๐บ๐ธ
TPI-Abuse
2026-09-22 23:47:16
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.162.146.204 (204.146.162.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.162.146.204 (204.146.162.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 19:47:09.076873 2026] [security2:error] [pid 10610:tid 10610] [client 34.162.146.204:40416] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.feaverslane.com"] [uri "/.git/config"] [unique_id "arMTfYQcYw-hUOlTkn6JRgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-22 19:40:07
(7 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 18:57:28
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.162.146.204 (204.146.162.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.162.146.204 (204.146.162.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 14:57:22.168212 2026] [security2:error] [pid 2583:tid 2583] [client 34.162.146.204:60532] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.exoticcarwrap.com"] [uri "/.git/config"] [unique_id "arLPkmu-qOixsctmb-J-XwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
clauss
2026-09-22 11:54:04
(15 hours ago)
34.162.146.204 - - [22/Sep/2026:14:54:03 +0300] "GET /.git/config HTTP/1.1" 404 3420 "-" "Mozilla/5. ...
show more
34.162.146.204 - - [22/Sep/2026:14:54:03 +0300] "GET /.git/config HTTP/1.1" 404 3420 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.162.146.204 - - [22/Sep/2026:14:54:03 +0300] "GET /.env.local HTTP/1.1" 404 3420 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 10:11:42
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.162.146.204 (204.146.162.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.162.146.204 (204.146.162.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 06:11:37.700396 2026] [security2:error] [pid 24414:tid 24414] [client 34.162.146.204:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.empoweruamerica.org"] [uri "/.git/config"] [unique_id "arJUWU9pTcg0-9AuvgoCdAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-09-22 03:24:36
(1 day ago)
[TueSep2205:24:34.8449262026][security2:error][pid179207:tid179237][client34.162.146.204:0]ModSecuri ...
show more
[TueSep2205:24:34.8449262026][security2:error][pid179207:tid179237][client34.162.146.204:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"cpanel.ecosuber.com\"][uri\"/.env.bak\"][unique_id\"arH08gUlWQxg_y_aygg5nAAAABI\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 01:44:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.162.146.204 (204.146.162.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.162.146.204 (204.146.162.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:44:40.274435 2026] [security2:error] [pid 28833:tid 28844] [client 34.162.146.204:34126] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.earthtravel.net"] [uri "/.git/config"] [unique_id "arHdiOhhvAGbQcBowgng8AAAAMU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:37:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.162.146.204 (204.146.162.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.162.146.204 (204.146.162.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:37:34.981900 2026] [security2:error] [pid 13226:tid 13226] [client 34.162.146.204:33092] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.drbolen.com"] [uri "/.git/config"] [unique_id "arGVjh8qxE6Zhi-hh7w21gAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:26:27
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.162.146.204 (204.146.162.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.162.146.204 (204.146.162.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:26:20.593986 2026] [security2:error] [pid 26776:tid 26776] [client 34.162.146.204:39592] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.doubloonswap.com"] [uri "/.git/config"] [unique_id "arGE3PmCvgV_J3Gl-9Tb8gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-21 19:25:03
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ต๐ฑ
Budyn
2026-09-21 18:55:58
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: cpanel.dont-eat-the-pudding.top | URI: /.git/config | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ญ๐บ
miszterx.hu
2026-09-20 14:56:01
(2 days ago)
XORP (haproxy): 118x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_i ...
show more
XORP (haproxy): 118x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_iptables_generator.sh (xorp.hu)
show less
Web App Attack
๐ช๐ธ
robotstxt
2026-09-20 13:13:21
(2 days ago)
34.162.146.204 - - [20/Sep/2026:13:13:01 +0000] "GET /.env HTTP/1.1" 403 208 "-" "Mozilla/5.0 (Macin ...
show more
34.162.146.204 - - [20/Sep/2026:13:13:01 +0000] "GET /.env HTTP/1.1" 403 208 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.162.146.204 - - [20/Sep/2026:13:13:01 +0000] "GET /.env.local HTTP/1.1" 403 208 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.162.146.204 - - [20/Sep/2026:13:13:01 +0000] "GET /.env.production HTTP/1.1" 403 208 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.162.146.204 - - [20/Sep/2026:13:13:01 +0000] "GET /.env.staging HTTP/1.1" 403 208 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.162.146.204 - - [20/Sep/2026:13:13:01 +0000] "GET /.env.development HTTP/1.1" 403 208 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, li
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 12:50:20
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.162.146.204 (204.146.162.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.162.146.204 (204.146.162.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 08:50:15.944002 2026] [security2:error] [pid 15039:tid 15088] [client 34.162.146.204:48278] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "certificationwiki.com"] [uri "/.git/config"] [unique_id "aq_Wh6ump6lny7qCk_sENgAAAVI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Thibault Millant
2026-09-20 12:49:07
(2 days ago)
2026/09/20 14:49:04 [error] 1008#1008: *86885 access forbidden by rule, client: 34.162.146.204, serv ...
show more
2026/09/20 14:49:04 [error] 1008#1008: *86885 access forbidden by rule, client: 34.162.146.204, server: certifications.millant.ovh, request: "GET /.git/config HTTP/1.1", host: "certifications.millant.ovh"
2026/09/20 14:49:05 [error] 1008#1008: *86885 access forbidden by rule, client: 34.162.146.204, server: certifications.millant.ovh, request: "GET /.env HTTP/1.1", host: "certifications.millant.ovh"
2026/09/20 14:49:05 [error] 1008#1008: *86885 access forbidden by rule, client: 34.162.146.204, server: certifications.millant.ovh, request: "GET /.env.local HTTP/1.1", host: "certifications.millant.ovh"
2026/09/20 14:49:05 [error] 1008#1008: *86885 access forbidden by rule, client: 34.162.146.204, server: certifications.millant.ovh, request: "GET /.env.production HTTP/1.1", host: "certifications.millant.ovh"
2026/09/20 14:49:05 [error] 1008#1008: *86885 access forbidden by rule, client: 34.162.146.204, server: certifications.millant.ovh, request: "GET /.env.staging HTTP/1.1", host: "certif
...
show less
Brute-Force
Exploited Host
Web App Attack