🇺🇸
TPI-Abuse
2026-09-09 13:13:33
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.165.68.194 (194.68.165.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.68.194 (194.68.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 09:13:28.939685 2026] [security2:error] [pid 4579:tid 4579] [client 34.165.68.194:50106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.wa211.org"] [uri "/.git/config"] [unique_id "aqFbeMZVklDICo7sZXfR3AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
4server
2026-09-09 04:24:04
(11 hours ago)
[WedSep0906:24:01.6537792026][security2:error][pid2518214:tid2518237][client34.165.68.194:0]ModSecur ...
show more
[WedSep0906:24:01.6537792026][security2:error][pid2518214:tid2518237][client34.165.68.194:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"cpcalendars.tpgs.ch\"][uri\"/.env.bak\"][unique_id\"aqDfYRL13ht25Lh-GliHZwAAAY8\"]
show less
Port Scan
Brute-Force
Web App Attack
🇫🇷
Zundapper
2026-09-07 12:07:40
(2 days ago)
34.165.68.194 - - [07/Sep/2026:14:07:39 +0200] "GET /phpinfo HTTP/1.1" 404 178 "-" "Mozilla/5.0 (X11 ...
show more
34.165.68.194 - - [07/Sep/2026:14:07:39 +0200] "GET /phpinfo HTTP/1.1" 404 178 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.165.68.194 - - [07/Sep/2026:14:07:39 +0200] "GET /info HTTP/1.1" 404 178 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.165.68.194 - - [07/Sep/2026:14:07:39 +0200] "GET /info HTTP/1.1" 404 178 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.165.68.194 - - [07/Sep/2026:14:07:40 +0200] "GET /_profiler/phpinfo HTTP/1.1" 404 178 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
Port Scan
🇺🇸
TPI-Abuse
2026-09-07 12:04:55
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.165.68.194 (194.68.165.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.68.194 (194.68.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 08:04:45.078117 2026] [security2:error] [pid 26072:tid 26072] [client 34.165.68.194:38302] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cncservices.ws"] [uri "/.git/config"] [unique_id "ap6oXTmM0FsYHbEpINqJmwAAAIU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 10:54:12
(2 days ago)
Bot / seems abusive / Apache connections: 25
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇫🇷
Zundapper
2026-09-07 10:54:11
(2 days ago)
34.165.68.194 - - [07/Sep/2026:12:54:09 +0200] "GET /phpinfo HTTP/1.1" 404 178 "-" "Mozilla/5.0 (Mac ...
show more
34.165.68.194 - - [07/Sep/2026:12:54:09 +0200] "GET /phpinfo HTTP/1.1" 404 178 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.165.68.194 - - [07/Sep/2026:12:54:10 +0200] "GET /info HTTP/1.1" 404 178 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.165.68.194 - - [07/Sep/2026:12:54:10 +0200] "GET /_profiler/phpinfo HTTP/1.1" 404 178 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.165.68.194 - - [07/Sep/2026:12:54:10 +0200] "GET /_environment HTTP/1.1" 404 178 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.165.68.194 - - [07/Sep/2026:12:54:11 +0200] "GET /webroot/index.php/_environment HTTP/1.1" 404 178 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (K
...
show less
Web App Attack
Port Scan
🇫🇷
dynamix
2026-09-07 09:41:20
(2 days ago)
Multiple WAF Violations
Web App Attack
🇷🇴
clauss
2026-09-07 08:39:01
(2 days ago)
34.165.68.194 - - [07/Sep/2026:11:39:00 +0300] "GET /phpinfo.php HTTP/2.0" 401 543 "-" "Mozilla/5.0 ...
show more
34.165.68.194 - - [07/Sep/2026:11:39:00 +0300] "GET /phpinfo.php HTTP/2.0" 401 543 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.165.68.194 - - [07/Sep/2026:11:39:00 +0300] "GET /info.php HTTP/2.0" 401 543 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
🇮🇪
kundukundu
2026-09-07 07:49:01
(2 days ago)
[Drupal AbuseIPDB module] Request path is blacklisted. /phpversion.php
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-07 07:11:37
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇳🇿
Antinson
2026-09-07 06:36:34
(2 days ago)
Scraping with a high error ratio and request rate
Bad Web Bot
🇵🇱
mscode.pl
2026-09-07 06:24:57
(2 days ago)
Triggered Cloudflare WAF (firewallCustom) from IL.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from IL.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (GET method)
Zone: cms.mscode.pl
Endpoint: /firebase-adminsdk.json
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-06 22:38:29
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.165.68.194 (194.68.165.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.68.194 (194.68.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 18:38:21.462884 2026] [security2:error] [pid 1298770:tid 1298856] [client 34.165.68.194:58956] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cmykdesign.com"] [uri "/.git/config"] [unique_id "ap3rXZUjPXe-IK_tUmCunQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇴
iulianh
2026-09-06 20:31:13
(2 days ago)
80,443
Brute-Force
SSH
🇨🇭
zynex
2026-09-06 20:23:51
(2 days ago)
URL Probing: /server/.env
Web App Attack