|
Anonymous
|
|
Blocked by ModSec and CSF
|
Port Scan
|
|
|
๐บ๐ธ
Jason Howell
|
|
130.49.79.115 - - [04/Jun/2026:03:47:50 -0500] "GET /wp-login.php HTTP/1.1" 301 576 "-" "Mozilla/5.0 ...
show more
130.49.79.115 - - [04/Jun/2026:03:47:50 -0500] "GET /wp-login.php HTTP/1.1" 301 576 "-" "Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.224 Safari/534.10"
130.49.79.115 - - [04/Jun/2026:03:48:05 -0500] "GET /wp-login.php HTTP/1.1" 200 4889 "-" "Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.224 Safari/534.10"
130.49.79.115 - - [04/Jun/2026:03:48:22 -0500] "POST /wp-login.php HTTP/1.1" 200 4971 "https://earthworksdesign.org/wp-login.php" "Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.224 Safari/534.10"
130.49.79.115 - - [04/Jun/2026:03:48:26 -0500] "GET /wp-login.php HTTP/1.1" 301 576 "-" "Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.224 Safari/534.10"
130.49.79.115 - - [04/Jun/2026:03:48:34 -0500] "GET /wp-login.php HTTP/1.1" 200 2669 "-" "Mozilla/5.0 (Windows; U; Wi
...
show less
|
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 130.49.79.115 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 130.49.79.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 02 06:16:24.869169 2026] [security2:error] [pid 2212:tid 2212] [client 130.49.79.115:31721] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.evolute.io"] [uri "/wp-config.php_bak"] [unique_id "afXO-HhC2-GX6u2I49KhJwAAAA0"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฉ๐ช
MusicLibrary
|
|
Attempted access to non existent wordpress urls
|
Bad Web Bot
|
|
|
๐ง๐ช
voormedia
|
|
Accessed trap at '/wp-login.php'
|
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 130.49.79.115 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 130.49.79.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 20 17:15:12.532365 2025] [security2:error] [pid 10695:tid 10695] [client 130.49.79.115:13223] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "grandvistalabs.com"] [uri "/.env"] [unique_id "aR-S8PVDp9u70v7YEDC6SwAAAAY"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210350) triggered by 130.49.79.115 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 130.49.79.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 15 13:24:44.878207 2025] [security2:error] [pid 31093:tid 31093] [client 130.49.79.115:42331] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||paladinmicro.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "paladinmicro.com"] [uri "/"] [unique_id "aRjFbNcnNzqw9mUMxLm3_gAAAEA"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210350) triggered by 130.49.79.115 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 130.49.79.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 15 12:34:42.960558 2025] [security2:error] [pid 10006:tid 10006] [client 130.49.79.115:24051] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||msbasile.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "msbasile.com"] [uri "/"] [unique_id "aRi5srZUuf51jhF3HHutvgAAAAo"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210350) triggered by 130.49.79.115 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 130.49.79.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 12 01:15:37.126942 2025] [security2:error] [pid 25158:tid 25158] [client 130.49.79.115:37665] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||g-h2o.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "g-h2o.com"] [uri "/"] [unique_id "aRQmCTHCiH_KeYDy4BnNKwAAAAI"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|