🇳🇱
TCATERDSBE
2026-08-17 15:14:00
(3 weeks ago)
SQL Injection
SQL Injection
🇺🇸
integrantservices.com
2026-08-07 01:40:48
(1 month ago)
(wordpress) Failed wordpress login from 64.112.57.188 (US/United States/-)
Brute-Force
Anonymous
2026-08-04 01:18:30
(1 month ago)
"GET /.env.production.local HTTP/1.1"
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-03 22:33:10
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 64.112.57.188 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 64.112.57.188 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 18:32:47.726815 2026] [security2:error] [pid 279826:tid 279828] [client 64.112.57.188:39619] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.uoexpanse.com"] [uri "/.env.prod.local"] [unique_id "anEXD0HH4ZklvPbe1Qs8iQAAAMA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-03 18:28:08
(1 month ago)
(mod_security) mod_security (id:212620) triggered by 64.112.57.188 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:212620) triggered by 64.112.57.188 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 14:27:39.469373 2026] [security2:error] [pid 561326:tid 561326] [client 64.112.57.188:41469] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||3905ccn.org|F|2"] [data "Matched Data: <script found within REQUEST_URI: /ncscalendar.php?year=2025&action=go&month=01<scr<script>ipt>alert(qsxss9k7z)</scr</script>ipt>&band=[all]&mode=[all]&ncscallsign=[all]"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "3905ccn.org"] [uri "/ncsCalendar.php"] [unique_id "anDdm6GUwX2CWJF4dp_PTgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-03 16:07:11
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 64.112.57.188 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 64.112.57.188 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 12:07:03.685627 2026] [security2:error] [pid 56088:tid 56088] [client 64.112.57.188:50321] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.laboquimia.es"] [uri "/.env.production.local"] [unique_id "anC8p1gbLHF9wJioxv8BfwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-03 15:27:28
(1 month ago)
(mod_security) mod_security (id:212620) triggered by 64.112.57.188 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:212620) triggered by 64.112.57.188 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 11:27:10.423839 2026] [security2:error] [pid 3832857:tid 3832857] [client 64.112.57.188:54151] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||watermarks.info|F|2"] [data "Matched Data: <script found within REQUEST_URI: /bus.php?tx&a=s&t=a&s=7'\\x22></title></style></textarea></script><script>alert(qsxss9k7z)</script>&db=i&i=on&o=n&c&pw=on&v=0&n=20&sk=0&l=i"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "watermarks.info"] [uri "/bus.php"] [unique_id "anCzTp6o3FBAFBvxwD-9YwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-03 14:54:44
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 64.112.57.188 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 64.112.57.188 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 10:54:26.354721 2026] [security2:error] [pid 301162:tid 301162] [client 64.112.57.188:55667] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.powerkiteforum.com"] [uri "/.env.production.local"] [unique_id "anCrop_WUHMtepVaH8lV4QAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
ipblock.com
2026-08-03 09:36:00
(1 month ago)
IPBlock protected site ID [4055-d][s=07].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-08-01 05:20:16
(1 month ago)
2.060 requests from abuseipdb.com blacklisted IP (3mos3w3d)
Brute-Force
Bad Web Bot
🇳🇱
Mangelot Hosting
2026-07-30 23:36:48
(1 month ago)
(db_admin_scan) srv103 Database Admin Scan 64.112.57.188 (US/United States/-): 1 in the last 3600 se ...
show more
(db_admin_scan) srv103 Database Admin Scan 64.112.57.188 (US/United States/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
🇧🇷
websecuritylabs
2026-07-29 20:23:57
(1 month ago)
Web App Attack
Web App Attack
🇱🇺
conseilgouz
2026-07-28 09:59:36
(1 month ago)
are-12 : Block return, carriage return, ... characters=>/?view=article'&amp(')
Hacking
🇺🇸
ipblock.com
2026-07-26 03:40:00
(1 month ago)
IPBlock protected site ID [4730-fr].
Exploit request, vulnerability probe.
Hacking
Bad Web Bot
Web App Attack
🇺🇸
nodepile
2026-07-25 11:27:50
(1 month ago)
Requests denied due to active blacklist hits (tenant=82 method=POST path=/checkout/cart/add/uenc/aHR ...
show more
Requests denied due to active blacklist hits (tenant=82 method=POST path=/checkout/cart/add/uenc/aHR0cHM6Ly91bW5pdHphLmNvbS93aGVlbHMuaHRtbD9jYXQ9/product/11780/ ua='Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36')
show less
Web App Attack
Exploited Host