๐ซ๐ท
tilellit.pro
2026-06-28 08:13:58
(1 day ago)
Fail2Ban banned 130.49.115.229 for security violations in jail wp-armour. Log: 2026/06/28 08:13:58 [ ...
show more
Fail2Ban banned 130.49.115.229 for security violations in jail wp-armour. Log: 2026/06/28 08:13:58 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 130.49.115.229 | Target: wplogin" , client: 130.49.115.229, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐ซ๐ท
tilellit.pro
2026-06-27 09:09:10
(2 days ago)
Fail2Ban banned 130.49.115.229 for security violations in jail wp-armour. Log: 2026/06/27 09:09:10 [ ...
show more
Fail2Ban banned 130.49.115.229 for security violations in jail wp-armour. Log: 2026/06/27 09:09:10 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 130.49.115.229 | Target: wplogin" , client: 130.49.115.229, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐บ๐ธ
ambor
2026-06-25 19:56:50
(3 days ago)
Honeypot triggered on tcpdata.com - Attempted to access /xmlrpc.php (wordpress_xmlrpc). User-Agent: ...
show more
Honeypot triggered on tcpdata.com - Attempted to access /xmlrpc.php (wordpress_xmlrpc). User-Agent: Wget/1.21.4
show less
Web App Attack
๐ซ๐ท
tilellit.pro
2026-06-25 17:35:22
(3 days ago)
Fail2Ban banned 130.49.115.229 for security violations in jail wp-armour. Log: 2026/06/25 17:35:22 [ ...
show more
Fail2Ban banned 130.49.115.229 for security violations in jail wp-armour. Log: 2026/06/25 17:35:22 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 130.49.115.229 | Target: wplogin" , client: 130.49.115.229, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐บ๐ธ
TPI-Abuse
2026-06-23 13:14:01
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 130.49.115.229 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.115.229 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 09:13:55.831373 2026] [security2:error] [pid 10404:tid 10442] [client 130.49.115.229:10319] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||transiit.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "transiit.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ajqGk214nc-yn7kLf2bEbAAAANU"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
CryptoYakari
2026-06-22 17:41:26
(6 days ago)
[Mon Jun 22 20:41:18.941888 2026] [proxy_fcgi:error] [pid 1396221:tid 1396230] [client 130.49.115.22 ...
show more
[Mon Jun 22 20:41:18.941888 2026] [proxy_fcgi:error] [pid 1396221:tid 1396230] [client 130.49.115.229:0] AH01071: Got error 'Primary script unknown'
[Mon Jun 22 20:41:19.794002 2026] [proxy_fcgi:error] [pid 1396222:tid 1396248] [client 130.49.115.229:0] AH01071: Got error 'Primary script unknown', referer: https://www.google.com
[Mon Jun 22 20:41:20.906127 2026] [proxy_fcgi:error] [pid 1396222:tid 1396272] [client 130.49.115.229:0] AH01071: Got error 'Primary script unknown', referer: https://www.google.com
...
show less
Web Spam
Blog Spam
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-05 07:33:20
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 130.49.115.229 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.115.229 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 05 03:33:14.237139 2026] [security2:error] [pid 1090:tid 1090] [client 130.49.115.229:50003] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||alan-ip.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "alan-ip.com"] [uri "/wp-json/wp/v2/users"] [unique_id "afmdOuWa0Bp0e_Y8GYIIwAAAABE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-04-29 21:24:22
(1 month ago)
Web password guessing
Brute-Force
Anonymous
2026-04-27 22:22:00
(2 months ago)
FPROCO WEBEXPLOIT 130.49.115.229 (130.49.115.229)
Web App Attack
๐บ๐ธ
nationaleventpros.com
2026-04-18 03:04:08
(2 months ago)
WordPress login attempt
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-04-17 22:40:37
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 130.49.115.229 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.115.229 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 17 18:40:29.530657 2026] [security2:error] [pid 138354:tid 138413] [client 130.49.115.229:47343] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||thetooheys.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "thetooheys.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aeK23Y82jMbmwqX-uM1MhAAAAIw"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-01-29 06:25:02
(5 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐บ๐ธ
rsiddall
2026-01-24 02:12:54
(5 months ago)
130.49.115.229 - - [23/Jan/2026:21:12:38 -0500] "POST /xmlrpc.php HTTP/1.1" 403 1809 "-" "Wget/1.21. ...
show more
130.49.115.229 - - [23/Jan/2026:21:12:38 -0500] "POST /xmlrpc.php HTTP/1.1" 403 1809 "-" "Wget/1.21.4"
130.49.115.229 - - [23/Jan/2026:21:12:53 -0500] "POST /xmlrpc.php HTTP/1.1" 403 1809 "-" "curl/8.6.0"
...
show less
Brute-Force
๐ฎ๐ฉ
Burayot
2026-01-01 07:49:06
(5 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 130.49.115.229 (-): 1 in the last 3 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 130.49.115.229 (-): 1 in the last 3600 secs
show less
Web App Attack
๐ช๐ธ
ofm-abuse
2025-12-31 06:33:28
(5 months ago)
Brute-force
...
Brute-Force
Bad Web Bot
Web App Attack