🇺🇸
interbiznw.com
2026-09-05 17:10:53
(19 hours ago)
fail2ban-ban
Hacking
Brute-Force
Exploited Host
Web App Attack
🇺🇸
TIScore
2026-09-04 08:07:54
(2 days ago)
Automated web attack / probing. Signals: Unexpected path. Last path: /wp-sitemap.xml
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 19:57:41
(2 days ago)
(mod_security) mod_security (id:217210) triggered by 72.1.158.127 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:217210) triggered by 72.1.158.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 15:57:35.018637 2026] [security2:error] [pid 3189:tid 3189] [client 72.1.158.127:44311] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||jcpenterprise.com|F|4"] [data "GET ?c=n;o=d HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "jcpenterprise.com"] [uri "/"] [unique_id "apnRL7_Pdnp2FBpYVUFNhwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 11:39:41
(3 days ago)
(mod_security) mod_security (id:217210) triggered by 72.1.158.127 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:217210) triggered by 72.1.158.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 07:39:36.625995 2026] [security2:error] [pid 5972:tid 5972] [client 72.1.158.127:57821] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||jhuddlestonconstruction.com|F|4"] [data "GET ?c=m;o=a HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "jhuddlestonconstruction.com"] [uri "/"] [unique_id "aplceIr0IBztthLoKLwr2gAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-31 16:47:41
(5 days ago)
(mod_security) mod_security (id:217210) triggered by 72.1.158.127 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:217210) triggered by 72.1.158.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 12:47:34.076703 2026] [security2:error] [pid 18831:tid 18831] [client 72.1.158.127:44851] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||simplyexquisitetravels.com|F|4"] [data "GET ?c=m;o=a HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "simplyexquisitetravels.com"] [uri "/"] [unique_id "apWwJgzE9RPxJF8L8RowawAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
ParaBug
2026-08-27 16:31:50
(1 week ago)
72.1.158.127 - - [27/Aug/2026:18:31:49 +0200] "GET /wp-sitemap.xml HTTP/1.1" 301 602 "https://www.an ...
show more
72.1.158.127 - - [27/Aug/2026:18:31:49 +0200] "GET /wp-sitemap.xml HTTP/1.1" 301 602 "https://www.antik-wagon.com/sitemap_index.xml" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.0.0 Safari/537.3"
...
show less
Phishing
Brute-Force
Web App Attack
🇺🇸
TIScore
2026-08-24 12:29:35
(1 week ago)
Automated web attack / probing. Signals: Unexpected path. Last path: /wp-sitemap.xml
Web App Attack
🇺🇸
HamSammich
2026-08-23 10:45:57
(2 weeks ago)
Automated sensor: 3 HTTPS connection/probe attempts over the last 24h (latest 2026-08-23T10:45Z).
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-21 23:46:07
(2 weeks ago)
(mod_security) mod_security (id:217210) triggered by 72.1.158.127 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:217210) triggered by 72.1.158.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 19:46:01.969416 2026] [security2:error] [pid 2916:tid 2916] [client 72.1.158.127:41011] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||emilyormen.com|F|4"] [data "GET ?c=n;o=d HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "emilyormen.com"] [uri "/"] [unique_id "aojjOaM-IABcP8J1Rf6xgAAAAA0"], referer: https://emilyormen.com/wp-sitemap.xml
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-16 04:27:43
(3 weeks ago)
(mod_security) mod_security (id:217210) triggered by 72.1.158.127 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:217210) triggered by 72.1.158.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 00:27:35.453531 2026] [security2:error] [pid 1999858:tid 1999858] [client 72.1.158.127:39097] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||contiautos.com|F|4"] [data "GET ?c=n;o=d HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "contiautos.com"] [uri "/"] [unique_id "aoE8N4YXrGEXE9Jvm05W1gAAAAA"], referer: https://contiautos.com/wp-sitemap.xml
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-15 13:34:42
(3 weeks ago)
(mod_security) mod_security (id:217210) triggered by 72.1.158.127 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:217210) triggered by 72.1.158.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 09:34:35.035184 2026] [security2:error] [pid 18688:tid 18688] [client 72.1.158.127:53479] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||abogadoparticular.com|F|4"] [data "GET ?c=s;o=a HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "abogadoparticular.com"] [uri "/"] [unique_id "aoBq6yr4_55xcpJ2Kw0tGgAAAAQ"], referer: https://abogadoparticular.com?c=m;o=a
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-13 01:23:56
(3 weeks ago)
(mod_security) mod_security (id:217210) triggered by 72.1.158.127 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:217210) triggered by 72.1.158.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 12 21:23:52.278197 2026] [security2:error] [pid 947568:tid 947568] [client 72.1.158.127:49655] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||darkcodeverse.com|F|4"] [data "GET ?c=n;o=d HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "darkcodeverse.com"] [uri "/"] [unique_id "an0cqKaG4lRTCbDlq_GBGAAAAAk"], referer: https://darkcodeverse.com/wp-sitemap.xml
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-12 00:50:14
(3 weeks ago)
(mod_security) mod_security (id:217210) triggered by 72.1.158.127 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:217210) triggered by 72.1.158.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 20:50:08.730031 2026] [security2:error] [pid 3163425:tid 3163425] [client 72.1.158.127:53145] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||scaface.com|F|4"] [data "GET ?c=n;o=d HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "scaface.com"] [uri "/"] [unique_id "anvDQMeshikqIM5fLvuKlAAAAAA"], referer: https://scaface.com/wp-sitemap.xml
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
interbiznw.com
2026-08-10 19:56:20
(3 weeks ago)
fail2ban-ban
Hacking
Brute-Force
Exploited Host
Web App Attack
Anonymous
2026-08-09 08:43:13
(4 weeks ago)
Web application attack detected.
Web App Attack