🇮🇹
sssrit
2026-09-11 19:08:25
(13 hours ago)
130.49.77.11 - - [11/Sep/2026:21:08:24 +0200] "GET /register HTTP/1.1" 404 11448 "-" "curl/8.14.1"
. ...
show more
130.49.77.11 - - [11/Sep/2026:21:08:24 +0200] "GET /register HTTP/1.1" 404 11448 "-" "curl/8.14.1"
...
show less
Web App Attack
🇺🇸
nationaleventpros.com
2026-09-05 02:27:40
(1 week ago)
WordPress login attempt
Brute-Force
🇸🇬
anotherwatcher
2026-09-03 03:52:37
(1 week ago)
bad bot
Bad Web Bot
🇸🇪
vaia.cloud
2026-08-31 15:45:01
(1 week ago)
crowdsecurity/http-cve-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 01:04:54
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 130.49.77.11 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.77.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 21:04:48.935239 2026] [security2:error] [pid 18064:tid 18064] [client 130.49.77.11:25641] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jolankagroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jolankagroup.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ao-NMFVX1u8hwJzRBfI-FQAAAAk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-08-17 18:55:03
(3 weeks ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-14 15:33:45
(4 weeks ago)
(mod_security) mod_security (id:225170) triggered by 130.49.77.11 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.77.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 14 11:33:38.945634 2026] [security2:error] [pid 9611:tid 9611] [client 130.49.77.11:29559] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||refreshmc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "refreshmc.com"] [uri "/wp-json/wp/v2/users"] [unique_id "an81Uq2xfoFffprQo7bPBAAAAA0"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-07 08:44:03
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 130.49.77.11 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.77.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 04:43:57.699917 2026] [security2:error] [pid 29209:tid 29209] [client 130.49.77.11:44087] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lingafelt.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lingafelt.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anWazZdQi_I_yAGPCJxJWwAAAAs"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
gigatech
2026-08-06 19:15:23
(1 month ago)
Webserver Probing
Web App Attack
🇩🇰
ScamAware
2026-08-06 03:09:41
(1 month ago)
Detected by Cloudflare Security Events via WordPress automation. Detection: user_enumeration (WordPr ...
show more
Detected by Cloudflare Security Events via WordPress automation. Detection: user_enumeration (WordPress user enumeration). Hits from same IP in last 60 minutes: 2. Unique request paths counted internally: 2. Cloudflare action: block. Cloudflare source: firewallCustom.
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-05 19:03:49
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 130.49.77.11 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.77.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 05 15:03:42.539846 2026] [security2:error] [pid 4018909:tid 4018928] [client 130.49.77.11:21443] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||venezuelaguia.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "venezuelaguia.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anOJDlDe4MIDOIzJ5mMtOgAAAQ4"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-03 22:31:06
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 130.49.77.11 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.77.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 18:30:59.759316 2026] [security2:error] [pid 1037430:tid 1037430] [client 130.49.77.11:64215] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pamelalambert.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pamelalambert.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anEWo5rO851q2AK1HU3Z7wAAAAk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-08 07:09:54
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 130.49.77.11 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.77.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 08 03:09:48.388437 2026] [security2:error] [pid 20592:tid 20592] [client 130.49.77.11:48923] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||calvarycavaliers.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "calvarycavaliers.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ak33vLcduDQpk-r9mf9FkAAAAAU"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-07 23:08:11
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 130.49.77.11 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.77.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 07 19:08:03.578229 2026] [security2:error] [pid 30809:tid 30809] [client 130.49.77.11:61351] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||baughman.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "baughman.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ak2G06mB79Xprx4vEFfhKQAAAAA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Tilellit.PRO
2026-06-29 16:29:56
(2 months ago)
Fail2Ban banned 130.49.77.11 for security violations in jail wp-armour. Log: 2026/06/29 16:29:55 [er ...
show more
Fail2Ban banned 130.49.77.11 for security violations in jail wp-armour. Log: 2026/06/29 16:29:55 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 130.49.77.11 | Target: wplogin" , client: 130.49.77.11, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam