Anonymous
2026-09-01 21:53:15
(1 day ago)
[Drupal AbuseIPDB module] Request path is blacklisted. /wp-json/
Web App Attack
๐จ๐ญ
backslash
2026-08-31 19:18:00
(2 days ago)
block ruleset AA06B7315BA6AEB6421B52F0B32E14B509FD5FF0
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-08-18 21:05:19
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 130.49.115.237 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.115.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 17:05:13.290388 2026] [security2:error] [pid 22307:tid 22307] [client 130.49.115.237:26949] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kirbyimc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kirbyimc.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aoTJCcWTlDvzWTQ4LGmExwAAAAM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 04:10:35
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 130.49.115.237 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.115.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 00:10:28.560658 2026] [security2:error] [pid 3498899:tid 3498899] [client 130.49.115.237:10933] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||assheton.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "assheton.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anqgtOINgEuebmCRMOCgLQAAAAY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Mike Stevenson
2026-08-04 05:40:30
(4 weeks ago)
Blog Spam
๐ฉ๐ช
maxpower
2026-07-24 23:18:51
(1 month ago)
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 130.49.115.237 (ES/Spain/-): 3 in the last 360 ...
show more
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 130.49.115.237 (ES/Spain/-): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 130.49.115.237 - - [25/Jul/2026:01:18:45 +0200] "GET /wp-admin.php HTTP/1.1" 404 43793 "https://www.google.com" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36" "-" host=www.mediaqualitylab.com
2026/07/25 01:18:47 [error] 3266364#3266364: *78062 access forbidden by rule, client: 130.49.115.237, server: mediaqualitylab.com, request: "GET /?author=1 HTTP/1.1", host: "mediaqualitylab.com", referrer: "https://www.google.com"
2026/07/25 01:18:48 [error] 3266353#3266353: *78064 access forbidden by rule, client: 130.49.115.237, server: mediaqualitylab.com, request: "POST /xmlrpc.php HTTP/1.1", host: "mediaqualitylab.com"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-21 17:28:53
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 130.49.115.237 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.115.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 13:28:48.501913 2026] [security2:error] [pid 5246:tid 5246] [client 130.49.115.237:31491] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||andrsn.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "andrsn.com"] [uri "/wp-json/wp/v2/users"] [unique_id "al-sUHkKyGPpD9GjNkZdzAAAABc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
librebit
2026-07-07 04:34:19
(1 month ago)
Brute force
Brute-Force
๐ช๐ธ
librebit
2026-07-05 14:47:41
(1 month ago)
Brute force
Brute-Force
๐ซ๐ท
Tilellit.PRO
2026-07-05 03:52:54
(1 month ago)
WP Armour Plugin detection
Web Spam
Brute-Force
๐ช๐ธ
librebit
2026-07-04 12:55:49
(1 month ago)
Brute force
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-02 06:11:25
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 130.49.115.237 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.115.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 02 02:11:18.838142 2026] [security2:error] [pid 24972:tid 24972] [client 130.49.115.237:23943] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||thestardance.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "thestardance.com"] [uri "/wp-json/wp/v2/users"] [unique_id "akYBBtcEZ8rbYYtDUKcOUgAAAAY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Tilellit.PRO
2026-06-29 10:27:08
(2 months ago)
Fail2Ban banned 130.49.115.237 for security violations in jail wp-armour. Log: 2026/06/29 10:27:07 [ ...
show more
Fail2Ban banned 130.49.115.237 for security violations in jail wp-armour. Log: 2026/06/29 10:27:07 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 130.49.115.237 | Target: wplogin" , client: 130.49.115.237, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐ช๐ธ
librebit
2026-06-29 03:30:24
(2 months ago)
Brute force
Brute-Force
๐ซ๐ท
Tilellit.PRO
2026-06-28 07:43:04
(2 months ago)
Fail2Ban banned 130.49.115.237 for security violations in jail wp-armour. Log: 2026/06/28 07:43:03 [ ...
show more
Fail2Ban banned 130.49.115.237 for security violations in jail wp-armour. Log: 2026/06/28 07:43:03 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 130.49.115.237 | Target: wplogin" , client: 130.49.115.237, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam