๐ซ๐ท
tilellit.pro
2026-06-28 08:21:59
(1 day ago)
Fail2Ban banned 130.49.11.125 for security violations in jail wp-armour. Log: 2026/06/28 08:21:58 [e ...
show more
Fail2Ban banned 130.49.11.125 for security violations in jail wp-armour. Log: 2026/06/28 08:21:58 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 130.49.11.125 | Target: wplogin" , client: 130.49.11.125, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐ฉ๐ช
ghostwarriors
2026-06-19 22:20:14
(1 week ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-06-10 18:23:17
(2 weeks ago)
567 limiting connections by zone (14m59s)
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 14:41:05
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 130.49.11.125 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.11.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 10:40:57.671815 2026] [security2:error] [pid 28470:tid 28470] [client 130.49.11.125:39821] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||barnesandbrower.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "barnesandbrower.com"] [uri "/wp-json/wp/v2/users"] [unique_id "adJ0eTQU7UjEXUhwE9LBRwAAAAg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-28 19:21:29
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 130.49.11.125 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.11.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 28 15:21:22.321096 2026] [security2:error] [pid 25379:tid 25379] [client 130.49.11.125:32979] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||khovanov.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "khovanov.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acgqMkZx8-UCeSzWvZ5qbAAAABM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-22 18:06:50
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 130.49.11.125 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.11.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 13:06:44.664341 2026] [security2:error] [pid 18969:tid 18969] [client 130.49.11.125:50763] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||phalanxemail.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "phalanxemail.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aXJnNO6o7DCq-_GvbxQNfwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-22 14:15:49
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 130.49.11.125 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.11.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 09:15:42.115431 2026] [security2:error] [pid 4569:tid 4569] [client 130.49.11.125:50215] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wealthsec.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wealthsec.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "aXIxDmo1iucsXVk36q6PgAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐น
Malta
2026-01-21 19:05:28
(5 months ago)
130.49.11.125 - - [21/Jan/2026:20:05:28 +0100] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows N ...
show more
130.49.11.125 - - [21/Jan/2026:20:05:28 +0100] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
Brute-force password attempt
show less
Hacking
Brute-Force
Web App Attack
๐จ๐ญ
backslash
2025-10-30 20:25:04
(7 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-10-29 22:48:07
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 130.49.11.125 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.11.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 29 18:48:00.561184 2025] [security2:error] [pid 12096:tid 12145] [client 130.49.11.125:30371] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sallykimmel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sallykimmel.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aQKZoHmuzHtgpJ-pGeQuBQAAAdA"]
show less
Brute-Force
Bad Web Bot
Web App Attack