๐บ๐ธ
TPI-Abuse
2026-09-18 07:41:40
(48 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.166.130.148 (148.130.166.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.130.148 (148.130.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 03:41:38.378600 2026] [security2:error] [pid 22183:tid 22221] [client 34.166.130.148:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.grandmasgentlesteps.com"] [uri "/.git/config"] [unique_id "aqzrMh4L074JeQDUSY6SXQAAAQk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
clauss
2026-09-17 17:01:44
(15 hours ago)
34.166.130.148 - - [17/Sep/2026:20:01:43 +0300] "GET /.git/config HTTP/1.1" 404 3420 "-" "Mozilla/5. ...
show more
34.166.130.148 - - [17/Sep/2026:20:01:43 +0300] "GET /.git/config HTTP/1.1" 404 3420 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.166.130.148 - - [17/Sep/2026:20:01:43 +0300] "GET /.env.local HTTP/1.1" 404 3420 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-17 12:11:25
(20 hours ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 1 domain(s) in 3s
Web App Attack
๐ฉ๐ช
4server
2026-09-17 10:07:34
(22 hours ago)
[ThuSep1712:07:31.4448592026][security2:error][pid2026275:tid2026317][client34.166.130.148:0]ModSecu ...
show more
[ThuSep1712:07:31.4448592026][security2:error][pid2026275:tid2026317][client34.166.130.148:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"cpanel.eimeko.ch\"][uri\"/.env.bak\"][unique_id\"aqu743vIUF1cjD8t_s2v_wAAAIY\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-09-17 07:55:03
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฉ๐ช
YF
2026-09-16 17:30:19
(1 day ago)
Distributed subnet attack โ coordinated scanning from multiple IPs in the same /24
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 16:30:59
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.166.130.148 (148.130.166.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.130.148 (148.130.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 12:30:55.195952 2026] [security2:error] [pid 1087:tid 1087] [client 34.166.130.148:42210] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "comitedelafamille.org"] [uri "/.git/config"] [unique_id "aqrEP70-GizPKA7ZtwGJ9QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 16:01:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.166.130.148 (148.130.166.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.130.148 (148.130.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 12:00:51.418443 2026] [security2:error] [pid 13228:tid 13228] [client 34.166.130.148:45040] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "comicpreservation.com"] [uri "/.git/config"] [unique_id "aqq9MwqcIg5JScEcxwN15gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 15:19:32
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.166.130.148 (148.130.166.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.130.148 (148.130.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 11:19:27.020805 2026] [security2:error] [pid 19675:tid 19675] [client 34.166.130.148:36548] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "comfortcartel.bilund.com"] [uri "/.git/config"] [unique_id "aqqzf6oMBNFDEgRZof4d5QAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
elcruzado.es
2026-09-16 14:31:27
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 34.166.130.148 (SA/Saudi Arabia/148.130 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.166.130.148 (SA/Saudi Arabia/148.130.166.34.bc.googleusercontent.com)
show less
SQL Injection
Anonymous
2026-09-16 14:08:40
(1 day ago)
Automated report from fail2ban.
Detected: automated probing for vulnerable/administrative endpoints ...
show more
Automated report from fail2ban.
Detected: automated probing for vulnerable/administrative endpoints (e.g. wp-login.php, phpMyAdmin) consistent with bot scanning.
Jail: nginx-botsearch
Failed attempts recorded: 2
Report time: 2026-09-16 14:08:40 UTC
This IP has been automatically and permanently blocked at our network perimeter.
Evidence (most recent matched log lines, redacted):
$f2bV_matches
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 13:52:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.166.130.148 (148.130.166.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.130.148 (148.130.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 09:52:38.525066 2026] [security2:error] [pid 10941:tid 10941] [client 34.166.130.148:60832] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "combustionlogic.com"] [uri "/.git/config"] [unique_id "aqqfJlCRMR6PJuel1QOOPgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Comberton
2026-09-16 13:31:54
(1 day ago)
Banned by Fail2Ban on apache-wordfence jail
Brute-Force
๐จ๐ฆ
polycoda
2026-09-16 13:18:31
(1 day ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ๏ธ Configuration File Access (Non Decay-Based ...
show more
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ๏ธ Configuration File Access (Non Decay-Based) - โช๏ธ Excessive 30X Errors (Decay-Based)
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 13:12:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.166.130.148 (148.130.166.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.130.148 (148.130.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 09:12:35.980146 2026] [security2:error] [pid 12562:tid 12562] [client 34.166.130.148:37750] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "constructiondomex.com"] [uri "/.git/config"] [unique_id "aqqVw_RYCWoDeLSSqQ9YwwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack