๐ณ๐ฑ
TCATERDSBE
2026-08-17 14:40:00
(3 days ago)
SQL Injection
SQL Injection
๐บ๐ธ
integrantservices.com
2026-08-07 01:40:24
(2 weeks ago)
(wordpress) Failed wordpress login from 64.112.57.149 (US/United States/-)
Brute-Force
๐ธ๐ฎ
administrator
2026-08-05 22:02:38
(2 weeks ago)
2026-08-04 06:21:31,439 fail2ban.actions [1590202]: NOTICE [apache-badbots] Ban 64.112.57.14 ...
show more
2026-08-04 06:21:31,439 fail2ban.actions [1590202]: NOTICE [apache-badbots] Ban 64.112.57.149
2026-08-04 06:21:31,439 fail2ban.actions [1590202]: NOTICE [apache-badbots] Ban 64.112.57.149
2026-08-04 06:21:31,439 fail2ban.actions [1590202]: NOTICE [apache-badbots] Ban 64.112.57.149
...
show less
Bad Web Bot
Web Spam
Email Spam
Blog Spam
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-05 18:52:34
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 64.112.57.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 64.112.57.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 05 14:52:19.022897 2026] [security2:error] [pid 3813353:tid 3813357] [client 64.112.57.149:39381] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "americanacademyofprojectmanagement.com"] [uri "/.env.stage"] [unique_id "anOGY5Ydk_wiAEbK_FMw8gAAAMI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
KIDOS
2026-08-05 05:17:16
(2 weeks ago)
IIS malicious activity: sql_injection_attempt
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-04 06:26:20
(2 weeks ago)
(mod_security) mod_security (id:212620) triggered by 64.112.57.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:212620) triggered by 64.112.57.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 04 02:25:48.119196 2026] [security2:error] [pid 1357664:tid 1357664] [client 64.112.57.149:32953] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||www.powerkiteforum.com|F|2"] [data "Matched Data: <script found within REQUEST_URI: /misc.php?action=list<scr<script>ipt>alert(qsxss9k7z)</scr</script>ipt>&desc"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "www.powerkiteforum.com"] [uri "/misc.php"] [unique_id "anGF7BhPvcYrwX_NmjFnJAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-08-04 04:14:30
(2 weeks ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐บ๐ธ
tropicalidad.be
2026-08-03 17:24:15
(2 weeks ago)
blog spam/exploit attempt
Blog Spam
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-03 16:07:13
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 64.112.57.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 64.112.57.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 12:07:03.622618 2026] [security2:error] [pid 55195:tid 55195] [client 64.112.57.149:47395] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.laboquimia.es"] [uri "/.env.bak"] [unique_id "anC8p2FU3pgc3WgompwZhAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ipblock.com
2026-08-03 09:39:00
(2 weeks ago)
IPBlock protected site ID [4055-d][s=06].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
ipblock.com
2026-07-31 16:54:00
(2 weeks ago)
IPBlock protected site ID [4055-d][s=06].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
Reinhard
2026-07-26 05:44:53
(3 weeks ago)
Unknown activity, but too many attacks with too many users.
Hacking
๐ฉ๐ช
iGroupware
2026-07-25 23:50:09
(3 weeks ago)
{"req/ip"=>{:discriminator=>"64.112.57.149", :count=>1, :period=>180, :limit=>500, :epoch_time=>1785 ...
show more
{"req/ip"=>{:discriminator=>"64.112.57.149", :count=>1, :period=>180, :limit=>500, :epoch_time=>1785023409}, "signups/ip"=>{:discriminator=>"64.112.57.149", :count=>1, :period=>3600, :limit=>5, :epoch_time=>1785023409}, "signups/email"=>{:discriminator=>"[email protected] ", :count=>4, :period=>86400, :limit=>2, :epoch_time=>1785023409}}
show less
Web App Attack
๐บ๐ธ
nodepile
2026-07-24 07:19:19
(4 weeks ago)
Requests denied due to active blacklist hits (tenant=82 method=POST path=/checkout/cart/add/uenc/aHR ...
show more
Requests denied due to active blacklist hits (tenant=82 method=POST path=/checkout/cart/add/uenc/aHR0cHM6Ly91bW5pdHphLmNvbS9hbmdlbC1leWVzL2tpYS5odG1sP3ByaWNlPQ~~/product/6489/ ua='Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36')
show less
Web App Attack
Exploited Host
๐ฉ๐ช
raph
2026-07-22 12:54:33
(4 weeks ago)
[001] honeypot form submission
Web Spam
Blog Spam