๐ณ๐ฑ
TCATERDSBE
2026-08-17 12:48:00
(2 weeks ago)
SQL Injection
SQL Injection
๐บ๐ธ
integrantservices.com
2026-08-07 01:40:27
(3 weeks ago)
(wordpress) Failed wordpress login from 64.112.56.32 (US/United States/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-04 06:26:38
(4 weeks ago)
(mod_security) mod_security (id:212620) triggered by 64.112.56.32 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:212620) triggered by 64.112.56.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 04 02:25:51.109652 2026] [security2:error] [pid 1357662:tid 1357662] [client 64.112.56.32:46873] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||www.powerkiteforum.com|F|2"] [data "Matched Data: <script found within REQUEST_URI: /member.php?action=viewpro'\\x22></title></style></textarea></script><script>alert(qsxss9k7z)</script>&member=nomadic"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "www.powerkiteforum.com"] [uri "/member.php"] [unique_id "anGF78XtV229-iY11QjT3wAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-04 05:47:02
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 64.112.56.32 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 64.112.56.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 04 01:46:40.216877 2026] [security2:error] [pid 3300312:tid 3300312] [client 64.112.56.32:36427] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "med-engineering.com"] [uri "/.env.production"] [unique_id "anF8wP4z3jToYycvnvGTnQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
IRT@Unisi
2026-08-04 01:27:12
(4 weeks ago)
Multiple web server 400 error codes from same source ip.
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-03 16:06:57
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 64.112.56.32 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 64.112.56.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 12:06:32.768133 2026] [security2:error] [pid 3987290:tid 3987311] [client 64.112.56.32:37029] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "uoexpanse.com"] [uri "/.env.dev"] [unique_id "anC8iP0K2YyTfUhw4ZiabgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
mikekarl
2026-07-27 14:58:25
(1 month ago)
SQL INJECTION 1234''
SQL Injection
๐ฎ๐ฉ
David Koswari
2026-07-27 05:33:00
(1 month ago)
REQ_BLOCKED_ACL
DDoS Attack
FTP Brute-Force
Ping of Death
Port Scan
Hacking
SQL Injection
Spoofing
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
IoT Targeted
๐บ๐ธ
nodepile
2026-07-25 11:27:47
(1 month ago)
Requests denied due to active blacklist hits (tenant=82 method=POST path=/checkout/cart/add/uenc/aHR ...
show more
Requests denied due to active blacklist hits (tenant=82 method=POST path=/checkout/cart/add/uenc/aHR0cHM6Ly91bW5pdHphLmNvbS93aGVlbHMuaHRtbD9jYXQ9/product/11767/ ua='Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36')
show less
Web App Attack
Exploited Host
๐บ๐ธ
Penny Packer
2026-07-23 08:55:38
(1 month ago)
Fail2Ban apache-tripwires
Web App Attack
๐ซ๐ท
conseilgouz
2026-07-18 16:32:32
(1 month ago)
joe-12 : Block return, carriage return, ... characters=>/joomla/telechargements/119-joomla-5/120-5-0 ...
show more
joe-12 : Block return, carriage return, ... characters=>/joomla/telechargements/119-joomla-5/120-5-0/121-5-0-0.html?task=download&collection=seb_download_full_package'&xi=0&file=seb_download_full_package&id=15895(')
show less
Hacking
๐ฉ๐ช
HandyTreff.de
2026-07-18 16:28:03
(1 month ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -106.99 (Bad < -10 / Very Bad < -20 ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -106.99 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
ipblock.com
2026-07-17 13:07:00
(1 month ago)
IPBlock protected site ID [4055-d][s=01].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
ipblock.com
2026-07-17 10:03:00
(1 month ago)
IPBlock protected site ID [4055-d][s=02].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 18:02:48
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 64.112.56.32 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 64.112.56.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 14:02:30.093774 2026] [security2:error] [pid 4536:tid 4536] [client 64.112.56.32:48345] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.r-390a.net"] [uri "/.env.dev.local"] [unique_id "alkctp_5zrVDEI5XpTf8wAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack