๐บ๐ธ
TPI-Abuse
2026-07-28 17:37:43
(19 hours ago)
(mod_security) mod_security (id:225170) triggered by 130.49.113.35 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.113.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 13:37:38.879644 2026] [security2:error] [pid 1488951:tid 1488951] [client 130.49.113.35:15347] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||toptek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "toptek.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amjo4pCt8mYJWTyqp7eTwQAAAAU"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-18 23:34:50
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 130.49.113.35 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.113.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 19:34:45.469321 2026] [security2:error] [pid 23039:tid 23054] [client 130.49.113.35:19113] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jab-us.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jab-us.com"] [uri "/wp-json/wp/v2/users"] [unique_id "alwNlYDYRljKKJl6WPKA7gAAAM0"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-14 16:00:53
(2 weeks ago)
Multiple WAF Violations
Web App Attack
๐จ๐ญ
backslash
2026-07-13 20:51:00
(2 weeks ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐ฉ๐ช
FeG Deutschland
2026-07-10 22:07:26
(2 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
๐ฌ๐ง
consul.to
2026-07-04 02:51:15
(3 weeks ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
LRob
2026-07-03 00:09:05
(3 weeks ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐ซ๐ท
Tilellit.PRO
2026-06-28 06:54:32
(1 month ago)
Fail2Ban banned 130.49.113.35 for security violations in jail wp-armour. Log: 2026/06/28 06:54:32 [e ...
show more
Fail2Ban banned 130.49.113.35 for security violations in jail wp-armour. Log: 2026/06/28 06:54:32 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 130.49.113.35 | Target: wplogin" , client: 130.49.113.35, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐จ๐ฟ
ptlab
2026-06-25 12:47:08
(1 month ago)
Detected wp_login attack from WP-host.
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-22 10:28:06
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 130.49.113.35 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.113.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 06:28:00.871008 2026] [security2:error] [pid 13215:tid 13215] [client 130.49.113.35:36855] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||butterfly-storm.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "butterfly-storm.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ajkOMLvWGEspdQPoEzMU9wAAAAU"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-20 08:24:53
(1 month ago)
(caddyscan) Scanner path probe from 130.49.113.35 (DE/Germany/-): 5 in the last 3600 secs; Ports: *; ...
show more
(caddyscan) Scanner path probe from 130.49.113.35 (DE/Germany/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 130.49.113.35 - - [20/Jun/2026:08:24:42 +0000] "POST /xmlrpc.php HTTP/1.1"
[REDACTED] 200 2627 130.49.113.35 - - [20/Jun/2026:08:24:43 +0000] "GET /wp-login.php HTTP/1.1"
[REDACTED] 200 2627 130.49.113.35 - - [20/Jun/2026:08:24:43 +0000] "GET /wp-login.php HTTP/1.1"
[REDACTED] 200 2627 130.49.113.35 - - [20/Jun/2026:08:24:46 +0000] "POST /xmlrpc.php HTTP/1.1"
[REDACTED] 200 2627 130.49.113.35 - - [20/Jun/2026:08:24:48 +0000] "GET /wp-login.php HTTP/1.1"
show less
Port Scan
๐ฉ๐ช
LRob
2026-06-08 07:15:06
(1 month ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐ซ๐ฎ
inlink.ltd
2026-05-18 07:06:33
(2 months ago)
Known malicious PHP file or CMS probe
Web App Attack
๐บ๐ธ
nationaleventpros.com
2026-05-14 19:34:21
(2 months ago)
WordPress login attempt
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-14 13:45:23
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 130.49.113.35 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.113.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 09:45:18.499190 2026] [security2:error] [pid 27187:tid 27187] [client 130.49.113.35:22473] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||abogadoparticular.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "abogadoparticular.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agXR7tf_4yaV_wBnCUb9kwAAAAw"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack