🇺🇸
integrantservices.com
2026-08-07 01:40:45
(3 weeks ago)
(wordpress) Failed wordpress login from 64.112.56.146 (US/United States/-)
Brute-Force
🇺🇸
TPI-Abuse
2026-08-03 22:33:09
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 64.112.56.146 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 64.112.56.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 18:32:47.718270 2026] [security2:error] [pid 217251:tid 217260] [client 64.112.56.146:53229] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.uoexpanse.com"] [uri "/.env.bak"] [unique_id "anEXD2TqDM2BvSHOfxKciAAAAQQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-03 21:43:53
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 64.112.56.146 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 64.112.56.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 17:43:29.944489 2026] [security2:error] [pid 935891:tid 935891] [client 64.112.56.146:41593] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.old.renju.net"] [uri "/.env.prod.local"] [unique_id "anELgYplHR_YlXDhhPdilAAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-03 19:13:14
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 64.112.56.146 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 64.112.56.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 15:12:55.463465 2026] [security2:error] [pid 623220:tid 623220] [client 64.112.56.146:43475] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "3905ccn.org"] [uri "/.env.live"] [unique_id "anDoN45FG2BkYgkZP_-FVwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
SilverZippo
2026-08-03 19:12:37
(3 weeks ago)
Web App Attack
Web App Attack
🇺🇸
tropicalidad.be
2026-08-03 17:24:14
(3 weeks ago)
blog spam/exploit attempt
Blog Spam
Hacking
🇺🇸
TPI-Abuse
2026-08-03 14:54:39
(3 weeks ago)
(mod_security) mod_security (id:212750) triggered by 64.112.56.146 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:212750) triggered by 64.112.56.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 10:54:20.934861 2026] [security2:error] [pid 300250:tid 300250] [client 64.112.56.146:39761] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\bon(?:abort|blur|change|click|dblclick|dragdrop|error|focus|keydown|keypress|keyup|load|mouse(?:down|move|out|over|up)|move|readystatechange|reset|resize|select|submit|unload)\\\\b[^a-zA-Z0-9_]{0,}?=" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "69"] [id "212750"] [rev "3"] [msg "COMODO WAF: XSS Attack Detected||www.powerkiteforum.com|F|2"] [data "Matched Data: onerror= found within REQUEST_URI: /viewthread.php?tid=22543\\x22><img src=x onerror=alert(qsxss9k7z)>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "www.powerkiteforum.com"] [uri "/viewthread.php"] [unique_id "anCrnEknDyiV2sew3LLQpgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
ipblock.com
2026-08-03 09:36:00
(3 weeks ago)
IPBlock protected site ID [4055-d][s=01].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
🇺🇸
Matthew Ping
2026-08-01 14:45:14
(4 weeks ago)
ModSecurity rule 949110 triggered on d865. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
🇱🇺
conseilgouz
2026-07-28 09:59:37
(1 month ago)
are-12 : Block return, carriage return, ... characters=>/component/contact/contact/4-nicole-luc-jacq ...
show more
are-12 : Block return, carriage return, ... characters=>/component/contact/contact/4-nicole-luc-jacque?Itemid=108'&amp(')
show less
Hacking
🇩🇪
iGroupware
2026-07-25 23:50:09
(1 month ago)
{"req/ip"=>{:discriminator=>"64.112.56.146", :count=>1, :period=>180, :limit=>500, :epoch_time=>1785 ...
show more
{"req/ip"=>{:discriminator=>"64.112.56.146", :count=>1, :period=>180, :limit=>500, :epoch_time=>1785023409}, "signups/ip"=>{:discriminator=>"64.112.56.146", :count=>1, :period=>3600, :limit=>5, :epoch_time=>1785023409}, "signups/email"=>{:discriminator=>"[email protected] ", :count=>14, :period=>86400, :limit=>2, :epoch_time=>1785023409}}
show less
Web App Attack
🇩🇪
raph
2026-07-22 12:54:33
(1 month ago)
[001] honeypot form submission
Web Spam
Blog Spam
🇺🇸
ipblock.com
2026-07-18 22:38:00
(1 month ago)
IPBlock protected site ID [4055-d][s=01].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
🇺🇸
ipblock.com
2026-07-17 13:07:00
(1 month ago)
IPBlock protected site ID [4055-d][s=01].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
🇺🇸
ipblock.com
2026-07-17 10:03:00
(1 month ago)
IPBlock protected site ID [4055-d][s=03].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack