🇺🇸
integrantservices.com
2026-08-07 01:40:39
(4 weeks ago)
(wordpress) Failed wordpress login from 64.112.57.179 (US/United States/-)
Brute-Force
🇸🇪
KIDOS
2026-08-04 10:18:34
(1 month ago)
IIS malicious activity: sql_injection_attempt
Web App Attack
🇺🇸
TPI-Abuse
2026-08-04 05:47:02
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 64.112.57.179 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 64.112.57.179 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 04 01:46:40.214728 2026] [security2:error] [pid 3296632:tid 3296632] [client 64.112.57.179:50613] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "med-engineering.com"] [uri "/.env.development.local"] [unique_id "anF8wBXLGTmA_iqaSbWlaQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-04 02:39:25
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 64.112.57.179 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 64.112.57.179 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 22:39:04.573340 2026] [security2:error] [pid 4310:tid 4310] [client 64.112.57.179:55885] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jwwsb.jaspercity.com"] [uri "/.env.bak"] [unique_id "anFQyNgNa4JZ9Os2sNFPmQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-03 20:40:04
(1 month ago)
(mod_security) mod_security (id:212620) triggered by 64.112.57.179 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:212620) triggered by 64.112.57.179 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 16:39:46.665130 2026] [security2:error] [pid 202445:tid 202450] [client 64.112.57.179:45089] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||www.uoexpanse.com|F|2"] [data "Matched Data: <script found within REQUEST_URI: /forums/viewtopic.php?t=57<scr<script>ipt>alert(qsxss9k7z)</scr</script>ipt>&p=63"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "www.uoexpanse.com"] [uri "/forums/viewtopic.php"] [unique_id "anD8kqDME1DBjgXc_5OpsAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-03 14:54:46
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 64.112.57.179 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 64.112.57.179 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 10:54:26.334321 2026] [security2:error] [pid 300641:tid 300641] [client 64.112.57.179:44309] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.powerkiteforum.com"] [uri "/.env.dev.local"] [unique_id "anCrojvBD75xYi1PaOvMTwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Matthew Ping
2026-08-01 14:45:19
(1 month ago)
ModSecurity rule 949110 triggered on d865. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
🇮🇱
spd.co.il
2026-07-28 23:03:18
(1 month ago)
Web application attack detected
Hacking
Web App Attack
🇱🇺
conseilgouz
2026-07-28 09:59:31
(1 month ago)
are-12 : Block return, carriage return, ... characters=>/component/contact/contact/4-nicole-luc-jacq ...
show more
are-12 : Block return, carriage return, ... characters=>/component/contact/contact/4-nicole-luc-jacque?Itemid=108&amp;catid=4'(')
show less
Hacking
🇩🇪
conseilgouz
2026-07-27 14:13:11
(1 month ago)
ece-12 : Block return, carriage return, ... characters=>/media/system/js/multiselect.min.js?b135d0=& ...
show more
ece-12 : Block return, carriage return, ... characters=>/media/system/js/multiselect.min.js?b135d0='(')
show less
Hacking
🇺🇸
Penny Packer
2026-07-23 09:01:15
(1 month ago)
Fail2Ban apache-tripwires
Web App Attack
🇩🇪
raph
2026-07-22 14:50:28
(1 month ago)
[001] honeypot form submission
Web Spam
Blog Spam
🇬🇧
SilverZippo
2026-07-20 10:30:58
(1 month ago)
Web App Attack
Web App Attack
🇺🇸
ipblock.com
2026-07-18 22:47:00
(1 month ago)
IPBlock protected site ID [955-wdo][s=11].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
🇫🇷
conseilgouz
2026-07-18 18:51:16
(1 month ago)
joe-12 : Block return, carriage return, ... characters=>/media/vendor/accessibility/js/accessibility ...
show more
joe-12 : Block return, carriage return, ... characters=>/media/vendor/accessibility/js/accessibility.min.js?3.0.17='(')
show less
Hacking