🇺🇸
integrantservices.com
2026-08-07 01:40:36
(1 month ago)
(wordpress) Failed wordpress login from 64.112.57.166 (US/United States/-)
Brute-Force
🇺🇸
TPI-Abuse
2026-08-04 06:27:05
(1 month ago)
(mod_security) mod_security (id:212750) triggered by 64.112.57.166 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:212750) triggered by 64.112.57.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 04 02:26:07.209989 2026] [security2:error] [pid 1357684:tid 1357684] [client 64.112.57.166:35705] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\bon(?:abort|blur|change|click|dblclick|dragdrop|error|focus|keydown|keypress|keyup|load|mouse(?:down|move|out|over|up)|move|readystatechange|reset|resize|select|submit|unload)\\\\b[^a-zA-Z0-9_]{0,}?=" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "69"] [id "212750"] [rev "3"] [msg "COMODO WAF: XSS Attack Detected||www.powerkiteforum.com|F|2"] [data "Matched Data: onerror= found within REQUEST_URI: /index.php?gid=45\\x22><img src=x onerror=alert(qsxss9k7z)>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "www.powerkiteforum.com"] [uri "/index.php"] [unique_id "anGF_zL7WfTNW4vOSvG7ewAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-03 22:44:23
(1 month ago)
(mod_security) mod_security (id:212620) triggered by 64.112.57.166 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:212620) triggered by 64.112.57.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 18:44:01.851143 2026] [security2:error] [pid 1193168:tid 1193168] [client 64.112.57.166:37055] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||www.bassboatmagazine.com|F|2"] [data "Matched Data: <script found within REQUEST_URI: /advertisebbm/gotourl.php?id=5'\\x22></title></style></textarea></script><script>alert(qsxss9k7z)</script>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "www.bassboatmagazine.com"] [uri "/advertiseBBM/gotourl.php"] [unique_id "anEZsQq_ox79Ah0_KPi_OQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-03 20:18:21
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 64.112.57.166 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 64.112.57.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 16:18:00.480912 2026] [security2:error] [pid 3351892:tid 3351892] [client 64.112.57.166:37003] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thegoldentether.com"] [uri "/.env.dev"] [unique_id "anD3eAWFPPpaDsjoUwXiiQAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
ipblock.com
2026-08-03 14:46:00
(1 month ago)
IPBlock protected site ID [3192-af][s=06].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
🇵🇱
nfsec.pl
2026-08-01 14:29:00
(1 month ago)
64.112.57.166 - - [01/Aug/2026:14:28:47 +0000] "GET /wp-includes/js/mediaelement/ HTTP/2.0" 403 1701 ...
show more
64.112.57.166 - - [01/Aug/2026:14:28:47 +0000] "GET /wp-includes/js/mediaelement/ HTTP/2.0" 403 1701 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
64.112.57.166 - - [01/Aug/2026:14:28:51 +0000] "GET /wp-includes/js/crop/ HTTP/2.0" 403 1701 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
64.112.57.166 - - [01/Aug/2026:14:28:57 +0000] "GET /admin/editor/ HTTP/2.0" 404 24879 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
64.112.57.166 - - [01/Aug/2026:14:28:59 +0000] "GET /vendor/phpunit/phpunit/src/Util/PHP/ HTTP/2.0" 404 24267 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
64.112.57.166 - - [01/Aug/2026:14:28:59 +0000] "GET /admin/controller/extension/extension/ HTTP/2.0" 404 24381 "-
...
show less
Web App Attack
Exploited Host
🇧🇪
cmbplf
2026-08-01 05:22:30
(1 month ago)
2.103 requests from abuseipdb.com blacklisted IP (1yr6mos2w)
Brute-Force
Bad Web Bot
🇮🇩
bps-statistics
2026-07-30 13:46:09
(1 month ago)
Web Application Attacks
Web App Attack
🇱🇺
conseilgouz
2026-07-28 10:00:02
(1 month ago)
are-12 : Block return, carriage return, ... characters=>/media/plg_system_mobilemenuck/assets/mobile ...
show more
are-12 : Block return, carriage return, ... characters=>/media/plg_system_mobilemenuck/assets/mobilemenuck.js?ver=1.7.1'(')
show less
Hacking
🇩🇪
Reinhard
2026-07-26 05:59:29
(1 month ago)
Unknown activity, but too many attacks with too many users.
Hacking
🇺🇸
ipblock.com
2026-07-26 03:13:00
(1 month ago)
IPBlock protected site ID [4730-fr].
Exploit request, vulnerability probe.
Hacking
Bad Web Bot
Web App Attack
🇩🇪
iGroupware
2026-07-25 23:50:10
(1 month ago)
{"req/ip"=>{:discriminator=>"64.112.57.166", :count=>1, :period=>180, :limit=>500, :epoch_time=>1785 ...
show more
{"req/ip"=>{:discriminator=>"64.112.57.166", :count=>1, :period=>180, :limit=>500, :epoch_time=>1785023410}, "signups/ip"=>{:discriminator=>"64.112.57.166", :count=>1, :period=>3600, :limit=>5, :epoch_time=>1785023410}, "signups/email"=>{:discriminator=>"[email protected] ", :count=>32, :period=>86400, :limit=>2, :epoch_time=>1785023410}}
show less
Web App Attack
🇺🇸
nodepile
2026-07-25 11:27:53
(1 month ago)
Requests denied due to active blacklist hits (tenant=82 method=POST path=/checkout/cart/add/uenc/aHR ...
show more
Requests denied due to active blacklist hits (tenant=82 method=POST path=/checkout/cart/add/uenc/aHR0cHM6Ly91bW5pdHphLmNvbS93aGVlbHMuaHRtbD9jYXQ9/product/11588/ ua='Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36')
show less
Web App Attack
Exploited Host
🇺🇸
Penny Packer
2026-07-23 10:26:07
(1 month ago)
Fail2Ban apache-tripwires
Web App Attack
🇨🇿
ptlab
2026-07-21 20:45:06
(1 month ago)
Detected xmlrpc_brute attack from WP-host.
Hacking
Web App Attack