🇺🇸
TPI-Abuse
2026-09-01 13:28:20
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 194.99.24.236 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 194.99.24.236 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:28:11.514896 2026] [security2:error] [pid 23110:tid 23110] [client 194.99.24.236:32795] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||clarktec.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "clarktec.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apbS63DskmWd4rGc6CSsnwAAAAw"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Yepngo
2026-08-23 23:27:06
(1 week ago)
194.99.24.236 - - [24/Aug/2026:01:08:58 +0200] "POST /wp-login.php HTTP/2.0" 200 12486 "https://yepn ...
show more
194.99.24.236 - - [24/Aug/2026:01:08:58 +0200] "POST /wp-login.php HTTP/2.0" 200 12486 "https://yepngo.com/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
194.99.24.236 - - [24/Aug/2026:01:27:06 +0200] "POST /wp-login.php HTTP/2.0" 200 12492 "https://yepngo.com/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-18 01:02:38
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 194.99.24.236 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 194.99.24.236 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 21:02:31.310039 2026] [security2:error] [pid 19963:tid 19963] [client 194.99.24.236:55737] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||churchtop.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "churchtop.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aoOvJwJ3L4v55wE8yUXTmwAAAA0"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-08-05 23:34:36
(4 weeks ago)
Multiple WAF Violations
Web App Attack
🇺🇸
kosada.com
2026-08-04 18:47:55
(4 weeks ago)
Web password guessing
Brute-Force
🇺🇸
TPI-Abuse
2026-08-04 01:58:29
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 194.99.24.236 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 194.99.24.236 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 21:58:21.602857 2026] [security2:error] [pid 1696962:tid 1696962] [client 194.99.24.236:15099] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mukau.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mukau.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anFHPba2xOE2ooyhN7z_fQAAABI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
SX Communications
2026-08-01 03:05:32
(1 month ago)
Blocked abusive HTTP application-layer DoS / botnet traffic from 194.99.24.236: traffic from this ad ...
show more
Blocked abusive HTTP application-layer DoS / botnet traffic from 194.99.24.236: traffic from this address continues high-cost dynamic page and feed requests at abusive rates via TCP/HTTPS despite edge block responses. Likely compromised end-user host.
show less
DDoS Attack
Bad Web Bot
Exploited Host
🇫🇷
Tilellit.PRO
2026-07-05 04:02:17
(1 month ago)
WP Armour Plugin detection
Web Spam
Brute-Force
🇺🇸
TPI-Abuse
2026-07-01 22:44:01
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 194.99.24.236 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 194.99.24.236 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 01 18:43:57.794525 2026] [security2:error] [pid 20369:tid 20369] [client 194.99.24.236:34679] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jolankagroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jolankagroup.com"] [uri "/wp-json/wp/v2/users"] [unique_id "akWYLYF2GXJypg93IhdysAAAABM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Tilellit.PRO
2026-06-27 13:57:37
(2 months ago)
Fail2Ban banned 194.99.24.236 for security violations in jail wp-armour. Log: 2026/06/27 13:57:37 [e ...
show more
Fail2Ban banned 194.99.24.236 for security violations in jail wp-armour. Log: 2026/06/27 13:57:37 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 194.99.24.236 | Target: wplogin" , client: 194.99.24.236, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
🇫🇷
Tilellit.PRO
2026-06-27 05:45:15
(2 months ago)
Fail2Ban banned 194.99.24.236 for security violations in jail wp-armour. Log: 2026/06/27 05:45:15 [e ...
show more
Fail2Ban banned 194.99.24.236 for security violations in jail wp-armour. Log: 2026/06/27 05:45:15 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 194.99.24.236 | Target: wplogin" , client: 194.99.24.236, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
🇺🇸
TPI-Abuse
2026-02-07 00:04:22
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 194.99.24.236 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 194.99.24.236 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 06 19:04:19.011387 2026] [security2:error] [pid 3524658:tid 3524658] [client 194.99.24.236:23215] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||citati.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "citati.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aYaBg_XWX1T4XCPImTXBSQAAAAM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇸
Smel
2023-12-09 18:48:45
(2 years ago)
Unauthorized Probe/Connection, Hack -
Port Scan
Hacking
🇨🇭
backslash
2023-12-01 07:39:32
(2 years ago)
Bad Web Bot
🇵🇱
rafix
2023-11-01 01:29:58
(2 years ago)
Scrapping website, using diffrent useragents, not wait for response, #botnet20231026
DDoS Attack
Bad Web Bot