๐บ๐ธ
TPI-Abuse
2026-07-17 13:24:32
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 194.99.24.99 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 194.99.24.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 09:24:25.634419 2026] [security2:error] [pid 17360:tid 17360] [client 194.99.24.99:55139] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dance4ovations.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dance4ovations.com"] [uri "/wp-json/wp/v2/users"] [unique_id "alotCa0iICOinAG5yGEpbQAAACc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Tilellit.PRO
2026-06-28 06:51:16
(3 weeks ago)
Fail2Ban banned 194.99.24.99 for security violations in jail wp-armour. Log: 2026/06/28 06:51:16 [er ...
show more
Fail2Ban banned 194.99.24.99 for security violations in jail wp-armour. Log: 2026/06/28 06:51:16 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 194.99.24.99 | Target: wplogin" , client: 194.99.24.99, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐บ๐ธ
NicoID
2026-04-28 00:15:40
(2 months ago)
194.99.24.99 - - [27/Apr/2026:05:39:22 -0600] "GET /wp-login.php HTTP/1.1" 200 4884 "https://www.goo ...
show more
194.99.24.99 - - [27/Apr/2026:05:39:22 -0600] "GET /wp-login.php HTTP/1.1" 200 4884 "https://www.google.com" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
...
show less
Brute-Force
๐จ๐ฟ
ptlab
2026-04-21 02:49:37
(3 months ago)
Detected wp_login attack from WP-host.
Hacking
Web App Attack
๐ฌ๐ง
hugolovepole
2026-04-02 02:35:18
(3 months ago)
Fail2Ban (nginx-badbots-444) on bethselamin
Port Scan
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-03-31 14:35:42
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 194.99.24.99 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 194.99.24.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 31 10:35:38.737157 2026] [security2:error] [pid 1915:tid 1915] [client 194.99.24.99:62071] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||visiontours.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "visiontours.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acvbull3GIsnEt1Gn3XNtAAAAAg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
octageeks.com
2026-03-20 04:11:41
(4 months ago)
Wordpress malicious attack:[octaxmlrpc]
Web App Attack
๐บ๐ธ
myagent.site
2026-03-19 00:46:59
(4 months ago)
Blocking for trying to access an exploit file: /xmlrpc.php
Hacking
๐ฉ๐ช
big-cloud.nl
2026-03-18 05:43:04
(4 months ago)
Try to access /xmlrpc.php
Web App Attack
๐บ๐ธ
myagent.site
2026-03-17 10:41:35
(4 months ago)
Blocking for trying to access an exploit file: /xmlrpc.php
Hacking
๐จ๐ญ
backslash
2026-01-25 03:20:04
(5 months ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-01-22 18:49:45
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 194.99.24.99 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 194.99.24.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 13:49:40.364366 2026] [security2:error] [pid 26088:tid 26088] [client 194.99.24.99:56839] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||forerunnersjazz.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "forerunnersjazz.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aXJxRDDYxRzmLjJp2ygZ0gAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-22 14:17:51
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 194.99.24.99 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 194.99.24.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 09:17:45.152393 2026] [security2:error] [pid 24138:tid 24138] [client 194.99.24.99:24561] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||deborahbein.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "deborahbein.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aXIxiX8lbPIaQ26PkgDhvwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-22 13:03:27
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 194.99.24.99 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 194.99.24.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 08:03:23.219484 2026] [security2:error] [pid 6199:tid 6199] [client 194.99.24.99:51059] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||adonamusic.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "adonamusic.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aXIgG8PKZL32a5LI-KgycwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-22 09:58:36
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 194.99.24.99 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 194.99.24.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 04:58:31.797220 2026] [security2:error] [pid 29852:tid 29852] [client 194.99.24.99:42607] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||brazilianbottom.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "brazilianbottom.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aXH0x0SH0y0Z1wRQxVX5WQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack