🇵🇱
dzpk
2026-09-18 01:20:48
(1 day ago)
130.49.77.231 - - [18/Sep/2026:03:20:47 +0200] "GET /wp-json/ HTTP/1.1" 404 272 "-" "curl/8.22.0"
Bad Web Bot
Web App Attack
🇸🇪
OnTheEdge
2026-09-14 17:11:31
(4 days ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
🇨🇿
Countryman
2026-09-12 00:10:01
(1 week ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
🇨🇿
lp
2026-09-10 03:21:26
(1 week ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 130.49.77.231
2026-09-10T04:46:10+02: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 130.49.77.231
2026-09-10T04:46:10+02:00 vpn Access-Reject 'daljinder-wd' station: 130.49.77.231 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
🇸🇪
OnTheEdge
2026-09-08 16:49:21
(1 week ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-08 02:19:54
(1 week ago)
[08/Sep/2026:05:19:53 +0300] -- 130.49.77.231 Ban reason: User-Agent curl/
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-06 05:53:26
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
🇺🇸
cwytech
2026-09-02 20:59:21
(2 weeks ago)
Fleet-wide ban from the Ghostfleet 👻. Triggered by scenario: cwy/tpot-web-high.
Bad Web Bot
Web App Attack
🇨🇭
backslash
2026-09-01 08:06:00
(2 weeks ago)
block ruleset AA06B7315BA6AEB6421B52F0B32E14B509FD5FF0
SQL Injection
🇺🇸
TPI-Abuse
2026-06-17 15:33:18
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 130.49.77.231 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.77.231 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 11:33:12.103730 2026] [security2:error] [pid 27163:tid 27163] [client 130.49.77.231:9833] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wickedworks.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wickedworks.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ajK-OBMbvF-ngJtq6EmregAAAAA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
JustMeHere
2026-06-11 22:46:22
(3 months ago)
[Thu Jun 11 18:46:17.662646 2026] [security2:error] [pid 94665:tid 94706] [client 130.49.77.231:2488 ...
show more
[Thu Jun 11 18:46:17.662646 2026] [security2:error] [pid 94665:tid 94706] [client 130.49.77.231:24889] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.15.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "yorknation.com"] [uri "/xmlrpc.php"] [unique_id "ais6ubrbQiJj5wDFBc-1gwAAAQ0"]
...
show less
Web App Attack
Anonymous
2026-06-11 17:10:51
(3 months ago)
PARMACOM WEBEXPLOIT 130.49.77.231 (130.49.77.231)
Web App Attack
🇺🇸
TPI-Abuse
2026-06-03 16:00:11
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 130.49.77.231 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.77.231 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 12:00:07.012066 2026] [security2:error] [pid 7428:tid 7428] [client 130.49.77.231:18461] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||memrfixitok.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "memrfixitok.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiBPh0nJvK0ZXkLUsPaq-AAAAA0"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-31 12:17:34
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 130.49.77.231 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.77.231 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 08:17:30.826614 2026] [security2:error] [pid 20126:tid 20126] [client 130.49.77.231:15599] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||humbliaslaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "humbliaslaw.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahwm2rqhOyi9R8A1PlowIQAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-05-31 12:00:10
(3 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack