This IP address has been reported a total of
4
times from
3 distinct
sources.
149.13.9.23 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Indonesia
with 2
reports;
France
with 1
report;
United States of America
with 1
report.
The most common categories in these recent reports were:
DDoS Attack
2
times;
Hacking
2
times;
Bad Web Bot
2
times;
Email Spam
2
times;
Exploited Host
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[Sat Oct 03 06:37:54.703904 2026] [security2:error] [pid 818580:tid 140632521696960] [client 149.13. ...
show more[Sat Oct 03 06:37:54.703904 2026] [security2:error] [pid 818580:tid 140632521696960] [client 149.13.9.23:0] ModSecurity: Access denied with code 403 (phase 1). Match of "pm matomo.staklim-malang.info " against "SERVER_NAME" required. [file "/etc/modsecurity/coreruleset-4.29.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "208"] [id "440235"] [msg "BAD REQUEST Bro"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: %3a found within SERVER_NAME: staklim-jatim.bmkg.go.id request_line = GET /index.php/profil/arsip-artikel?catid=483&id=982%3Aprakiraan-cuaca-daerah-malang-dan-batu-seminggu-ke-depan-berlaku-tanggal-3-9-mei-2016&start=10 HTTP/1.1 Request URI RAW = /index.php/profil/arsip-artikel?catid=483&id=982%3Aprakiraan-cuaca-daerah-malang-dan-batu-seminggu-ke-depan-berlaku-tanggal-3-9-mei-2016&start=10 Request Ba..."] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/profil/arsip-artikel"] [unique_id "asBAUgIhm9t9S2
...
show less
HTTP application-layer DoS / botnet traffic from 149.13.9.23: repeated high-cost dynamic page and fe ...
show moreHTTP application-layer DoS / botnet traffic from 149.13.9.23: repeated high-cost dynamic page and feed requests (profile/tag views, forums, tracker, RSS) at abusive rates via completed TCP/HTTPS. Likely compromised end-user host.
show less