๐ซ๐ท
tilellit.pro
2026-06-28 08:15:20
(12 hours ago)
Fail2Ban banned 130.49.112.192 for security violations in jail wp-armour. Log: 2026/06/28 08:15:20 [ ...
show more
Fail2Ban banned 130.49.112.192 for security violations in jail wp-armour. Log: 2026/06/28 08:15:20 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 130.49.112.192 | Target: wplogin" , client: 130.49.112.192, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐ซ๐ท
tilellit.pro
2026-06-27 20:05:07
(1 day ago)
Fail2Ban banned 130.49.112.192 for security violations in jail wp-armour. Log: 2026/06/27 20:05:07 [ ...
show more
Fail2Ban banned 130.49.112.192 for security violations in jail wp-armour. Log: 2026/06/27 20:05:07 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 130.49.112.192 | Target: wplogin" , client: 130.49.112.192, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐ซ๐ท
tilellit.pro
2026-06-27 06:29:20
(1 day ago)
Fail2Ban banned 130.49.112.192 for security violations in jail wp-armour. Log: 2026/06/27 06:29:20 [ ...
show more
Fail2Ban banned 130.49.112.192 for security violations in jail wp-armour. Log: 2026/06/27 06:29:20 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 130.49.112.192 | Target: wplogin" , client: 130.49.112.192, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐บ๐ธ
TPI-Abuse
2026-06-21 09:33:37
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 130.49.112.192 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.112.192 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 05:33:32.195193 2026] [security2:error] [pid 14204:tid 14204] [client 130.49.112.192:14305] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tlo-afghanistan.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tlo-afghanistan.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ajev7L_bL88OPi7-c5L6OgAAABc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-05-30 16:52:54
(4 weeks ago)
Web password guessing
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-01-22 17:50:46
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 130.49.112.192 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.112.192 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 12:50:39.024515 2026] [security2:error] [pid 6436:tid 6436] [client 130.49.112.192:33033] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kentsavagelaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kentsavagelaw.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aXJjb8NuDRMT791q0iEXmAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-01-21 11:43:02
(5 months ago)
๐ Probes for xmlrpc.php everywhere
Hacking
Web App Attack
๐ฉ๐ช
stinpriza
2026-01-21 11:33:25
(5 months ago)
Web App Attack
Web App Attack
Anonymous
2026-01-21 11:06:07
(5 months ago)
Trying to access config files
Web App Attack
๐บ๐ธ
mind5t0rm
2026-01-21 09:39:19
(5 months ago)
(WPLOGIN,XMLRPC) Login failure/trigger from 130.49.112.192 (TR/Tรยผrkiye/-): 3 in the last 3600 secs; ...
show more
(WPLOGIN,XMLRPC) Login failure/trigger from 130.49.112.192 (TR/Tรยผrkiye/-): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: 130.49.112.192 - - [21/Jan/2026:16:30:31 +0700] "GET /xmlrpc.php HTTP/1.1" 403 165 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36"
130.49.112.192 - - [21/Jan/2026:16:30:34 +0700] "GET /wp-login.php HTTP/1.1" 200 2465 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36"
130.49.112.192 - - [21/Jan/2026:16:39:14 +0700] "GET /xmlrpc.php HTTP/1.1" 403 165 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36"
show less
Port Scan
๐ง๐ช
cmbplf
2026-01-21 09:31:06
(5 months ago)
1.558 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐บ๐ธ
nationaleventpros.com
2026-01-21 08:44:08
(5 months ago)
WordPress login attempt
Brute-Force
๐ฎ๐น
VHosting
2026-01-21 08:30:13
(5 months ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
Mundo Bueno
2026-01-21 08:08:45
(5 months ago)
Accรจs suspect sur /xmlrpc.php via ISILIA Development protection.
Hacking
Web App Attack
๐ต๐ฑ
IROK
2026-01-21 07:50:39
(5 months ago)
Malware/WebShell Scan blocked by ModSecurity
...
Hacking