๐ฉ๐ช
Vegascosmetics
2026-09-24 07:36:09
(18 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after locale-probe / error-handler fuzzing ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after locale-probe / error-handler fuzzing against ASP.NET shop. Evidence: AttackPattern: /Geral/(ChangeCountry|ChooseCountrie|ChangeCulture).*currentUrl=.{180,} (Match: /geral/changeculture lingua=pt¤turl=...
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TIScore
2026-09-24 05:20:47
(20 hours ago)
Automated web attack / probing. Signals: Unexpected path. Last path: /wp-sitemap.xml
Web App Attack
๐บ๐ธ
HamSammich
2026-09-23 02:27:25
(1 day ago)
Automated sensor: 1 HTTPS connection/probe attempts over the last 24h (latest 2026-09-23T02:27Z).
Brute-Force
Web App Attack
๐ฉ๐ช
LRob
2026-09-22 20:23:28
(2 days ago)
This address requests our sites over plain http, is answered with a redirect to https, and never fol ...
show more
This address requests our sites over plain http, is answered with a redirect to https, and never follows it โ over and over. A browser follows redirects; a scanner enumerating hosts does not. It reads nothing it asks for and only loads the server; blocked. Please check what runs on this address. | method: GET | path: / | 2026-09-22 20:23 UTC
show less
Bad Web Bot
๐บ๐ธ
HamSammich
2026-09-21 18:59:11
(3 days ago)
Automated sensor: 1 HTTPS connection/probe attempts over the last 24h (latest 2026-09-21T18:59Z).
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 06:13:59
(3 days ago)
(mod_security) mod_security (id:217210) triggered by 72.1.138.29 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:217210) triggered by 72.1.138.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 02:13:51.840930 2026] [security2:error] [pid 23840:tid 23840] [client 72.1.138.29:53331] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||brandintellectgh.com|F|4"] [data "GET ?c=n;o=d HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "brandintellectgh.com"] [uri "/"] [unique_id "arDLH1FtvgbwCzI0Z2GOUwAAAAk"], referer: https://brandintellectgh.com/wp-sitemap.xml
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 23:32:05
(4 days ago)
(mod_security) mod_security (id:217210) triggered by 72.1.138.29 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:217210) triggered by 72.1.138.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:31:58.961537 2026] [security2:error] [pid 3368:tid 3368] [client 72.1.138.29:35783] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||darkcodeverse.com|F|4"] [data "GET ?c=n;o=d HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "darkcodeverse.com"] [uri "/"] [unique_id "arBs7lOSzOJKoh9U5q4VLgAAAAI"], referer: https://darkcodeverse.com/wp-sitemap.xml
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 01:56:42
(5 days ago)
(mod_security) mod_security (id:217210) triggered by 72.1.138.29 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:217210) triggered by 72.1.138.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 21:56:38.023972 2026] [security2:error] [pid 26248:tid 26344] [client 72.1.138.29:51741] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||jevan1.com|F|4"] [data "GET ?c=n;o=d HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "jevan1.com"] [uri "/"] [unique_id "aq89VoBwQPnDgRCM2ArXqAAAAVY"], referer: https://jevan1.com/wp-sitemap.xml
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
HamSammich
2026-09-15 22:30:14
(1 week ago)
Automated sensor: 1 HTTPS connection/probe attempts over the last 24h (latest 2026-09-15T22:30Z).
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 05:09:33
(1 week ago)
(mod_security) mod_security (id:217210) triggered by 72.1.138.29 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:217210) triggered by 72.1.138.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 01:09:30.214089 2026] [security2:error] [pid 1934:tid 1934] [client 72.1.138.29:51137] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||israelartifact.com|F|4"] [data "GET ?c=n;o=d HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "israelartifact.com"] [uri "/"] [unique_id "aqeBirW6nFMrzLnAuHjmYgAAAAg"], referer: https://israelartifact.com/wp-sitemap.xml
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-12 08:58:55
(1 week ago)
(mod_security) mod_security (id:217210) triggered by 72.1.138.29 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:217210) triggered by 72.1.138.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 04:58:51.039320 2026] [security2:error] [pid 19770:tid 19770] [client 72.1.138.29:41553] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||reconsideringfear.com|F|4"] [data "GET ?c=n;o=d HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "reconsideringfear.com"] [uri "/"] [unique_id "aqUUS0CyUt5jkiT9QHRKDwAAAAY"], referer: https://reconsideringfear.com/wp-sitemap.xml
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ParaBug
2026-09-11 20:06:01
(1 week ago)
72.1.138.29 - - [11/Sep/2026:22:06:01 +0200] "GET /wp-sitemap.xml HTTP/1.1" 404 4476 "https://antik- ...
show more
72.1.138.29 - - [11/Sep/2026:22:06:01 +0200] "GET /wp-sitemap.xml HTTP/1.1" 404 4476 "https://antik-wagon.com/wp-sitemap.xml" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.0.0 Safari/537.3"
...
show less
Phishing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 02:22:20
(1 week ago)
(mod_security) mod_security (id:217210) triggered by 72.1.138.29 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:217210) triggered by 72.1.138.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 22:22:17.230726 2026] [security2:error] [pid 1947:tid 1967] [client 72.1.138.29:36423] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||ureseal.com|F|4"] [data "GET ?c=s;o=a HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "ureseal.com"] [uri "/"] [unique_id "aqNl2abJcAvq5WSsO6r_0QAAABA"], referer: https://ureseal.com?c=m;o=a
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
interbiznw.com
2026-09-10 18:36:04
(2 weeks ago)
fail2ban-ban
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-10 16:42:03
(2 weeks ago)
(mod_security) mod_security (id:217210) triggered by 72.1.138.29 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:217210) triggered by 72.1.138.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 12:41:57.742914 2026] [security2:error] [pid 6780:tid 6780] [client 72.1.138.29:43651] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||egrabbagsale.com|F|4"] [data "GET ?c=s;o=a HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "egrabbagsale.com"] [uri "/"] [unique_id "aqLd1cAHn9yVaPrCvNUyewAAAAQ"], referer: https://egrabbagsale.com?c=m;o=a
show less
Brute-Force
Bad Web Bot
Web App Attack