🇨🇭
backslash
2026-09-03 05:12:00
(8 hours ago)
block ruleset AA06B7315BA6AEB6421B52F0B32E14B509FD5FF0
SQL Injection
🇺🇦
URAN Publishing Service
2026-09-01 19:05:46
(1 day ago)
[01/Sep/2026:22:05:46 +0300] -- 130.49.11.164 Ban reason: User-Agent curl/
Bad Web Bot
Web App Attack
🇺🇦
URAN Publishing Service
2026-08-31 17:22:10
(2 days ago)
[31/Aug/2026:20:22:09 +0300] -- 130.49.11.164 Ban reason: User-Agent curl/
Bad Web Bot
Web App Attack
🇦🇺
electronico
2026-08-12 01:15:38
(3 weeks ago)
130.49.11.164 - - [12/Aug/2026:12:15:37 +1100] "POST /xmlrpc.php HTTP/2.0" 200 307 "-" "Mozilla/5.0 ...
show more
130.49.11.164 - - [12/Aug/2026:12:15:37 +1100] "POST /xmlrpc.php HTTP/2.0" 200 307 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
🇹🇷
eryilmaz
2026-07-30 02:00:08
(1 month ago)
Automated attack blocked by eryilmaz WAF/fail2ban: 4 event(s) [waf.autoban,waf.block] in the last 1 ...
show more
Automated attack blocked by eryilmaz WAF/fail2ban: 4 event(s) [waf.autoban,waf.block] in the last 1 days, e.g. /xmlrpc.php
show less
Web App Attack
Hacking
🇹🇷
eryilmaz
2026-07-29 16:50:08
(1 month ago)
Automated attack blocked by eryilmaz WAF/defense engine (level 1, source: auto, path: /wp-login.php)
Web App Attack
Hacking
🇨🇦
DRI
2026-07-26 09:37:24
(1 month ago)
Web attack/Malicious activity detected
Web App Attack
🇨🇭
backslash
2026-07-13 10:18:00
(1 month ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
🇺🇸
TPI-Abuse
2026-05-02 18:43:19
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 130.49.11.164 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.11.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 02 14:43:13.735822 2026] [security2:error] [pid 16002:tid 16002] [client 130.49.11.164:34283] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||paintriver.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "paintriver.com"] [uri "/wp-json/wp/v2/users"] [unique_id "afZFwQY8Fe5IWpf1NxuT0AAAAAc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-24 07:02:33
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 130.49.11.164 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.11.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 24 03:02:26.268598 2026] [security2:error] [pid 315101:tid 315101] [client 130.49.11.164:63099] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rockymtnfire.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rockymtnfire.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aesVggHy8pn2-9REpRF2qQAAAAM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-16 09:28:41
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 130.49.11.164 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.11.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 16 05:28:34.856431 2026] [security2:error] [pid 2848956:tid 2848956] [client 130.49.11.164:20113] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||starfi.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "starfi.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aeCrwi6_mkCfCjtLD43gUAAAAAM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-01-22 18:48:07
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 130.49.11.164 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.11.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 13:48:03.421501 2026] [security2:error] [pid 2467913:tid 2467913] [client 130.49.11.164:15275] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||blacktieokc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "blacktieokc.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "aXJw47ngPEyHVjzzgxqpggAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-01-22 13:53:59
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 130.49.11.164 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.11.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 08:53:52.841030 2026] [security2:error] [pid 18522:tid 18522] [client 130.49.11.164:53005] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||boaredraven.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "boaredraven.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aXIr8EU3-mBWg78bnMDsBwAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-01-22 12:45:29
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 130.49.11.164 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.11.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 07:45:24.142933 2026] [security2:error] [pid 7320:tid 7320] [client 130.49.11.164:33243] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mirai-labo.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mirai-labo.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aXIb5Mmakxfs7lmJw7o8LwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack