "120"] [id "440004"] [msg "Keep Alive Header"] [data "Matched Data: 300 found within REQUEST_HEADERS:Keep-Alive: 300 request_line = GET / HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/"] [unique_id "Zunt7BdQnKFnna7Q03HIIwAAAJI"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[290311] [YTSv+haO2bA] [Zunt7BdQnKFnna7Q03HIIwAAAJI] keep_alive=[0] [2024-09-18 04:00:28.583063] [R:Zunt7BdQnKFnna7Q03HIIwAAAJI] UA:'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36' Host:'staklim-jatim.bmkg.go.id' ACCEPT:'text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8' Accept-Language:
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
penjaga BRIN
2024-09-17 21:13:43
(1 year ago)
Multiple BOT Scanning Attack Detected from same source ip.-111
Brute-Force
Anonymous
2024-06-18 13:57:35
(2 years ago)
XSS Attempt
Hacking
๐ฎ๐ฉ
penjaga BRIN
2024-06-09 23:32:30
(2 years ago)
nginx-dos-240
Bad Web Bot
๐ฎ๐ฉ
hermawan
2024-06-01 09:56:34
(2 years ago)
[Sat Jun 01 16:56:30.619002 2024] [security2:error] [pid 1158951:tid 129237359003200] [client 66.96. ...
show more
[Sat Jun 01 16:56:30.619002 2024] [security2:error] [pid 1158951:tid 129237359003200] [client 66.96.225.106:41828] [client 66.96.225.106] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i),.*?[\\"'\\\\)0-9`-f][\\"'`](?:[\\"'`].*?[\\"'`]|(?:\\\\r?\\\\n)?\\\\z|[^\\"'`]+)|[^0-9A-Z_a-z]select.+[^0-9A-Z_a-z]*?from|(?:alter|(?:(?:cre|trunc|upd)at|renam)e|d(?:e(?:lete|sc)|rop)|(?:inser|selec)t|load)[\\\\s\\\\v]*?\\\\([\\\\s\\\\v]*?space[\\\\s\\\\v]*?\\\\(" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "2109"] [id "942200"] [msg "Detects MySQL comment-/space-obfuscated injections and backtick termination"] [data "Matched Data: , like Gecko) Version/4.0 Chrome/125.0.6422.54 Mobile Safari/537.36 OcIdWebView ({\\x22os\\x22:\\x22Android\\x22, found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (Linux; Android 12; CPH2477 Build/SP1A.210812.016; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
amanat institute
2024-01-11 12:05:58
(2 years ago)
trying to ddos our web app
DDoS Attack
Brute-Force
๐ฎ๐ฉ
Burayot
2023-11-09 06:47:01
(2 years ago)
LF_POP3D: (pop3d) Failed POP3 login from 66.96.225.106 (ID/Indonesia/host-66-96-225-106.myrepublic.c ...
show more
LF_POP3D: (pop3d) Failed POP3 login from 66.96.225.106 (ID/Indonesia/host-66-96-225-106.myrepublic.co.id): 2 in the last 3600 secs
show less
Brute-Force
๐ฎ๐ฉ
Incidents Response Neptus Team
2023-09-22 06:39:06
(2 years ago)
Report Abuse IP
DDoS Attack
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
bigscoots.com
2023-08-09 05:47:31
(3 years ago)
66.96.225.106 (ID/Indonesia/host-66-96-225-106.myrepublic.co.id), 5 distributed sshd attacks on acco ...
show more
66.96.225.106 (ID/Indonesia/host-66-96-225-106.myrepublic.co.id), 5 distributed sshd attacks on account [root] in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_DISTATTACK; Logs: Aug 9 00:45:42 14835 sshd[10284]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=65.2.10.245 user=root
Aug 9 00:45:43 14835 sshd[10284]: Failed password for root from 65.2.10.245 port 43494 ssh2
Aug 9 00:47:09 14835 sshd[10398]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=66.96.225.106 user=root
Aug 9 00:44:09 14835 sshd[10188]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=80.90.184.133 user=root
Aug 9 00:44:11 14835 sshd[10188]: Failed password for root from 80.90.184.133 port 43900 ssh2
IP Addresses Blocked:
65.2.10.245 (IN/India/ec2-65-2-10-245.ap-south-1.compute.amazonaws.com)
show less
Brute-Force
SSH
๐บ๐ธ
bigscoots.com
2023-08-09 04:49:23
(3 years ago)
66.96.225.106 (ID/Indonesia/host-66-96-225-106.myrepublic.co.id), 5 distributed sshd attacks on acco ...
show more
66.96.225.106 (ID/Indonesia/host-66-96-225-106.myrepublic.co.id), 5 distributed sshd attacks on account [root] in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_DISTATTACK; Logs: Aug 8 23:48:13 15146 sshd[5014]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=66.96.225.106 user=root
Aug 8 23:48:15 15146 sshd[5014]: Failed password for root from 66.96.225.106 port 15752 ssh2
Aug 8 23:49:01 15146 sshd[5021]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=103.75.197.123 user=root
Aug 8 23:41:22 15146 sshd[4479]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=47.236.29.188 user=root
Aug 8 23:41:24 15146 sshd[4479]: Failed password for root from 47.236.29.188 port 53762 ssh2
IP Addresses Blocked:
show less
Brute-Force
SSH