๐บ๐ธ
TPI-Abuse
2026-07-29 21:00:12
(1 day ago)
(mod_security) mod_security (id:210350) triggered by 212.119.41.251 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 212.119.41.251 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 17:00:06.905597 2026] [security2:error] [pid 3099770:tid 3099770] [client 212.119.41.251:24369] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||steinmetzjewelers.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "steinmetzjewelers.com"] [uri "/"] [unique_id "ampp1udWMVzg_Jq3X7DdXQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-22 14:00:45
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 212.119.41.251 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 212.119.41.251 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 10:00:35.429714 2026] [security2:error] [pid 13344:tid 13344] [client 212.119.41.251:64697] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.bak" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abilityengraving.com"] [uri "/wp-config.bak"] [unique_id "ahBhg5ppB1ZyHGsUb-qVIQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-20 16:14:11
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 212.119.41.251 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 212.119.41.251 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 12:14:05.969529 2026] [security2:error] [pid 21019:tid 21019] [client 212.119.41.251:36631] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.txt" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stantontownship.org"] [uri "/wp-config.txt"] [unique_id "ag3dzXQxRXpaRUpDUKag5QAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Tilellit.PRO
2026-02-05 02:18:04
(5 months ago)
Fail2Ban banned 212.119.41.251 for security violations in jail wp-armour. Log: 2026/02/05 02:18:04 [ ...
show more
Fail2Ban banned 212.119.41.251 for security violations in jail wp-armour. Log: 2026/02/05 02:18:04 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 212.119.41.251 | Target: wplogin" , client: 212.119.41.251, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐ญ๐บ
bcsaba
2025-11-21 18:32:31
(8 months ago)
Joomla spam
212.119.41.251 - - [21/Nov/2025:19:32:29 +0100] "GET /index.php?option=com_easyblog&view ...
show more
Joomla spam
212.119.41.251 - - [21/Nov/2025:19:32:29 +0100] "GET /index.php?option=com_easyblog&view=dashboard&layout=write HTTP/1.1" 404 789 "https://*REDACTED*/intezmenyek/civil-szervezetek" "Mozilla/5.0 (Linux x86_64; rv:114.0) Gecko/20100101 Firefox/114.0"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-21 23:06:36
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 212.119.41.251 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 212.119.41.251 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 21 19:06:28.983660 2025] [security2:error] [pid 28289:tid 28289] [client 212.119.41.251:50955] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||babylontravelone.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "babylontravelone.com"] [uri "/"] [unique_id "aPgR9Kox8zP07tmEy2mfXQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
octageeks.com
2025-08-31 04:07:04
(11 months ago)
Wordpress malicious attack:[octawp]
Web App Attack
Anonymous
2025-08-20 21:19:53
(11 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐จ๐ฆ
wil.com
2024-10-27 03:34:17
(1 year ago)
GlobalProtect login attempts with user wonderware.
VPN IP
Brute-Force
๐ท๐บ
sms.ru
2024-09-28 13:55:05
(1 year ago)
SMS pumping attack from foreign country
DDoS Attack
Anonymous
2024-06-06 14:41:14
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฆ๐บ
oncord
2024-05-21 03:29:28
(2 years ago)
Form spam
Web Spam
๐บ๐ธ
tropicalidad.be
2024-05-06 13:41:14
(2 years ago)
blog comment/referrer spam
Web Spam
๐ฌ๐ง
essinghigh
2024-04-30 22:34:15
(2 years ago)
1714516455 # Service_probe # SIGNATURE_SEND # source_ip:212.119.41.251 # dst_port:5607
...
Port Scan
๐ฌ๐ท
JCB
2023-08-26 15:09:19
(2 years ago)
Form spam
Web Spam