๐ซ๐ฎ
bittiguru.fi
2026-09-23 04:33:12
(17 hours ago)
194.99.26.245 - [23/Sep/2026:07:32:18 +0300] "POST /xmlrpc.php HTTP/2.0" 404 12529 "-" "Mozilla/5.0 ...
show more
194.99.26.245 - [23/Sep/2026:07:32:18 +0300] "POST /xmlrpc.php HTTP/2.0" 404 12529 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.0 Safari/605.1.15" "4.66"
194.99.26.245 - [23/Sep/2026:07:33:11 +0300] "POST /xmlrpc.php HTTP/2.0" 404 12529 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.0 Safari/605.1.15" "4.66"
...
show less
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
LRob
2026-09-22 15:14:07
(1 day ago)
This address sends abusive requests to WordPress sites we host: user enumeration through the REST AP ...
show more
This address sends abusive requests to WordPress sites we host: user enumeration through the REST API, xmlrpc.php calls the site refuses, endpoints the site does not serve. These are the reconnaissance and attack calls of automated WordPress attack tools, blocked on sight. Please check the machine behind it. | method: GET | path: /wp-login.php | 2026-09-22 15:14 UTC
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-29 20:18:45
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 194.99.26.245 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 194.99.26.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 16:18:35.564248 2026] [security2:error] [pid 674698:tid 674698] [client 194.99.26.245:57619] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||waterjetsolutions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "waterjetsolutions.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ampgG8Ls1mMkKfwEBWRF7QAAAAg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
DRI
2026-07-29 09:28:09
(1 month ago)
Web attack/Malicious activity detected
Web App Attack
๐น๐ท
eryilmaz
2026-07-28 19:43:10
(1 month ago)
Automated attack blocked by eryilmaz WAF/defense engine (level 1, source: auto, path: /wp-login.php)
Web App Attack
Hacking
๐จ๐ญ
backslash
2026-07-19 17:57:00
(2 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐ต๐พ
SecOpsSL
2026-07-11 07:30:20
(2 months ago)
194.99.26.245 - - [11/Jul/2026:04:09:20 -0300] "POST /wp-login.php HTTP/1.1" 200 3151 "https://ucmb. ...
show more
194.99.26.245 - - [11/Jul/2026:04:09:20 -0300] "POST /wp-login.php HTTP/1.1" 200 3151 "https://ucmb.edu.py/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
194.99.26.245 - - [11/Jul/2026:04:23:12 -0300] "POST /wp-login.php HTTP/1.1" 200 3096 "https://ucmb.edu.py/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
194.99.26.245 - - [11/Jul/2026:04:30:19 -0300] "POST /wp-login.php HTTP/1.1" 200 3142 "https://ucmb.edu.py/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
show less
Brute-Force
Web App Attack
๐ซ๐ท
Tilellit.PRO
2026-06-28 09:33:55
(2 months ago)
Fail2Ban banned 194.99.26.245 for security violations in jail wp-armour. Log: 2026/06/28 09:33:55 [e ...
show more
Fail2Ban banned 194.99.26.245 for security violations in jail wp-armour. Log: 2026/06/28 09:33:55 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 194.99.26.245 | Target: wplogin" , client: 194.99.26.245, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐บ๐ธ
kosada.com
2026-06-24 20:30:44
(2 months ago)
Web password guessing
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-02-26 17:25:23
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 194.99.26.245 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 194.99.26.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 26 12:25:20.047494 2026] [security2:error] [pid 29514:tid 29514] [client 194.99.26.245:22463] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dmasoftlab.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dmasoftlab.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aaCCAOXO4h9h_Cw18R_RsgAAAAU"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-23 03:15:00
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 194.99.26.245 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 194.99.26.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 22:14:52.340688 2026] [security2:error] [pid 567:tid 567] [client 194.99.26.245:37963] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||greensandbeans.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "greensandbeans.us"] [uri "/wp-json/wp/v2/users"] [unique_id "aXLnrNa74kBEL2Okdn8_tQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-22 21:33:20
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 194.99.26.245 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 194.99.26.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 16:33:15.746500 2026] [security2:error] [pid 19942:tid 19942] [client 194.99.26.245:57241] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||versallis.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "versallis.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "aXKXm2xJ6UyQtELZR0GRXQAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-22 10:28:28
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 194.99.26.245 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 194.99.26.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 05:28:24.622638 2026] [security2:error] [pid 7554:tid 7554] [client 194.99.26.245:64005] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||phillipstasklist.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "phillipstasklist.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "aXH7yPZ_LoEZYP7SElzJPwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
octageeks.com
2025-03-03 05:09:47
(1 year ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2025-02-09 07:21:34
(1 year ago)
WP Login Scan Activities
Web App Attack