🇺🇸
TPI-Abuse
2026-09-12 21:52:02
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.165.91.162 (162.91.165.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.91.162 (162.91.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 17:51:55.547596 2026] [security2:error] [pid 31963:tid 31963] [client 34.165.91.162:47102] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.frenosilent.ar"] [uri "/.git/config"] [unique_id "aqXJe4lvbcGWNN2bdhPH4wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 19:59:59
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.165.91.162 (162.91.165.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.91.162 (162.91.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 15:59:54.842605 2026] [security2:error] [pid 27228:tid 27228] [client 34.165.91.162:60692] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.formationone.com"] [uri "/.git/config"] [unique_id "aqWvOm3_IobgL4JWAGvGrgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 15:39:09
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.165.91.162 (162.91.165.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.91.162 (162.91.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 11:39:02.541233 2026] [security2:error] [pid 22365:tid 22365] [client 34.165.91.162:58610] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.softwarezz.net"] [uri "/.git/config"] [unique_id "aqVyFm2QGZ4O9mZWDl43hgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 13:54:11
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.165.91.162 (162.91.165.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.91.162 (162.91.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 09:54:06.079495 2026] [security2:error] [pid 25900:tid 25900] [client 34.165.91.162:40858] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.feaverslane.com"] [uri "/.git/config"] [unique_id "aqVZfr8jcgO96jVjAMu6ZwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 12:08:07
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.165.91.162 (162.91.165.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.91.162 (162.91.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 08:08:00.681639 2026] [security2:error] [pid 4446:tid 4446] [client 34.165.91.162:52808] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.skintormint.com"] [uri "/.git/config"] [unique_id "aqVAoHteODWFVcEv-qIfdAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 11:51:42
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.165.91.162 (162.91.165.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.91.162 (162.91.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 07:51:35.010300 2026] [security2:error] [pid 3127:tid 3127] [client 34.165.91.162:44818] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.fairfieldfarms.net"] [uri "/.git/config"] [unique_id "aqU8x2q7b2v0p4QgXgZvWQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 10:48:48
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.165.91.162 (162.91.165.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.91.162 (162.91.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 06:48:41.185060 2026] [security2:error] [pid 2495712:tid 2495712] [client 34.165.91.162:39784] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.sinsky.net"] [uri "/.git/config"] [unique_id "aqUuCauIps_JbXMvXOWGOgAAAF0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
rellik
2026-09-12 10:44:00
(20 hours ago)
Brute Force Scanning Critical Directories
Hacking
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 04:49:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.165.91.162 (162.91.165.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.91.162 (162.91.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 00:49:42.638854 2026] [security2:error] [pid 3274:tid 3274] [client 34.165.91.162:44216] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.serenimedit.com"] [uri "/.git/config"] [unique_id "aqTZ5uVRB5lnJ5-TMveiwAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
4server
2026-09-12 04:46:04
(1 day ago)
[SatSep1206:45:59.3330272026][security2:error][pid2724355:tid2724583][client34.165.91.162:0]ModSecur ...
show more
[SatSep1206:45:59.3330272026][security2:error][pid2724355:tid2724583][client34.165.91.162:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"cpanel.serban.ch\"][uri\"/.env.bak\"][unique_id\"aqTZB7EWcdVUahz2RIwcngAAAUE\"]
show less
Port Scan
Brute-Force
Web App Attack
🇮🇹
VHosting
2026-09-12 04:40:04
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 03:32:59
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.165.91.162 (162.91.165.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.91.162 (162.91.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 23:32:54.407029 2026] [security2:error] [pid 18902:tid 18902] [client 34.165.91.162:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.empoweruamerica.org"] [uri "/.git/config"] [unique_id "aqTH5p-izqdET3npmQHsmwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 03:06:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.165.91.162 (162.91.165.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.91.162 (162.91.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 23:06:14.619179 2026] [security2:error] [pid 5631:tid 5631] [client 34.165.91.162:58202] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.sebog.org"] [uri "/.git/config"] [unique_id "aqTBppzpVLpfiITgbXAq7AAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
screwlooseit.com.au
2026-09-12 02:10:20
(1 day ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/162.91.165.34.bc.googleuserconten ...
show more
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/162.91.165.34.bc.googleusercontent.com
show less
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-11 22:01:56
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-10.
show less
Web App Attack
SSH
Hacking