๐บ๐ธ
TPI-Abuse
2026-05-21 11:01:28
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 194.99.27.166 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 194.99.27.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 07:01:23.010907 2026] [security2:error] [pid 2609:tid 2609] [client 194.99.27.166:27765] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mikelynchphoto.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mikelynchphoto.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ag7mA2yActzUG25OSF6pkwAAAAs"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
tilellit.pro
2026-05-07 20:11:28
(1 month ago)
Fail2Ban banned 194.99.27.166 for security violations in jail wp-armour. Log: 2026/05/07 20:11:28 [e ...
show more
Fail2Ban banned 194.99.27.166 for security violations in jail wp-armour. Log: 2026/05/07 20:11:28 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 194.99.27.166 | Target: wplogin" , client: 194.99.27.166, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐ซ๐ท
tilellit.pro
2026-05-06 13:03:31
(1 month ago)
Fail2Ban banned 194.99.27.166 for security violations in jail wp-armour. Log: 2026/05/06 13:03:30 [e ...
show more
Fail2Ban banned 194.99.27.166 for security violations in jail wp-armour. Log: 2026/05/06 13:03:30 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 194.99.27.166 | Target: wplogin" , client: 194.99.27.166, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐บ๐ธ
TPI-Abuse
2026-05-03 16:39:02
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 194.99.27.166 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 194.99.27.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 03 12:38:59.113124 2026] [security2:error] [pid 20362:tid 20362] [client 194.99.27.166:63493] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||schelske.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "schelske.us"] [uri "/wp-json/wp/v2/users"] [unique_id "afd6I_rmLRyUCRSGOQaGgAAAABc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
tilellit.pro
2026-05-02 19:18:57
(1 month ago)
Fail2Ban banned 194.99.27.166 for security violations in jail wp-armour. Log: 2026/05/02 19:18:56 [e ...
show more
Fail2Ban banned 194.99.27.166 for security violations in jail wp-armour. Log: 2026/05/02 19:18:56 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 194.99.27.166 | Target: wplogin" , client: 194.99.27.166, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐จ๐ญ
backslash
2026-03-21 01:06:11
(2 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐บ๐ธ
octageeks.com
2026-03-20 04:06:57
(2 months ago)
Wordpress malicious attack:[octaxmlrpc]
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-03-19 04:46:20
(2 months ago)
Try to access /xmlrpc.php
Web App Attack
๐ฉ๐ช
LRob.fr
2026-03-17 12:30:17
(2 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-03-17 08:58:40
(2 months ago)
Blocking for trying to access an exploit file: /xmlrpc.php
Hacking
๐ฎ๐ณ
dineshskt4all
2025-10-26 18:33:54
(7 months ago)
[Sun Oct 26 18:33:52.001460 2025] [proxy_fcgi:error] [pid 2209739:tid 139002956547776] [client 194.9 ...
show more
[Sun Oct 26 18:33:52.001460 2025] [proxy_fcgi:error] [pid 2209739:tid 139002956547776] [client 194.99.27.166:0] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
๐ณ๐ฑ
exxos
2025-10-10 11:03:01
(7 months ago)
Attacks with Bad user agents
Hacking
๐จ๐ฟ
lp
2025-07-03 04:51:22
(11 months ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 194.99.27.166
2025-07-03T06:41:40+02: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 194.99.27.166
2025-07-03T06:41:40+02:00 vpn Access-Reject 'd.brown' station: 194.99.27.166 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐จ๐ฟ
lp
2025-07-02 15:22:12
(11 months ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 194.99.27.166
2025-07-02T15:46:59+02: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 194.99.27.166
2025-07-02T15:46:59+02:00 vpn Access-Reject 'c.smith' station: 194.99.27.166 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐จ๐ฟ
lp
2025-07-02 00:23:31
(11 months ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 194.99.27.166
2025-07-02T01:38:03+02: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 194.99.27.166
2025-07-02T01:38:03+02:00 vpn Access-Reject 'j.brown' station: 194.99.27.166 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack