πΊπΈ
TPI-Abuse
2026-01-03 18:26:52
(5 months ago)
(mod_security) mod_security (id:210350) triggered by 212.119.44.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 212.119.44.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 03 13:26:49.112188 2026] [security2:error] [pid 27501:tid 27501] [client 212.119.44.21:62553] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||staben.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "staben.com"] [uri "/"] [unique_id "aVlfaU4LnVjlMv_HYWHvtAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
voormedia
2025-08-05 14:22:38
(10 months ago)
Accessed trap at '/wp-login.php'
Web App Attack
π¨πΏ
lp
2025-03-04 11:50:32
(1 year ago)
Unauthorized VPN login attempts: 4 attempts were recorded from 212.119.44.21
2025-03-04T12:00:01+01: ...
show more
Unauthorized VPN login attempts: 4 attempts were recorded from 212.119.44.21
2025-03-04T12:00:01+01:00 vpn Access-Reject 'hawk' station: 212.119.44.21 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2025-03-04T12:07:14+01:00 vpn Access-Reject 'bandit' station: 212.119.44.21 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2025-03-04T12:10:50+01:00 vpn Access-Reject 'homer' station: 212.119.44.21 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2025-03-04T12:16:14+01:00 vpn Access-Reject 'outlaw' station: 212.119.44.21 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
π¨πΏ
lp
2025-03-01 02:49:58
(1 year ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 212.119.44.21
2025-03-01T02:19:38+01: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 212.119.44.21
2025-03-01T02:19:38+01:00 vpn Access-Reject 'alistair' station: 212.119.44.21 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
π¨πΏ
lp
2025-02-27 08:50:17
(1 year ago)
Unauthorized VPN login attempts: 3 attempts were recorded from 212.119.44.21
2025-02-27T09:14:55+01: ...
show more
Unauthorized VPN login attempts: 3 attempts were recorded from 212.119.44.21
2025-02-27T09:14:55+01:00 vpn Access-Reject 'inequity' station: 212.119.44.21 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2025-02-27T09:16:52+01:00 vpn Access-Reject 'grit' station: 212.119.44.21 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2025-02-27T09:22:02+01:00 vpn Access-Reject 'leitmotif' station: 212.119.44.21 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
π¦πΊ
MAGIC
2023-12-19 00:03:31
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
π¦πΊ
MAGIC
2023-12-15 05:07:20
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
π¦πΊ
MAGIC
2023-12-13 06:09:55
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
ππΊ
HoneyPotEu
2023-12-09 08:27:00
(2 years ago)
212.119.44.21 [redacted] (26548-PUREVOLTAGE-INC Israel -) - - [09/Dec/2023:09:26:00 +0100] "GET /wp- ...
show more
212.119.44.21 [redacted] (26548-PUREVOLTAGE-INC Israel -) - - [09/Dec/2023:09:26:00 +0100] "GET /wp-login.php HTTP/1.1" 401 574 "-" "Mozilla/5.0 (Linux; Android 11; LM-K500) AppleWebKit/537.36 (KHTM
...
show less
Bad Web Bot
Web App Attack
π¦πΊ
MAGIC
2023-12-02 09:03:54
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
πΊπΈ
TPI-Abuse
2023-11-29 12:24:04
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 212.119.44.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 212.119.44.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 29 07:23:56.726866 2023] [security2:error] [pid 27408] [client 212.119.44.21:30455] [client 212.119.44.21] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sharawi-gum.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sharawi-gum.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZWctXHhbY-HWh4AOI6jJAwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2023-11-23 10:39:32
(2 years ago)
opencart admin attack from fail2ban
...
DDoS Attack
Brute-Force
SSH
π«π·
Cyber SOC
2023-07-04 16:44:40
(2 years ago)
Peaksys - 1688489024000
Open Proxy
π«π·
Cyber SOC
2023-06-27 09:57:45
(2 years ago)
Peaksys - 1687859810000
Open Proxy
π―π΅
HeliJP
2022-09-29 11:22:16
(3 years ago)
2022-09-29 11:37:40 - Recognized attacks\bad behavior from IP address 212.119.44.21 on port 443\80 ( ...
show more
2022-09-29 11:37:40 - Recognized attacks\bad behavior from IP address 212.119.44.21 on port 443\80 (59 daily hits): Remote Command Execution: Windows Command Injection, Remote Command Execution: Wildcard bypass technique attempt, PHP Injection Attack: High-Risk PHP Function Call Found, PHP Injection Attack: Low-Value PHP Function Call Found, SQL Injection Attack Detected via libinjection, SQL Injection Attack: SQL Operator Detected, SQL Injection Attack: SQL Tautology Detected, SQL Injection Attack, Detects MySQL comments, conditions and ch(a)r injections, Detects chained SQL injection attempts 2/2, Detects classic SQL injection probings 2/3, Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (12), SQL Comment Sequence Detected, SQL Hex Encoding Identified
show less
Hacking
SQL Injection
Web App Attack