🇺🇸
integrantservices.com
2026-08-07 01:39:19
(1 month ago)
(wordpress) Failed wordpress login from 64.112.56.58 (US/United States/-)
Brute-Force
🇺🇸
TPI-Abuse
2026-08-04 06:26:47
(1 month ago)
(mod_security) mod_security (id:212750) triggered by 64.112.56.58 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:212750) triggered by 64.112.56.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 04 02:25:50.039830 2026] [security2:error] [pid 1357681:tid 1357681] [client 64.112.56.58:34873] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\bon(?:abort|blur|change|click|dblclick|dragdrop|error|focus|keydown|keypress|keyup|load|mouse(?:down|move|out|over|up)|move|readystatechange|reset|resize|select|submit|unload)\\\\b[^a-zA-Z0-9_]{0,}?=" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "69"] [id "212750"] [rev "3"] [msg "COMODO WAF: XSS Attack Detected||www.powerkiteforum.com|F|2"] [data "Matched Data: onerror= found within REQUEST_URI: /misc.php?action=list&desc=\\x22><img src=x onerror=alert(qsxss9k7z)>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "www.powerkiteforum.com"] [uri "/misc.php"] [unique_id "anGF7teJpNHKhsdBEMsevAAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-03 19:13:16
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 64.112.56.58 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 64.112.56.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 15:12:55.523704 2026] [security2:error] [pid 619091:tid 619091] [client 64.112.56.58:41089] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "3905ccn.org"] [uri "/.env.prod.local"] [unique_id "anDoN18owXkY1dsJ8bP_jgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
ipblock.com
2026-08-03 09:36:00
(1 month ago)
IPBlock protected site ID [4055-d][s=07].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
🇺🇸
Matthew Ping
2026-08-01 14:45:01
(1 month ago)
ModSecurity rule 949110 triggered on d865. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
🇷🇺
Mga Admin
2026-07-30 14:38:23
(1 month ago)
64.112.56.58 - - [30/Jul/2026:21:38:22 +0700] "GET /lam/templates/lib/misc/ajax.php?function=webauth ...
show more
64.112.56.58 - - [30/Jul/2026:21:38:22 +0700] "GET /lam/templates/lib/misc/ajax.php?function=webauthn' HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
...
show less
Web App Attack
🇱🇺
conseilgouz
2026-07-28 09:59:27
(1 month ago)
are-12 : Block return, carriage return, ... characters=>/?task=suggestions.suggest&format=json&a ...
show more
are-12 : Block return, carriage return, ... characters=>/?task=suggestions.suggest&format=json&tmpl=component'&Itemid=103(')
show less
Hacking
🇩🇪
conseilgouz
2026-07-27 14:13:02
(1 month ago)
ece-12 : Block return, carriage return, ... characters=>/media/astroid/js/offcanvas.min.js?7ea5d6=&# ...
show more
ece-12 : Block return, carriage return, ... characters=>/media/astroid/js/offcanvas.min.js?7ea5d6='(')
show less
Hacking
🇺🇸
nodepile
2026-07-24 07:19:33
(1 month ago)
Requests denied due to active blacklist hits (tenant=82 method=GET path=/angel-eyes/audi.html ua='Mo ...
show more
Requests denied due to active blacklist hits (tenant=82 method=GET path=/angel-eyes/audi.html ua='Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36')
show less
Web App Attack
Exploited Host
🇺🇸
ipblock.com
2026-07-19 00:17:00
(1 month ago)
IPBlock protected site ID [4730-fr].
Exploit request, vulnerability probe.
Hacking
Bad Web Bot
Web App Attack
🇺🇸
ipblock.com
2026-07-18 23:07:00
(1 month ago)
IPBlock protected site ID [4055-d][s=06].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
🇺🇸
ipblock.com
2026-07-17 13:07:00
(1 month ago)
IPBlock protected site ID [4055-d][s=06].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
🇺🇸
ipblock.com
2026-07-17 10:03:00
(1 month ago)
IPBlock protected site ID [4055-d][s=02].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TheJimmo
2026-07-16 13:47:01
(1 month ago)
64.112.56.58 64.112.56.58 - - [16/Jul/2026:13:45:36 +0000] "GET /administrator/components/com_joomla ...
show more
64.112.56.58 64.112.56.58 - - [16/Jul/2026:13:45:36 +0000] "GET /administrator/components/com_joomla-visites/core/include/myMailer.class.php?mosConfig_absolute_path=../../../../../../../../../../../../etc/passwd HTTP/1.1" 404 13524 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
64.112.56.58 64.112.56.58 - - [16/Jul/2026:13:45:40 +0000] "POST /module/ HTTP/1.1" 404 13346 "https://foreverpontiac.comadmin/view:modules/load_module:users" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
64.112.56.58 64.112.56.58 - - [16/Jul/2026:13:45:45 +0000] "POST /wp-login.php HTTP/1.1" 404 13352 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
64.112.56.58 64.112.56.58 - - [16/Jul/2026:13:45:45 +0000] "GET /document%3F__report=test.rptdesign&sample=%3C%25out.println%28%22Z5BFilaMwiHF
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-07-15 14:36:50
(1 month ago)
[Drupal AbuseIPDB module] Request path is blacklisted. /wp-admin/admin-ajax.php
Web App Attack