Anonymous
2026-04-20 14:12:11
(1 month ago)
212.119.41.222 - - [20/Apr/2026:14:12:08 +0000] "GET /.env.development.local HTTP/1.1" 404 41919 "-" ...
show more
212.119.41.222 - - [20/Apr/2026:14:12:08 +0000] "GET /.env.development.local HTTP/1.1" 404 41919 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-10 14:34:53
(6 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-10-11 22:47:46
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 212.119.41.222 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 212.119.41.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 11 18:47:42.479702 2025] [security2:error] [pid 12452:tid 12452] [client 212.119.41.222:36187] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||gamepart.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "gamepart.com"] [uri "/"] [unique_id "aOrejpIyAXeuD83L8oS4EQAAAA4"], referer: https://www.facebook.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-12 09:50:48
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 212.119.41.222 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 212.119.41.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 12 05:50:39.431171 2025] [security2:error] [pid 19275:tid 19275] [client 212.119.41.222:25439] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||windermerewatch2.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "windermerewatch2.com"] [uri "/"] [unique_id "aMPs7x-8-yhVDxZ41PaZlAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-04-08 10:08:59
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ป๐ณ
Xuan Can
2025-01-24 17:01:05
(1 year ago)
(mod_security) mod_security (id:6) triggered by 212.119.41.222 (IL/Israel/-): 1 in the last 3600 sec ...
show more
(mod_security) mod_security (id:6) triggered by 212.119.41.222 (IL/Israel/-): 1 in the last 3600 secs; Ports: 80,443; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 25 00:01:01.409960 2025] [security2:error] [pid 2592:tid 2692] [client 212.119.41.222:46481] [client 212.119.41.222] ModSecurity: Access denied with connection close (phase 2). Pattern match "wp-login.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "62"] [id "6"] [severity "CRITICAL"] [hostname "kb.pavietnam.vn"] [uri "/wp-login.php"] [unique_id "Z5PHTUg1IA8fBRINemGgFgAAAdA"], referer: https://kb.pavietnam.vn/wp-login.php?action=register
show less
Brute-Force
SSH
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2025-01-08 23:15:08
(1 year ago)
WP Login Scan Activities
Web App Attack
Anonymous
2024-09-30 08:25:08
(1 year ago)
Automatic report - Vulnerability scan
/RDWeb/Pages/en-US/login.aspx
Web App Attack
Anonymous
2024-09-26 19:00:12
(1 year ago)
Automatic report - Vulnerability scan
/RDWeb/Pages/en-US/login.aspx
Web App Attack
๐จ๐ฆ
wil.com
2024-09-24 02:09:57
(1 year ago)
GlobalProtect login attempts with user khubbard.
VPN IP
Brute-Force
๐บ๐ธ
TPI-Abuse
2024-05-13 13:31:21
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 212.119.41.222 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 212.119.41.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 13 09:31:16.856957 2024] [security2:error] [pid 24027] [client 212.119.41.222:13391] [client 212.119.41.222] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||crowleywoodworking.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "crowleywoodworking.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZkIWJLHhuXW4diIjuTSxggAAAAA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
i-turnradio.nl
2024-03-04 14:55:26
(2 years ago)
2024-03-04 @ 15:55:26 (CET) ~ Blocked for trying to access: /RDWeb/Pages/
Web App Attack