This IP address has been reported a total of
8
times from
4 distinct
sources.
72.56.164.36 was first reported on
June 21st 2026 , and the most recent report was
1 day ago .
In the last 60 days, the top reporter locations were:
United States of America
with 5
reports;
Canada
with 1
report.
The most common categories in these recent reports were:
Web App Attack
6
times;
Bad Web Bot
5
times;
Brute-Force
5
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
πΊπΈ
TPI-Abuse
2026-10-01 11:46:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 72.56.164.36 (undefined.hostname.localhost): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 72.56.164.36 (undefined.hostname.localhost): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 07:46:38.582139 2026] [security2:error] [pid 4382:tid 4382] [client 72.56.164.36:33069] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "flowerweddinginvitations.com"] [uri "/.git/HEAD"] [unique_id "ar5IHu-RRb3VDT3yuM6g-AAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 09:12:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 72.56.164.36 (undefined.hostname.localhost): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 72.56.164.36 (undefined.hostname.localhost): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 05:12:10.819356 2026] [security2:error] [pid 29486:tid 29486] [client 72.56.164.36:33275] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "flic.net"] [uri "/.git/HEAD"] [unique_id "ar4j6qy1Nx4WAmz0Z1Nt8AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-18 00:45:39
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 72.56.164.36 (undefined.hostname.localhost): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 72.56.164.36 (undefined.hostname.localhost): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 20:45:33.149221 2026] [security2:error] [pid 22932:tid 22932] [client 72.56.164.36:52157] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "boasfrequencias.com"] [uri "/.git/HEAD"] [unique_id "aqyJrR1JeHP0KtTo8en8UwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-17 13:30:15
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 72.56.164.36 (undefined.hostname.localhost): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 72.56.164.36 (undefined.hostname.localhost): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 09:30:10.561230 2026] [security2:error] [pid 28518:tid 28518] [client 72.56.164.36:56485] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "acmax.com"] [uri "/.env"] [unique_id "aqvrYqfAJ7__V4Lk4NsaSgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-16 01:13:46
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 72.56.164.36 (undefined.hostname.localhost): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 72.56.164.36 (undefined.hostname.localhost): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 21:13:42.921209 2026] [security2:error] [pid 21205:tid 21205] [client 72.56.164.36:51867] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "barmitzvahnapkins.com"] [uri "/.git/HEAD"] [unique_id "aqntRvnss4qtrYPfXdrK7wAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-04 10:46:30
(1 month ago)
FortiWeb WAF: 18 attacks detected. Threat Score: 10989830. Types: Client Management(9), Signature De ...
show more
FortiWeb WAF: 18 attacks detected. Threat Score: 10989830. Types: Client Management(9), Signature Detection(9). Origin: United States.
show less
Web App Attack
Anonymous
2026-07-22 06:31:44
(2 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
Anonymous
2026-06-21 07:18:59
(3 months ago)
Unauthorized VPN login attempts
Hacking
Brute-Force
Showing 1 to
8
of 8 reports