๐บ๐ธ
integrantservices.com
2026-08-07 01:40:46
(3 weeks ago)
(wordpress) Failed wordpress login from 64.112.57.165 (US/United States/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-04 05:47:06
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 64.112.57.165 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 64.112.57.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 04 01:46:40.210519 2026] [security2:error] [pid 3304720:tid 3304720] [client 64.112.57.165:58355] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "med-engineering.com"] [uri "/.env.local"] [unique_id "anF8wLJcKx5eYlJS5QlKjwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-04 02:39:25
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 64.112.57.165 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 64.112.57.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 22:39:05.300977 2026] [security2:error] [pid 12742:tid 12742] [client 64.112.57.165:59125] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jwwsb.jaspercity.com"] [uri "/.env.stage"] [unique_id "anFQyQMJBEjLOHxVHZ_00QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-03 21:43:52
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 64.112.57.165 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 64.112.57.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 17:43:29.894306 2026] [security2:error] [pid 935887:tid 935887] [client 64.112.57.165:44381] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.old.renju.net"] [uri "/.env.production"] [unique_id "anELgR1n8DnxANm68yErlQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-03 20:40:08
(4 weeks ago)
(mod_security) mod_security (id:212620) triggered by 64.112.57.165 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:212620) triggered by 64.112.57.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 16:39:46.660017 2026] [security2:error] [pid 213852:tid 213875] [client 64.112.57.165:60905] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||www.uoexpanse.com|F|2"] [data "Matched Data: <script found within REQUEST_URI: /forums/viewtopic.php?t=57&p=63'\\x22></title></style></textarea></script><script>alert(qsxss9k7z)</script>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "www.uoexpanse.com"] [uri "/forums/viewtopic.php"] [unique_id "anD8knyysjeCjexCNTYGGAAAAFM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-03 17:35:05
(4 weeks ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
tropicalidad.be
2026-08-03 17:24:14
(4 weeks ago)
blog spam/exploit attempt
Blog Spam
Hacking
๐บ๐ธ
ipblock.com
2026-08-03 09:36:00
(4 weeks ago)
IPBlock protected site ID [4055-d][s=06].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
ipblock.com
2026-07-31 16:49:00
(1 month ago)
IPBlock protected site ID [4055-d][s=06].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
conseilgouz
2026-07-27 14:12:37
(1 month ago)
ece-12 : Block return, carriage return, ... characters=>/plan-du-site?view=html&amp='(')
Hacking
๐ฉ๐ช
iGroupware
2026-07-25 23:50:09
(1 month ago)
{"req/ip"=>{:discriminator=>"64.112.57.165", :count=>1, :period=>180, :limit=>500, :epoch_time=>1785 ...
show more
{"req/ip"=>{:discriminator=>"64.112.57.165", :count=>1, :period=>180, :limit=>500, :epoch_time=>1785023409}, "signups/ip"=>{:discriminator=>"64.112.57.165", :count=>1, :period=>3600, :limit=>5, :epoch_time=>1785023409}, "signups/email"=>{:discriminator=>"[email protected] ", :count=>3, :period=>86400, :limit=>2, :epoch_time=>1785023409}}
show less
Web App Attack
๐บ๐ธ
nodepile
2026-07-25 11:27:53
(1 month ago)
Requests denied due to active blacklist hits (tenant=82 method=POST path=/checkout/cart/add/uenc/aHR ...
show more
Requests denied due to active blacklist hits (tenant=82 method=POST path=/checkout/cart/add/uenc/aHR0cHM6Ly91bW5pdHphLmNvbS93aGVlbHMuaHRtbD9jYXQ9/product/11588/ ua='Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36')
show less
Web App Attack
Exploited Host
๐ญ๐บ
zolav8
2026-07-24 10:28:32
(1 month ago)
Excessive crawling
Bad Web Bot
๐บ๐ธ
ipblock.com
2026-07-18 22:43:00
(1 month ago)
IPBlock protected site ID [4055-d][s=07].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐ฎ๐ฑ
spd.co.il
2026-07-17 14:02:16
(1 month ago)
Web application attack detected
Hacking
Web App Attack