๐ฉ๐ช
Packets-Decreaser.NET
2025-12-29 14:01:08
(5 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-10-24 01:10:36
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 212.119.40.34 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 212.119.40.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 23 21:10:31.026753 2025] [security2:error] [pid 4024:tid 4024] [client 212.119.40.34:57371] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jolankagroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jolankagroup.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aPrSBz52SR3TdvO_iXyVigAAABM"], referer: https://jolankagroup.com/wp-json/wp/v2/users/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2025-08-19 08:31:52
(9 months ago)
๐ Probes for wp-login.php and other inexistent URLs
Hacking
Web App Attack
๐ช๐ธ
el-brujo
2025-08-18 16:48:55
(9 months ago)
[Mon Aug 18 18:48:54.943813 2025] [proxy_fcgi:error] [pid 2588833:tid 2589370] [remote 212.119.40.34 ...
show more
[Mon Aug 18 18:48:54.943813 2025] [proxy_fcgi:error] [pid 2588833:tid 2589370] [remote 212.119.40.34:0] AH01071: Got error 'Primary script unknown\n', referer: https://www.google.com
[Mon Aug 18 18:48:55.457535 2025] [proxy_fcgi:error] [pid 2588833:tid 2589352] [remote 212.119.40.34:0] AH01071: Got error 'Primary script unknown\n', referer: https://www.google.com
...
show less
Hacking
Web App Attack
๐จ๐ฟ
lp
2025-08-18 15:21:39
(9 months ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 212.119.40.34
2025-08-18T17:03:07+02: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 212.119.40.34
2025-08-18T17:03:07+02:00 vpn Access-Reject 'chrystal' station: 212.119.40.34 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐จ๐ฟ
lp
2025-08-18 06:22:47
(9 months ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 212.119.40.34
2025-08-18T07:32:18+02: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 212.119.40.34
2025-08-18T07:32:18+02:00 vpn Access-Reject 'caroyln' station: 212.119.40.34 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐ช๐ธ
el-brujo
2025-08-17 20:49:33
(9 months ago)
Cloudflare WAF: Request Path: / Request Query: Host: elhacker.net userAgent: Mozilla/5.0 (X11; Linu ...
show more
Cloudflare WAF: Request Path: / Request Query: Host: elhacker.net userAgent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36 Action: block Source: firewallManaged ASN Description: BTTGROUP-AS Country: US Method: GET Timestamp: 2025-08-17T20:49:33Z ruleId: 8e361ee4328f4a3caf6caf3e664ed6fe. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐จ๐ฟ
lp
2025-08-17 16:50:48
(9 months ago)
Unauthorized VPN login attempts: 2 attempts were recorded from 212.119.40.34
2025-08-17T17:55:24+02: ...
show more
Unauthorized VPN login attempts: 2 attempts were recorded from 212.119.40.34
2025-08-17T17:55:24+02:00 vpn Access-Reject 'service' station: 212.119.40.34 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2025-08-17T17:55:34+02:00 vpn Access-Reject 'analytics' station: 212.119.40.34 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐ช๐ธ
el-brujo
2025-08-17 15:26:16
(9 months ago)
Cloudflare WAF: Request Path: / Request Query: Host: elhacker.net userAgent: Mozilla/5.0 (X11; Linu ...
show more
Cloudflare WAF: Request Path: / Request Query: Host: elhacker.net userAgent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36 Action: block Source: firewallManaged ASN Description: BTTGROUP-AS Country: US Method: GET Timestamp: 2025-08-17T15:26:16Z ruleId: 8e361ee4328f4a3caf6caf3e664ed6fe. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐ช๐ธ
el-brujo
2025-08-17 15:26:14
(9 months ago)
[Sun Aug 17 17:26:14.141925 2025] [proxy_fcgi:error] [pid 1716842:tid 1717772] [remote 212.119.40.34 ...
show more
[Sun Aug 17 17:26:14.141925 2025] [proxy_fcgi:error] [pid 1716842:tid 1717772] [remote 212.119.40.34:0] AH01071: Got error 'Primary script unknown\n', referer: https://www.google.com
[Sun Aug 17 17:26:14.619640 2025] [proxy_fcgi:error] [pid 1716842:tid 1717782] [remote 212.119.40.34:0] AH01071: Got error 'Primary script unknown\n', referer: https://www.google.com
...
show less
Hacking
Web App Attack
๐บ๐ธ
Psycho Solutions LLC
2025-08-17 11:59:46
(9 months ago)
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-json/wp/v2/users - User A ...
show more
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-json/wp/v2/users - User Agent: N/A - Timestamp: 8/17/2025 11:59 am (UTC-6)
show less
Web Spam
Hacking
Bad Web Bot
Web App Attack
Anonymous
2025-08-16 16:08:14
(9 months ago)
Ports: 2077,2078,2082,2083,2086,2087,2095,2096; Direction: 0; Trigger: LF_DISTATTACK
Brute-Force
SSH
๐บ๐ธ
island-freaks.com
2025-08-16 00:22:47
(9 months ago)
Attack Type: WordPress Exploit Bot attempt on /wp-json/wp/v2/users | DNS 212.119.40.34 | Agent: Mozi ...
show more
Attack Type: WordPress Exploit Bot attempt on /wp-json/wp/v2/users | DNS 212.119.40.34 | Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36
show less
Port Scan
Hacking
Bad Web Bot
Exploited Host
Web App Attack
๐ฑ๐ป
garmtech.com
2025-08-15 17:41:09
(9 months ago)
Attempted access to sensitive endpoint (/wp-login.php) detected. Automated scan or unauthorized prob ...
show more
Attempted access to sensitive endpoint (/wp-login.php) detected. Automated scan or unauthorized probing.
show less
Web App Attack
๐จ๐ฆ
wil.com
2025-06-08 19:10:14
(11 months ago)
GlobalProtect login attempts with user lmartin.
VPN IP
Brute-Force