๐บ๐ธ
mnsf
2026-06-19 17:06:27
(1 day ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 17:01:19
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 212.119.41.24 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 212.119.41.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 13:01:15.723100 2026] [security2:error] [pid 23255:tid 23255] [client 212.119.41.24:64205] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cyberrob.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cyberrob.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aimYW8KhY9AtgHdFzJAPuQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2025-11-19 12:35:00
(7 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 212.119.41.24 (IL/Israel/-): 1 in t ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 212.119.41.24 (IL/Israel/-): 1 in the last 3600 secs
show less
Web App Attack
๐จ๐ญ
backslash
2025-11-10 10:50:08
(7 months ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-10-30 04:50:20
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 212.119.41.24 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 212.119.41.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 30 00:50:10.643964 2025] [security2:error] [pid 974514:tid 974514] [client 212.119.41.24:32635] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||harvestfrc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "harvestfrc.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aQLughvvc5ad1Gz6DpV36wAAAAA"], referer: https://harvestfrc.com/wp-json/wp/v2/users/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-08-20 21:09:00
(10 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-08-14 00:12:42
(10 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
Penny Packer
2025-08-03 13:21:44
(10 months ago)
Fail2Ban apache-tripwires
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-06 04:56:00
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 212.119.41.24 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 212.119.41.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 06 00:55:55.966308 2025] [security2:error] [pid 593736:tid 593736] [client 212.119.41.24:27295] [client 212.119.41.24] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Barcalounger/Images/Clive/Thumbs.db"] [unique_id "aBmWW9vzWjp9aPPlTzBHYgAAAAk"], referer: https://vitalitywebb.com/backstore/Barcalounger/Images/Clive/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-02-18 21:31:53
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-02-17 04:56:14
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐จ๐ญ
backslash
2024-11-01 04:30:06
(1 year ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
๐จ๐ฆ
wil.com
2024-09-23 16:19:41
(1 year ago)
GlobalProtect login attempts with user rhalphin.
VPN IP
Brute-Force
๐บ๐ธ
TPI-Abuse
2024-08-07 16:34:14
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 212.119.41.24 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 212.119.41.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 07 12:34:06.094592 2024] [security2:error] [pid 7399:tid 7399] [client 212.119.41.24:58825] [client 212.119.41.24] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Barcalounger/Images/Hansen II/Thumbs.db"] [unique_id "ZrOh_s52Qn0fN4K5tRau0AAAADA"], referer: https://vitalitywebb.com/backstore/Barcalounger/Images/Hansen%20II/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Admins@FBN
2024-04-07 20:47:12
(2 years ago)
VPN Logon Failed: AAA user authentication Rejected user = <mobile>
Brute-Force
Exploited Host