🇩🇪
4server
2026-09-07 22:27:32
(6 hours ago)
[TueSep0800:27:28.8157482026][security2:error][pid728273:tid728304][client34.166.16.200:0]ModSecurit ...
show more
[TueSep0800:27:28.8157482026][security2:error][pid728273:tid728304][client34.166.16.200:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"cpanel.galardi.ch\"][uri\"/.env.bak\"][unique_id\"ap86UAe7cIbYnKTY9FsaOQAAAFY\"]
show less
Port Scan
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 18:36:56
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.166.16.200 (200.16.166.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.16.200 (200.16.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:36:49.485469 2026] [security2:error] [pid 10613:tid 10613] [client 34.166.16.200:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.frogmouthatx.com"] [uri "/.git/config"] [unique_id "ap8EQWWhQgu3VSzIHRUFXAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 15:19:58
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.166.16.200 (200.16.166.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.16.200 (200.16.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 11:19:55.581507 2026] [security2:error] [pid 803:tid 803] [client 34.166.16.200:54484] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.formationone.com"] [uri "/.git/config"] [unique_id "ap7WG_ME0W91tJW2mGuBfQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-07 13:05:03
(15 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 07:14:06
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.166.16.200 (200.16.166.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.16.200 (200.16.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 03:13:59.056987 2026] [security2:error] [pid 22662:tid 22662] [client 34.166.16.200:33536] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.feaverslane.com"] [uri "/.git/config"] [unique_id "ap5kN6aI4G-JAoyscUjybwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 05:15:36
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.166.16.200 (200.16.166.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.16.200 (200.16.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 01:15:31.982138 2026] [security2:error] [pid 1775986:tid 1776063] [client 34.166.16.200:39886] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.fandgins.com"] [uri "/.git/config"] [unique_id "ap5Ic1AY7FEzOcUqwbYDgAAAAY4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 04:33:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.166.16.200 (200.16.166.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.16.200 (200.16.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 00:33:10.366678 2026] [security2:error] [pid 8154:tid 8154] [client 34.166.16.200:46406] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.fairfieldfarms.net"] [uri "/.git/config"] [unique_id "ap4-hkDl6Gh37FnvlF7V_QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 02:17:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.166.16.200 (200.16.166.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.16.200 (200.16.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 22:17:14.385602 2026] [security2:error] [pid 1308:tid 1308] [client 34.166.16.200:53876] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.exoticcarwrap.com"] [uri "/.git/config"] [unique_id "ap4eqqzszupfqSyRm8oF4AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇴
clauss
2026-09-06 19:21:47
(1 day ago)
34.166.16.200 - - [06/Sep/2026:22:21:45 +0300] "GET /.git/config HTTP/1.1" 404 3420 "-" "Mozilla/5.0 ...
show more
34.166.16.200 - - [06/Sep/2026:22:21:45 +0300] "GET /.git/config HTTP/1.1" 404 3420 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.166.16.200 - - [06/Sep/2026:22:21:46 +0300] "GET /.env.local HTTP/1.1" 404 3420 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 17:32:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.166.16.200 (200.16.166.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.16.200 (200.16.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 13:32:26.764380 2026] [security2:error] [pid 17989:tid 17989] [client 34.166.16.200:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.empoweruamerica.org"] [uri "/.git/config"] [unique_id "ap2jqp5-YsOOYPazDrmHvgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 13:52:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.166.16.200 (200.16.166.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.16.200 (200.16.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 09:52:29.081967 2026] [security2:error] [pid 13508:tid 13508] [client 34.166.16.200:59022] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.elegantweddingnapkins.com"] [uri "/.git/config"] [unique_id "ap1wHby32GM1pBHVcpOY0QAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-06 13:50:04
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack