๐ฉ๐ช
4server
2026-09-02 04:24:45
(13 hours ago)
[WedSep0206:24:39.5893012026][security2:error][pid926439:tid926504][client130.49.11.13:0]ModSecurity ...
show more
[WedSep0206:24:39.5893012026][security2:error][pid926439:tid926504][client130.49.11.13:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(curl\|wget\|python\|nikto\|sqlmap\|acunetix\|fimap\|dirbuster\|cmsmap\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"217\"][id\"990210\"][msg\"Suspicioususer-agentblocked\"][hostname\"mgevents.ch\"][uri\"/\"][unique_id\"apelBzX4tUTNDx71YszakAAAAIQ\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ณ๐ฑ
DSCloud9
2026-09-01 00:59:29
(1 day ago)
Rce attack targeting dscloud9.nl - Severity: high
Hacking
Web App Attack
๐บ๐ธ
johnkarlhill
2026-08-31 21:30:06
(1 day ago)
WebKnight blocked malicious web request on johnkarlhill.com
Brute-Force
SSH
๐ธ๐ช
vaia.cloud
2026-08-31 12:25:02
(2 days ago)
crowdsecurity/http-cve-probing
Brute-Force
Web App Attack
๐จ๐ฆ
DRI
2026-07-28 23:34:38
(1 month ago)
Web attack/Malicious activity detected
Web App Attack
๐จ๐ฆ
DRI
2026-07-27 08:54:45
(1 month ago)
Web attack/Malicious activity detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 08:15:03
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 130.49.11.13 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.11.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 04:14:56.313068 2026] [security2:error] [pid 5761:tid 5761] [client 130.49.11.13:37403] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||moellerlaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "moellerlaw.com"] [uri "/wp-json/wp/v2/users"] [unique_id "al8qgOTiYefcdxFc_Zeu6AAAACg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
DRI
2026-07-19 09:41:27
(1 month ago)
Web attack/Malicious activity detected
Web App Attack
๐จ๐ฆ
DRI
2026-07-17 14:22:11
(1 month ago)
Web attack/Malicious activity detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-11 17:28:57
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 130.49.11.13 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.11.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 11 13:28:52.931336 2026] [security2:error] [pid 875:tid 875] [client 130.49.11.13:14403] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||toody.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "toody.com"] [uri "/wp-json/wp/v2/users"] [unique_id "alJ9VDBNIlS870GkM5pHKgAAAAU"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 12:02:43
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 130.49.11.13 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.11.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 08:02:36.607714 2026] [security2:error] [pid 303644:tid 303644] [client 130.49.11.13:54463] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bgellis.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bgellis.com"] [uri "/wp-json/wp/v2/users"] [unique_id "adOg3O5fO2h_GObtWtFfWwAAAB4"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-22 20:38:50
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 130.49.11.13 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.11.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 15:38:38.172663 2026] [security2:error] [pid 1384:tid 1384] [client 130.49.11.13:48697] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ixd.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ixd.net"] [uri "/wp-json/wp/v2/users/2"] [unique_id "aXKKzgerM6suWhCpCanBpAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack