๐บ๐ธ
TPI-Abuse
2026-09-16 15:56:45
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.166.147.12 (12.147.166.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.147.12 (12.147.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 11:56:39.383949 2026] [security2:error] [pid 5121:tid 5121] [client 34.166.147.12:32808] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "convtek.com"] [uri "/.git/config"] [unique_id "aqq8N7MNdE7ptQVv4-sG9gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 15:03:36
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.166.147.12 (12.147.166.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.147.12 (12.147.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 11:03:31.486277 2026] [security2:error] [pid 27378:tid 27378] [client 34.166.147.12:59374] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "conversationtalentnetwork.com"] [uri "/.git/config"] [unique_id "aqqvw6weSCBpv1rjA-TtAQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-16 14:48:39
(2 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ง๐ท
dominioz
2026-09-16 14:03:37
(3 hours ago)
2026-09-16 14:03:12 GET /.env - - 34.166.147.12 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+A ...
show more
2026-09-16 14:03:12 GET /.env - - 34.166.147.12 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 404 5093
2026-09-16 14:03:14 GET /.env.local - - 34.166.147.12 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 404 5105
2026-09-16 14:03:15 GET /.env.production - - 34.166.147.12 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 404 5115
2026-09-16 14:03:17 GET /.env.staging - - 34.166.147.12 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 404 5109
2026-09-16 14:03:18 GET /.env.development - - 34.166.147.12 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 404 5117
2026-09-16 14:03:19 GET /.env.test - - 34.166.147.12 HTTP/1.1 M
...
show less
Web App Attack
๐บ๐ธ
abuse-opdc
2026-09-16 13:10:42
(3 hours ago)
Malicious HTTP requests matching injection/exploit signatures.
Web App Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-16 12:45:41
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.166.147.12 (12.147.166.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.147.12 (12.147.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 08:45:32.929214 2026] [security2:error] [pid 7437:tid 7437] [client 34.166.147.12:37376] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "contrarianadvisors.com"] [uri "/.git/config"] [unique_id "aqqPbKRcIoX2S7fo6E44fgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 12:04:44
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.166.147.12 (12.147.166.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.147.12 (12.147.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 08:04:36.824011 2026] [security2:error] [pid 27565:tid 27605] [client 34.166.147.12:54102] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.absurdotron.com"] [uri "/.git/config"] [unique_id "aqqF1Nlm8WST2oTU5VjhFwAAAMg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 11:18:27
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.166.147.12 (12.147.166.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.147.12 (12.147.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 07:18:19.270630 2026] [security2:error] [pid 25134:tid 25134] [client 34.166.147.12:52448] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.abdulhameeds.art"] [uri "/.git/config"] [unique_id "aqp6-wUZ4xeksjan0X71fQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 08:09:13
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.166.147.12 (12.147.166.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.147.12 (12.147.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 04:09:05.156421 2026] [security2:error] [pid 13108:tid 13108] [client 34.166.147.12:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.365soft.top"] [uri "/.git/config"] [unique_id "aqpOoQWdXhGRzvmUerr4DgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 06:47:32
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.166.147.12 (12.147.166.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.147.12 (12.147.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 02:47:27.529354 2026] [security2:error] [pid 3166:tid 3166] [client 34.166.147.12:51932] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.179vfs.com"] [uri "/.git/config"] [unique_id "aqo7f8Udlipt5Mr-e1vg-wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
updown.io
2026-09-16 06:41:37
(10 hours ago)
{"level":"info","ts":1789540892.6866727,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1789540892.6866727,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.166.147.12","remote_port":"58796","client_ip":"34.166.147.12","proto":"HTTP/1.1","method":"GET","host":"cpanel.159-089-098-098.cprapid.com","uri":"/public/.env","headers":{"X-Nextjs-Request-Id":["2c16c09e"],"Cookie":["REDACTED"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"],"Accept-Encoding":["gzip, deflate"],"Accept":["*/*"],"Connection":["keep-alive"],"Next-Action":["x"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"http/1.1","server_name":"cpanel.159-089-098-098.cprapid.com","ech":false}},"bytes_read":0,"user_id":"","duration":0.000190924,"size":0,"status":429,"resp_headers":{"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"],"Server":["Caddy"]}}
{"level":"info","ts":1789540893.198068,"logger":"http.log.access.log1","msg":"handled request","request":{"r
...
show less
DDoS Attack
Web App Attack
๐ฌ๐ท
setupgr
2026-09-16 05:46:34
(11 hours ago)
(mod_security) mod_security (id:11000011) triggered by 34.166.147.12 (SA/Saudi Arabia/Eastern Provin ...
show more
(mod_security) mod_security (id:11000011) triggered by 34.166.147.12 (SA/Saudi Arabia/Eastern Province/Dammam/-/[AS396982 Google LLC]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Wed Sep 16 08:46:29.677682 2026] [security2:error] [pid 1197089:tid 1197203] [client 34.166.147.12:37296] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "googleusercontent.com" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: 12.147.166.34.bc.googleusercontent.com"] [severity "CRITICAL"] [hostname "cpanagiotou.gr"] [uri "/"] [unique_id "aqotNRrJgmk1hh30IUpzSgAAAMI"]
show less
Port Scan
๐บ๐ธ
Starburst SysOp Team
2026-09-16 05:46:04
(11 hours ago)
Malware host detected by rbl.malware.expert. RBL lookup of 12.147.166.34.rbl.malware.expert succeede ...
show more
Malware host detected by rbl.malware.expert. RBL lookup of 12.147.166.34.rbl.malware.expert succeeded at REMOTE_ADDR. (400010-stl2-14)
show less
Hacking
๐ซ๐ท
dynamix
2026-09-16 05:43:08
(11 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
dot.mg
2026-09-16 04:54:02
(12 hours ago)
Bad behaviour
Web Spam