🇨🇿
lp
2026-09-15 03:22:33
(10 hours ago)
Unauthorized VPN login attempts: 3 attempts were recorded from 212.87.219.222
2026-09-15T04:51:36+02 ...
show more
Unauthorized VPN login attempts: 3 attempts were recorded from 212.87.219.222
2026-09-15T04:51:36+02:00 vpn Access-Reject 'admin1' station: 212.87.219.222 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-15T04:52:56+02:00 vpn Access-Reject 'vpnuser' station: 212.87.219.222 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-15T04:54:15+02:00 vpn Access-Reject '32074' station: 212.87.219.222 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
🇨🇿
Countryman
2026-09-13 00:10:01
(2 days ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
🇸🇪
OnTheEdge
2026-09-09 16:34:47
(5 days ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
🇫🇮
JimArchon72
2026-07-30 16:15:03
(1 month ago)
2026/07/30 16:14:35 "GET /wp-login.php?action=register HTTP/1.1"
Web App Attack
🇺🇸
TRoden
2026-06-16 13:36:44
(2 months ago)
Geo Block Plugin: Escalation flag(s): rce_attempt
Hacking
🇺🇸
TPI-Abuse
2026-04-30 05:51:11
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 212.87.219.222 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 212.87.219.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 01:51:04.368761 2026] [security2:error] [pid 1364:tid 1364] [client 212.87.219.222:64331] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||songforana.michaelsabbey.org|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "songforana.michaelsabbey.org"] [uri "/s3cmd.ini"] [unique_id "afLtyJ7HtOZ_m2k23zV5RwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-29 01:56:58
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 212.87.219.222 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 212.87.219.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 21:56:55.162933 2026] [security2:error] [pid 20247:tid 20247] [client 212.87.219.222:10641] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.bhempower.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.bhempower.com"] [uri "/s3cmd.ini"] [unique_id "afFlZ_YRuuqvgjfGUaK4RgAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-04-28 10:18:55
(4 months ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 212.87.219.222 (US/United States/-): ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 212.87.219.222 (US/United States/-): 1 in the last 3600 secs (0-195)
show less
Hacking
🇺🇸
TPI-Abuse
2026-04-26 14:16:38
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 212.87.219.222 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 212.87.219.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 10:16:32.048015 2026] [security2:error] [pid 8487:tid 8487] [client 212.87.219.222:10867] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||webcam.oxfordgliding.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "webcam.oxfordgliding.com"] [uri "/s3cmd.ini"] [unique_id "ae4eQPWWJ-Qo-riXU9aYIQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-26 09:07:39
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 212.87.219.222 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 212.87.219.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 05:07:31.540928 2026] [security2:error] [pid 19455:tid 19497] [client 212.87.219.222:61337] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.financialcertified.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.financialcertified.com"] [uri "/s3cmd.ini"] [unique_id "ae3V08wa0P4XMDeRKWrpvAAAAck"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-26 05:18:45
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 212.87.219.222 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 212.87.219.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 01:18:39.954091 2026] [security2:error] [pid 20316:tid 20327] [client 212.87.219.222:14367] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.browbrew.metalartgate.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.browbrew.metalartgate.com"] [uri "/s3cmd.ini"] [unique_id "ae2gL4QG7hKF2dzQiicUpAAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack