This IP address has been reported a total of
7
times from
3 distinct
sources.
64.64.115.218 was first reported on
January 24th 2025 , and the most recent report was
4 days ago .
In the last 60 days, the only reporter location was:
Switzerland
with 1
report.
The only category in these recent reports was:
Hacking
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐จ๐ญ
Kepler-1649c
2026-09-22 10:06:55
(4 days ago)
Detected Attack: Generic.Path.Traversal.Detection
Hacking
๐บ๐ธ
TPI-Abuse
2025-12-29 20:38:07
(8 months ago)
(mod_security) mod_security (id:221260) triggered by 64.64.115.218 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:221260) triggered by 64.64.115.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 15:37:51.067538 2025] [security2:error] [pid 21770:tid 21781] [client 64.64.115.218:38047] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "77"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||www.kettlehill.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kettlehill.net"] [uri "/test.cgi"] [unique_id "aVLmn-1IUNfWG5lsn0GbLwAAAYg"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-01 06:12:43
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 64.64.115.218 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 64.64.115.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 01:12:27.978636 2025] [security2:error] [pid 8488:tid 8574] [client 64.64.115.218:53523] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "staging.kettlehill.com"] [uri "/.env.www.staging"] [unique_id "aS0xy9ZHHfu_5jcVG6pjcwAAAZM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-05 19:06:57
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 64.64.115.218 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 64.64.115.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 05 15:06:46.125110 2025] [security2:error] [pid 27029:tid 27029] [client 64.64.115.218:40401] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.nbcnewsradio.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.nbcnewsradio.com"] [uri "/error.log"] [unique_id "aJJWRvPLF960a_IGvAjmngAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-27 00:23:35
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 64.64.115.218 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 64.64.115.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 26 20:23:19.483768 2025] [security2:error] [pid 172226:tid 172444] [client 64.64.115.218:50587] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.kettlehill.com"] [uri "/.env.prod.local"] [unique_id "aIVxd36EtJKYjh039Gs-TwAAAIU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-29 19:34:19
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 64.64.115.218 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 64.64.115.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 29 15:34:07.223448 2025] [security2:error] [pid 3260716:tid 3260716] [client 64.64.115.218:48565] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.farmers123.com"] [uri "/.env.bak"] [unique_id "aDi2rxIN5kURpADVbPrWWQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-01-24 18:40:42
(1 year ago)
| Common web attack.
Hacking
SQL Injection
Web App Attack
Showing 1 to
7
of 7 reports