🇺🇸
integrantservices.com
2026-08-07 01:40:37
(4 weeks ago)
(wordpress) Failed wordpress login from 64.112.56.50 (US/United States/-)
Brute-Force
🇺🇸
TPI-Abuse
2026-08-05 18:47:59
(1 month ago)
(mod_security) mod_security (id:212620) triggered by 64.112.56.50 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:212620) triggered by 64.112.56.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 05 14:47:43.908033 2026] [security2:error] [pid 3828832:tid 3828856] [client 64.112.56.50:57345] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||americanacademyofprojectmanagement.com|F|2"] [data "Matched Data: <script found within REQUEST_URI: /pageb214.html?pg=sitemap<scr<script>ipt>alert(qsxss9k7z)</scr</script>ipt>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "americanacademyofprojectmanagement.com"] [uri "/pageb214.html"] [unique_id "anOFT0nnv4Hua8dSeTPMBAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
london2038.com
2026-08-04 08:57:12
(1 month ago)
Malformed or malicious web request
64.112.56.50 - - [04/Aug/2026:10:56:48 +0200] "GET /c/site-feedba ...
show more
Malformed or malicious web request
64.112.56.50 - - [04/Aug/2026:10:56:48 +0200] "GET /c/site-feedback/3?page=1' HTTP/2.0" 400 13356 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
show less
Hacking
Web App Attack
🇫🇷
conseilgouz
2026-08-04 00:54:13
(1 month ago)
sae-6 : Trying access system files=>/.env.prod(htaccessphp)
Hacking
🇺🇸
TPI-Abuse
2026-08-04 00:14:36
(1 month ago)
(mod_security) mod_security (id:212750) triggered by 64.112.56.50 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:212750) triggered by 64.112.56.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 20:14:20.482109 2026] [security2:error] [pid 2860356:tid 2860356] [client 64.112.56.50:40371] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\bon(?:abort|blur|change|click|dblclick|dragdrop|error|focus|keydown|keypress|keyup|load|mouse(?:down|move|out|over|up)|move|readystatechange|reset|resize|select|submit|unload)\\\\b[^a-zA-Z0-9_]{0,}?=" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "69"] [id "212750"] [rev "3"] [msg "COMODO WAF: XSS Attack Detected||med-engineering.com|F|2"] [data "Matched Data: onload= found within REQUEST_URI: /component/k2/item/2/2.html?start=90480\\x22><svg onload=alert(qsxss9k7z)>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "med-engineering.com"] [uri "/component/k2/item/2/2.html"] [unique_id "anEu3MY2hIxhEO4zMa2GdwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-03 21:43:54
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 64.112.56.50 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 64.112.56.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 17:43:29.895311 2026] [security2:error] [pid 935890:tid 935890] [client 64.112.56.50:45005] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.old.renju.net"] [uri "/.env.bak"] [unique_id "anELgYNHn0-poSUw4ZoNNgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
ipblock.com
2026-08-03 09:37:00
(1 month ago)
IPBlock protected site ID [4055-d][s=06].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
🇺🇸
Matthew Ping
2026-08-01 14:45:07
(1 month ago)
ModSecurity rule 949110 triggered on d865. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
🇺🇸
ipblock.com
2026-07-31 16:58:00
(1 month ago)
IPBlock protected site ID [4055-d][s=06].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
🇷🇺
Mga Admin
2026-07-30 14:38:14
(1 month ago)
64.112.56.50 - - [30/Jul/2026:21:38:13 +0700] "GET /lam/templates/lib/multiEdit.php?ajaxStatus=' HTT ...
show more
64.112.56.50 - - [30/Jul/2026:21:38:13 +0700] "GET /lam/templates/lib/multiEdit.php?ajaxStatus=' HTTP/1.1" 404 16 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
...
show less
Web App Attack
🇺🇸
ipblock.com
2026-07-26 03:40:00
(1 month ago)
IPBlock protected site ID [4730-fr].
Exploit request, vulnerability probe.
Hacking
Bad Web Bot
Web App Attack
🇩🇪
Vegascosmetics
2026-07-22 22:43:39
(1 month ago)
(Kingcopy.org-AI-IDS-Report):IP automatically blocked after suspicious activity. Vegas Security
DDoS Attack
Hacking
Exploited Host
🇺🇸
ipblock.com
2026-07-18 22:40:00
(1 month ago)
IPBlock protected site ID [4055-d][s=07].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
🇺🇸
ipblock.com
2026-07-17 10:03:00
(1 month ago)
IPBlock protected site ID [4055-d][s=07].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TheJimmo
2026-07-16 13:46:49
(1 month ago)
64.112.56.50 64.112.56.50 - - [16/Jul/2026:13:45:35 +0000] "GET /index.php?option=com_perchacategori ...
show more
64.112.56.50 64.112.56.50 - - [16/Jul/2026:13:45:35 +0000] "GET /index.php?option=com_perchacategoriestree&controller=../../../../../../../../../../etc/passwd%00 HTTP/1.1" 404 13593 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
64.112.56.50 64.112.56.50 - - [16/Jul/2026:13:45:36 +0000] "GET /resource/file%3a///etc/passwd/ HTTP/1.1" 404 13385 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
64.112.56.50 64.112.56.50 - - [16/Jul/2026:13:45:38 +0000] "GET /device.rsp?opt=user&cmd=list HTTP/1.1" 404 13374 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
64.112.56.50 64.112.56.50 - - [16/Jul/2026:13:45:38 +0000] "POST /dologin.action HTTP/1.1" 404 13355 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari
...
show less
Bad Web Bot
Web App Attack