Anonymous
2026-07-23 03:33:02
(1 month ago)
Suspicious or malicious traffic has been detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 14:41:33
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 130.49.9.18 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.9.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 10:41:27.377573 2026] [security2:error] [pid 31375:tid 31375] [client 130.49.9.18:61685] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||madronabluff.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "madronabluff.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiwal7PgYfpaAM_dMoLJxwAAAAg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-28 10:39:25
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 130.49.9.18 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.9.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 28 06:39:19.852322 2026] [security2:error] [pid 5918:tid 5940] [client 130.49.9.18:58553] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||khalessilaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "khalessilaw.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahgbV-mtsZ7cop7C_3WUgQAAAJQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-24 23:52:50
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 130.49.9.18 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.9.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 24 19:52:43.200697 2026] [security2:error] [pid 15235:tid 15235] [client 130.49.9.18:26859] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||beautyradio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "beautyradio.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahOPS0jqbYWh76q4wzIX8QAAABk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ambor
2026-05-21 21:56:54
(3 months ago)
Honeypot access: WordPress admin access attempt. Path: /wp-login.php
Brute-Force
Web App Attack
Anonymous
2026-05-20 03:48:20
(3 months ago)
[redacted] 130.49.9.18 - - [20/May/2026:05:47:37 +0200] "POST /xmlrpc.php HTTP/1.1" 200 132 "-" "Apa ...
show more
[redacted] 130.49.9.18 - - [20/May/2026:05:47:37 +0200] "POST /xmlrpc.php HTTP/1.1" 200 132 "-" "Apache-HttpClient/4.5.13 (Java/17.0.18)"
[redacted] 130.49.9.18 - - [20/May/2026:05:47:58 +0200] "POST /xmlrpc.php HTTP/1.1" 200 132 "-" "Apache-HttpClient/4.5.13 (Java/17.0.18)"
[redacted] 130.49.9.18 - - [20/May/2026:05:48:01 +0200] "POST /xmlrpc.php HTTP/1.1" 200 206 "-" "Apache-HttpClient/4.5.13 (Java/17.0.18)"
[redacted] 130.49.9.18 - - [20/May/2026:05:48:03 +0200] "POST /xmlrpc.php HTTP/1.1" 200 206 "-" "Apache-HttpClient/4.5.13 (Java/17.0.18)"
[redacted] 130.49.9.18 - - [20/May/2026:05:48:05 +0200] "POST /xmlrpc.php HTTP/1.1" 200 206 "-" "Apache-HttpClient/4.5.13 (Java/17.0.18)"
[redacted] 130.49.9.18 - - [20/May/2026:05:48:07 +0200] "POST /xmlrpc.php HTTP/1.1" 200 206 "-" "Apache-HttpClient/4.5.13 (Java/17.0.18)"
[redacted] 130.49.9.18 - - [20/May/2026:05:48:09 +0200] "POST /xmlrpc.php HTTP/1.1" 200 206 "-" "Apache-HttpCl
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-17 14:28:28
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 130.49.9.18 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.9.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 17 10:28:23.553931 2026] [security2:error] [pid 19486:tid 19486] [client 130.49.9.18:19501] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||primacomm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "primacomm.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agnQh2pulHYZ0zjzeYWT3gAAAAg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 16:37:23
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 130.49.9.18 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.9.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 12:37:18.100154 2026] [security2:error] [pid 25644:tid 25644] [client 130.49.9.18:35447] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||justinrudd.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "justinrudd.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agdLvp1s-7LM5-03jMCDeAAAABA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-11 23:27:46
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 130.49.9.18 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.9.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 19:27:40.804414 2026] [security2:error] [pid 5696:tid 5696] [client 130.49.9.18:32359] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||321q.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "321q.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agJl7F1PfIwaOkhz3ncw_AAAAAM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-04-30 07:39:05
(4 months ago)
IM360 WAF: WordPress plugin/theme auto install block
Web App Attack
๐ซ๐ท
masterguru
2026-04-12 13:20:47
(4 months ago)
(modsec_5015) ModSec 5015: Suspicious User-Agent from 130.49.9.18 (FR/France/-): 1 in the last 3600 ...
show more
(modsec_5015) ModSec 5015: Suspicious User-Agent from 130.49.9.18 (FR/France/-): 1 in the last 3600 secs (0-196)
show less
Hacking
๐ฎ๐น
VHosting
2026-03-26 20:10:58
(5 months ago)
Detected attack and reported by a human
Brute-Force
Web App Attack
SSH
DDoS Attack
Exploited Host
Bad Web Bot
Anonymous
2026-01-26 02:26:48
(7 months ago)
wordpress-trap
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-10 14:34:50
(9 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam