๐ซ๐ท
MatStef132
2026-06-21 21:27:26
(4 days ago)
MatShield L7: blocked on mathost.eu (ua-quarantined)
Bad Web Bot
๐ฎ๐ฉ
hermawan
2026-06-08 16:00:44
(2 weeks ago)
[Mon Jun 08 23:00:44.146699 2026] [security2:error] [pid 1211650:tid 140661785401024] [client 103.16 ...
show more
[Mon Jun 08 23:00:44.146699 2026] [security2:error] [pid 1211650:tid 140661785401024] [client 103.166.8.10:50460] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.yahoo.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "582"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.yahoo.go.id found within REQUEST_HEADERS:Referer: https://www.yahoo.go.id/ request_line = GET /index-v100.js HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index-v100.js"] [unique_id "aibnLBMtjkx4uN0Afmp--gAClRg"], referer https://www.yahoo.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[1211675] [EcjlHEAXHoY] [aibnLBMtjkx4uN0Afmp--gAClRg] keep_alive=[1] [2026-06-08 23:00:44.146704] [R:aibnLBMtjkx4uN0Afmp--gAClRg] UA:'Mozilla/5.0 (Linux; Android 14; Pixel 6 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.6261.119 Mobile Safari/537.36 OPR/81.2.4292.78
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
sockominfo
2026-05-24 22:00:39
(1 month ago)
Late night login (22:00-05:30) - High risk Jakarta timezone (WIB). Threat Score: 8.9/10 (CRITICAL). ...
show more
Late night login (22:00-05:30) - High risk Jakarta timezone (WIB). Threat Score: 8.9/10 (CRITICAL). Confidence: 70%. CVSS v3.1: 9.9/10 (Critical). CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. Bayesian Probability: 87%. MITRE ATT&CK: T1078 (Valid Accounts). Tactic: TA0001. Freshness: Fresh. Source Reputation: KNOWN_MALICIOUS. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-05-24 21:00:11
(1 month ago)
Late night login (22:00-05:30) - High risk Jakarta timezone (WIB). Threat Score: 8.6/10 (HIGH). Repo ...
show more
Late night login (22:00-05:30) - High risk Jakarta timezone (WIB). Threat Score: 8.6/10 (HIGH). Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐จ๐ญ
backslash
2026-05-16 10:21:01
(1 month ago)
block ruleset Badbot using very old user-agents 5CF3CDB778C7D82564405B86B9242E612F378C68
Bad Web Bot
๐ฌ๐ง
PeravixGroup
2026-05-09 23:39:20
(1 month ago)
Honeypot detection: Telnet / IoT device brute-force or exploitation attempt on port 23. Severity: ME ...
show more
Honeypot detection: Telnet / IoT device brute-force or exploitation attempt on port 23. Severity: MEDIUM. Aaran.cloud
show less
IoT Targeted
Brute-Force
๐ฎ๐ฉ
sockominfo
2026-05-06 23:00:46
(1 month ago)
Late night login (22:00-05:30) - High risk Jakarta timezone (WIB). Threat Score: 8.8/10 (CRITICAL). ...
show more
Late night login (22:00-05:30) - High risk Jakarta timezone (WIB). Threat Score: 8.8/10 (CRITICAL). Confidence: 70%. CVSS v3.1: 9.9/10 (Critical). CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. Bayesian Probability: 87%. MITRE ATT&CK: T1078 (Valid Accounts). Tactic: TA0001. Freshness: Fresh. Source Reputation: KNOWN_MALICIOUS. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-05-06 22:00:39
(1 month ago)
Late night login (22:00-05:30) - High risk Jakarta timezone (WIB). Threat Score: 8.9/10 (CRITICAL). ...
show more
Late night login (22:00-05:30) - High risk Jakarta timezone (WIB). Threat Score: 8.9/10 (CRITICAL). Confidence: 70%. CVSS v3.1: 9.9/10 (Critical). CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. Bayesian Probability: 87%. MITRE ATT&CK: T1078 (Valid Accounts). Tactic: TA0001. Freshness: Very Fresh. Source Reputation: KNOWN_MALICIOUS. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฆ๐น
urnilxfgbez
2026-05-01 22:45:00
(1 month ago)
Last 24 Hours suspicious: (DPT=445|DPT=3389|DPT=22|DPT=3306|DPT=8080|DPT=23|DPT=5900|DPT=1433)
Port Scan
๐ซ๐ท
security.rdmc.fr
2026-05-01 20:12:55
(1 month ago)
Port Scan Attack proto:TCP src:60946 dst:23
Port Scan
๐บ๐ธ
RAP
2026-05-01 20:00:12
(1 month ago)
2026-05-01 20:00:12 UTC Unauthorized activity to TCP port 23. Telnet
Port Scan
๐ฎ๐ฉ
sockominfo
2026-04-26 22:00:47
(1 month ago)
User login to application during non-business hours. Threat Score: 6.5/10 (HIGH). Confidence: 40%. C ...
show more
User login to application during non-business hours. Threat Score: 6.5/10 (HIGH). Confidence: 40%. CVSS v3.1: 4.6/10 (Medium). CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L. Bayesian Probability: 87%. MITRE ATT&CK: T1046 (Network Service Scanning). Tactic: TA0001. Freshness: Very Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐จ๐ญ
backslash
2026-03-14 07:16:56
(3 months ago)
Bad Web Bot
๐ง๐ท
marlorodrigues
2026-01-27 03:19:54
(4 months ago)
Brute Force SSH or Port Scan
Port Scan
๐จ๐ญ
cybsecaoccol
2026-01-18 02:28:15
(5 months ago)
unauthorized connection or malicious port scan attempted on tcp port 23 - sch
Port Scan
Hacking