🇵🇹
Subnet Shadow Specter
2026-09-09 05:04:36
(7 hours ago)
[CRITICAL][Security Alert: Bot Masquerading] Spoofed Google-InspectionTool User-Agent from unverifie ...
show more
[CRITICAL][Security Alert: Bot Masquerading] Spoofed Google-InspectionTool User-Agent from unverified ASN/IP. [IP Address]: 94.31.70.129 [User-Agent]: Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.6099.224 Mobile Safari/537.36 (compatible; Google-InspectionTool/1.0) [IoA Datetime]: 2026-09-09 06:04:36 UTC +1.
show less
Port Scan
Hacking
Spoofing
Bad Web Bot
Web App Attack
🇺🇸
gui-ying233
2026-09-01 11:03:54
(1 week ago)
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Sa ...
show more
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36
show less
Bad Web Bot
🇺🇸
kosada.com
2026-08-26 23:55:09
(1 week ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
Anonymous
2026-08-21 04:20:24
(2 weeks ago)
Web attack
Bad Web Bot
Web App Attack
🇺🇸
SX Communications
2026-07-21 17:47:41
(1 month ago)
HTTP application-layer DoS / botnet traffic from 94.31.70.129: repeated high-cost dynamic page and f ...
show more
HTTP application-layer DoS / botnet traffic from 94.31.70.129: repeated high-cost dynamic page and feed requests (profile/tag views, forums, tracker, RSS) at abusive rates via completed TCP/HTTPS. Likely compromised end-user host.
show less
DDoS Attack
Bad Web Bot
Exploited Host
🇩🇪
HandyTreff.de
2026-07-18 08:59:02
(1 month ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -47.72 (Bad < -10 / Very Bad < -20 / ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -47.72 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (Linux; Android 8.0.0; SM-J330G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0
show less
Web App Attack
Bad Web Bot
🇺🇸
kosada.com
2026-07-08 10:53:50
(2 months ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
🇮🇩
hermawan
2026-07-02 06:13:32
(2 months ago)
[Thu Jul 02 13:13:29.741897 2026] [security2:error] [pid 131917:tid 140540352005824] [client 94.31.7 ...
show more
[Thu Jul 02 13:13:29.741897 2026] [security2:error] [pid 131917:tid 140540352005824] [client 94.31.70.129:3760] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.bing.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "601"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.bing.go.id found within REQUEST_HEADERS:Referer: https://www.bing.go.id/ request_line = GET /pdfjs/web/viewer.html?file=/images/Klimatologi/Analisis/02-Analisis_Dasarian/Monitoring_dan_Prakiraan_Curah_Hujan-Dasarian/Monitoring_dan_Prakiraan_Curah_Hujan-Dasarian_di_Provinsi_Jawa_Timur/2026/06_Juni_2026/Das-I/Monitoring_dan_Prediksi_Curah_Hujan-Dasarian_di_Provinsi_Jawa_Timur_Update_10_Juni_2026.pdf HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/pdfjs/web/viewer.html"] [unique_id "akYBiZvzx5fSYvvde8A10AAAgQA"], referer https://www.bing.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jat
...
show less
Email Spam
Hacking
🇫🇷
bigorre.org
2026-06-25 15:22:37
(2 months ago)
Unidentified crawling: not a self-announced bot in user-agent
Bad Web Bot
Anonymous
2026-06-13 04:09:04
(2 months ago)
Web attack
Bad Web Bot
Web App Attack
🇮🇩
hermawan
2026-06-08 21:42:13
(3 months ago)
[Tue Jun 09 04:42:12.993956 2026] [security2:error] [pid 1444313:tid 140661152003776] [client 94.31. ...
show more
[Tue Jun 09 04:42:12.993956 2026] [security2:error] [pid 1444313:tid 140661152003776] [client 94.31.70.129:3767] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.google.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "582"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.google.go.id found within REQUEST_HEADERS:Referer: https://www.google.go.id/ request_line = GET /index.php/analisis-iklim/analisis-bulanan/analisis-distribusi-hujan/analisis-distribusi-curah-hujan HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/analisis-iklim/analisis-bulanan/analisis-distribusi-hujan/analisis-distribusi-curah-hujan"] [unique_id "aic3NHaO_f541rGx3P1ynAAAAEs"], referer https://www.google.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[1444351] [Bmge4kT+z48] [aic3NHaO_f541rGx3P1ynAAAAEs] keep_alive=[0] [2026-06-09 04:42:12.993964] [R:a
...
show less
Email Spam
Hacking
🇮🇩
hermawan
2026-06-02 13:47:00
(3 months ago)
[Tue Jun 02 20:46:57.183169 2026] [security2:error] [pid 86695:tid 140424649897664] [client 94.31.70 ...
show more
[Tue Jun 02 20:46:57.183169 2026] [security2:error] [pid 86695:tid 140424649897664] [client 94.31.70.129:3815] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.baidu.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "582"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.baidu.go.id found within REQUEST_HEADERS:Referer: http://www.baidu.go.id/ request_line = GET /plant-t.webp HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/plant-t.webp"] [unique_id "ah7e0fiI5nb54ItJCSAaSAAASwA"], referer http://www.baidu.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[86702] [alZliwUwIi8] [ah7e0fiI5nb54ItJCSAaSAAASwA] keep_alive=[1] [2026-06-02 20:46:57.183175] [R:ah7e0fiI5nb54ItJCSAaSAAASwA] UA:'Mozilla/5.0 (Android 13; Mobile; rv:127.0) Gecko/127.0 Firefox/127.0' Host:'staklim-jatim.bmkg.go.id:443' ACCEPT:'text/html,application/xhtml+xml,applic
...
show less
Email Spam
Hacking
🇮🇩
hermawan
2026-05-20 06:53:52
(3 months ago)
[Wed May 20 13:53:49.151115 2026] [security2:error] [pid 597671:tid 140082978195136] [client 94.31.7 ...
show more
[Wed May 20 13:53:49.151115 2026] [security2:error] [pid 597671:tid 140082978195136] [client 94.31.70.129:3823] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.yandex.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "624"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.yandex.go.id found within REQUEST_HEADERS:Referer: https://www.yandex.go.id/ request_line = GET /index.php HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php"] [unique_id "ag1afWnV7h6D6Qa4SsrU5AAASQU"], referer https://www.yandex.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[597677] [Ktr5Qfo27L8] [ag1afWnV7h6D6Qa4SsrU5AAASQU] keep_alive=[1] [2026-05-20 13:53:49.151121] [R:ag1afWnV7h6D6Qa4SsrU5AAASQU] UA:'Mozilla/5.0 (Linux; Android 13; SM-S901B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Mobile Safari/537.36' Host:'staklim-jatim.bmkg.go.id
...
show less
Email Spam
Hacking
🇺🇸
matt
2026-03-03 22:45:09
(6 months ago)
DDOS attack with query parameters attempting to overload WordPress site.
DDoS Attack
🇺🇸
matt
2026-03-02 21:59:47
(6 months ago)
DDOS attack with query parameters attempting to overload WordPress site.
DDoS Attack