Anonymous
2026-08-27 09:50:59
(1 day ago)
FPROCO WEBEXPLOIT 130.49.79.178 (130.49.79.178)
Web App Attack
๐ซ๐ท
Yepngo
2026-08-23 23:13:34
(5 days ago)
130.49.79.178 - - [24/Aug/2026:01:10:17 +0200] "POST /wp-login.php HTTP/2.0" 200 12486 "https://yepn ...
show more
130.49.79.178 - - [24/Aug/2026:01:10:17 +0200] "POST /wp-login.php HTTP/2.0" 200 12486 "https://yepngo.com/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
130.49.79.178 - - [24/Aug/2026:01:13:34 +0200] "POST /wp-login.php HTTP/2.0" 200 12492 "https://yepngo.com/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 23:49:10
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 130.49.79.178 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.79.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 19:49:03.791585 2026] [security2:error] [pid 10931:tid 10931] [client 130.49.79.178:41125] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||securityzonepr.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "securityzonepr.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aoTvb8GTxI9p9xb83iib-QAAAAc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-10 14:41:27
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 130.49.79.178 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.79.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 10:41:20.988852 2026] [security2:error] [pid 2868796:tid 2868796] [client 130.49.79.178:22099] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cephedanisman.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cephedanisman.com"] [uri "/wp-json/wp/v2/users"] [unique_id "annjELJiPrv6-R5XHi_zswAAAAA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 00:27:32
(4 weeks ago)
(mod_security) mod_security (id:225170) triggered by 130.49.79.178 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.79.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 20:27:23.917700 2026] [security2:error] [pid 30497:tid 30497] [client 130.49.79.178:55303] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lsippell.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lsippell.com"] [uri "/wp-json/wp/v2/users"] [unique_id "am09a0dGIfgRGw-Uva1a2AAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-21 19:10:23
(1 month ago)
Suspicious or malicious traffic has been detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 22:53:30
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 130.49.79.178 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 130.49.79.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 18:53:24.960171 2026] [security2:error] [pid 30115:tid 30139] [client 130.49.79.178:35563] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mandhco.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mandhco.com"] [uri "/wp-json/wp/v2/users"] [unique_id "allg5MgMDM45aR7jLIZD6AAAARQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
librebit
2026-07-05 01:03:25
(1 month ago)
Brute force
Brute-Force
๐ช๐ธ
librebit
2026-07-03 20:23:13
(1 month ago)
Brute force
Brute-Force
๐บ๐ธ
NetVexor
2026-07-02 03:20:56
(1 month ago)
Attack source identified and submitted via NetVexor BGP Blackhole Network
Port Scan
Hacking
Brute-Force
๐ซ๐ท
Tilellit.PRO
2026-06-27 08:45:30
(2 months ago)
Fail2Ban banned 130.49.79.178 for security violations in jail wp-armour. Log: 2026/06/27 08:45:29 [e ...
show more
Fail2Ban banned 130.49.79.178 for security violations in jail wp-armour. Log: 2026/06/27 08:45:29 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 130.49.79.178 | Target: wplogin" , client: 130.49.79.178, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐ณ๐ฑ
Site.eu
2026-05-22 07:27:29
(3 months ago)
Excessive 404/403 errors
Brute-Force
๐ณ๐ฑ
Site.eu
2026-05-16 07:30:09
(3 months ago)
Excessive 404/403 errors
Brute-Force
๐จ๐ฟ
lp
2026-03-07 06:01:10
(5 months ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 130.49.79.178
2026-03-07T06:24:00+01: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 130.49.79.178
2026-03-07T06:24:00+01:00 vpn Access-Reject 'keithw' station: 130.49.79.178 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐จ๐ฟ
lp
2026-03-03 16:27:28
(5 months ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 130.49.79.178
2026-03-03T16:10:59+01: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 130.49.79.178
2026-03-03T16:10:59+01:00 vpn Access-Reject 'gangrel' station: 130.49.79.178 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack