๐บ๐ธ
TPI-Abuse
2026-09-01 19:37:23
(23 hours ago)
(mod_security) mod_security (id:210740) triggered by 72.56.73.23 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210740) triggered by 72.56.73.23 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 15:37:16.210039 2026] [security2:error] [pid 26397:tid 26397] [client 72.56.73.23:47710] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||frogdesignmexico.com:443|F|4"] [data "/proxy-connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "frogdesignmexico.com"] [uri "/"] [unique_id "apcpbIOCM_AqHPh78TxLNgAAAIs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
aranguren.org
2026-09-01 12:16:29
(1 day ago)
[Tue Sep 01 22:16:09.715897 2026] [authz_core:error] [pid 2385817:tid 2385866] [client 72.56.73.23:6 ...
show more
[Tue Sep 01 22:16:09.715897 2026] [authz_core:error] [pid 2385817:tid 2385866] [client 72.56.73.23:60298] AH01630: client denied by server configuration: /srv/http/
[Tue Sep 01 22:16:23.349575 2026] [authz_core:error] [pid 2385817:tid 2385878] [client 72.56.73.23:43166] AH01630: client denied by server configuration: /srv/http/
[Tue Sep 01 22:16:29.203485 2026] [authz_core:error] [pid 2385817:tid 2385856] [client 72.56.73.23:37014] AH01630: client denied by server configuration: /srv/http/
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 01:25:21
(1 day ago)
(mod_security) mod_security (id:217210) triggered by 72.56.73.23 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:217210) triggered by 72.56.73.23 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 21:25:16.796043 2026] [security2:error] [pid 30927:tid 30927] [client 72.56.73.23:37450] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||weathercarib.com:443|F|4"] [data "CONNECT weathercarib.com:443 HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "weathercarib.com"] [uri "/"] [unique_id "apYpfB5j-gNPMPpsjjpPuAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
paissangroup
2026-08-31 01:02:25
(2 days ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
luxuria.cfd
2026-08-30 19:49:34
(2 days ago)
Credential scanning on player_api.php (5 distinct logins in 120s). Auto-blocked by XUI Shield.
DDoS Attack
Port Scan
๐ฉ๐ช
yitzhaq
2026-08-30 14:16:14
(3 days ago)
72.56.73.23 - - [30/Aug/2026:16:16:11 +0200] "CONNECT [site]:443 HTTP/1.1" 301 516 "-" "-"
Open Proxy
๐บ๐ธ
TPI-Abuse
2026-08-29 22:53:46
(3 days ago)
(mod_security) mod_security (id:217210) triggered by 72.56.73.23 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:217210) triggered by 72.56.73.23 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 18:53:40.910770 2026] [security2:error] [pid 32154:tid 32154] [client 72.56.73.23:59868] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||www.123clearmyticket.com:443|F|4"] [data "CONNECT www.123clearmyticket.com:443 HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.123clearmyticket.com"] [uri "/"] [unique_id "apNi9MgITuU7ffM48FpRXQAAADM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 18:49:43
(4 days ago)
(mod_security) mod_security (id:217210) triggered by 72.56.73.23 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:217210) triggered by 72.56.73.23 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 14:49:39.326100 2026] [security2:error] [pid 32172:tid 32289] [client 72.56.73.23:50238] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||www.myrtlebeachdiet.com:443|F|4"] [data "CONNECT www.myrtlebeachdiet.com:443 HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.myrtlebeachdiet.com"] [uri "/"] [unique_id "apMpwwbImfQ5iYSxTioNTgAAAQQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
DrLex0
2026-08-29 01:01:41
(4 days ago)
BnL002: GET with absolute URL, obvious botnet minion; either attempt to find exploitable proxy, or j ...
show more
BnL002: GET with absolute URL, obvious botnet minion; either attempt to find exploitable proxy, or just plain stupidity from whomever wrote this piece of crap
show less
Hacking
Bad Web Bot
Exploited Host
๐จ๐ญ
Origon
2026-08-28 10:27:31
(5 days ago)
http-open-proxy - IP: 72.56.73.23 - time="2026-08-28T12:27:30+02:00" level=info msg="(555f66b4f6a74 ...
show more
http-open-proxy - IP: 72.56.73.23 - time="2026-08-28T12:27:30+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-open-proxy by ip 72.56.73.23 (NL/210976) : 4h ban on Ip 72.56.73.23" module=db
show less
Web App Attack