๐บ๐ธ
TPI-Abuse
2026-06-03 06:03:24
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 212.119.41.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 212.119.41.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 02:03:19.565328 2026] [security2:error] [pid 25285:tid 25285] [client 212.119.41.90:54947] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Golden-Technologies/pics/Colors/Thumbs.db"] [unique_id "ah_Dp5WRxEu4038A3hDoRwAAABg"], referer: https://vitalitywebb.com/backstore/Golden-Technologies/pics/Colors/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-04-16 00:27:00
(1 month ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-14 12:08:05
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 212.119.41.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 212.119.41.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 08:07:55.412473 2026] [security2:error] [pid 17047:tid 17047] [client 212.119.41.90:13383] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Barcalounger/Images/Briarwood II/Stetson Coffee/originals/Thumbs.db"] [unique_id "abVPm05S7Lom3rmOEfiPxQAAABQ"], referer: https://vitalitywebb.com/backstore/Barcalounger/Images/Briarwood%20II/Stetson%20Coffee/originals/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-03-11 20:42:01
(2 months ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
๐บ๐ธ
[email protected]
2025-12-03 01:01:17
(6 months ago)
Fail2Ban jail apache-json-scanners detected activity on 2025-12-03T01:01:17Z
Brute-Force
๐บ๐ธ
[email protected]
2025-12-03 00:02:38
(6 months ago)
Fail2Ban jail apache-json-scanners detected activity on 2025-12-03T00:02:38Z
Brute-Force
๐ฆ๐บ
MAGIC
2025-11-19 02:13:57
(6 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-11-04 18:58:13
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 212.119.41.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 212.119.41.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 04 13:58:08.990191 2025] [security2:error] [pid 14644:tid 14644] [client 212.119.41.90:39613] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.oualierealty.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.oualierealty.com"] [uri "/st-kitts-nevis-real-estate-2-50000,---listingsdb_id,DESC-1--"] [unique_id "aQpMwAYtnA4jKy43GgCN4gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
jfz-abuse
2025-11-04 12:49:41
(7 months ago)
fail2ban: apache-php-recon
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-18 00:34:33
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 212.119.41.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 212.119.41.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 17 20:34:28.672647 2025] [security2:error] [pid 6675:tid 6675] [client 212.119.41.90:20511] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||fingershrine.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "fingershrine.com"] [uri "/"] [unique_id "aMtTlMYDtdnXOW4WcOp_qAAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-02-17 11:21:22
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-02-16 09:03:04
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-01-01 00:48:39
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 212.119.41.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 212.119.41.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 31 19:48:28.817207 2024] [security2:error] [pid 2003157:tid 2003157] [client 212.119.41.90:33295] [client 212.119.41.90] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||engravingbyangela.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "engravingbyangela.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z3SQ3DulkOfzq2lg3GtSOAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
NxtGenIT
2024-06-09 19:30:15
(1 year ago)
212.119.41.90 has been observed attacking Port 8443. Observed Threat: Suspicious TLS Evasion Found
Web App Attack
๐ฌ๐ง
essinghigh
2024-04-29 21:58:30
(2 years ago)
1714427909 # Service_probe # SIGNATURE_SEND # source_ip:212.119.41.90 # dst_port:5607
...
Port Scan