๐บ๐ธ
TPI-Abuse
2026-09-18 20:49:52
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.166.190.195 (195.190.166.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.190.195 (195.190.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 16:49:44.931097 2026] [security2:error] [pid 22879:tid 22879] [client 34.166.190.195:51302] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.montymilburn.com"] [uri "/.git/config"] [unique_id "aq2j6FMtimIJ_TiFRyHbuQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 17:47:44
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.166.190.195 (195.190.166.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.190.195 (195.190.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 13:47:37.600155 2026] [security2:error] [pid 31583:tid 31604] [client 34.166.190.195:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.mindgardens.com"] [uri "/.env.docker"] [unique_id "aq15OdAyftu17j0FAnS4UQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-09-18 17:46:38
(11 hours ago)
[FriSep1819:46:32.9455472026][security2:error][pid3928467:tid3928588][client34.166.190.195:0]ModSecu ...
show more
[FriSep1819:46:32.9455472026][security2:error][pid3928467:tid3928588][client34.166.190.195:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"cpcontacts.mjgold.ch\"][uri\"/.env.bak\"][unique_id\"aq14-Fny1FJIcEHpC18iTgAAANA\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 16:30:15
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.166.190.195 (195.190.166.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.190.195 (195.190.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 12:30:07.504945 2026] [security2:error] [pid 10204:tid 10204] [client 34.166.190.195:57604] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.isyourcompanysafe.com"] [uri "/.git/config"] [unique_id "aq1nD9UkcmQItAIyYKUiNwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 15:00:38
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.166.190.195 (195.190.166.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.190.195 (195.190.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 11:00:34.097715 2026] [security2:error] [pid 7895:tid 7895] [client 34.166.190.195:35792] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.microscopicpablo.com"] [uri "/.git/config"] [unique_id "aq1SElHsGvhiT7d-cHlo5wAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 12:35:35
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.166.190.195 (195.190.166.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.190.195 (195.190.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 08:35:27.953084 2026] [security2:error] [pid 25861:tid 25861] [client 34.166.190.195:56748] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.merlinaerospace.com"] [uri "/.git/config"] [unique_id "aq0wD-RISlkHerBJVSVs-wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 10:52:54
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.166.190.195 (195.190.166.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.190.195 (195.190.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 06:52:47.891010 2026] [security2:error] [pid 15914:tid 15914] [client 34.166.190.195:41912] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.medpact.net"] [uri "/.git/config"] [unique_id "aq0X_yBnJhbmuM2cVVZpmQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-09-18 08:38:32
(20 hours ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ๏ธ Configuration File Access (Non Decay-Based ...
show more
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ๏ธ Configuration File Access (Non Decay-Based) - โ Excessive 40X Errors (Decay-Based)
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 02:19:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.166.190.195 (195.190.166.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.190.195 (195.190.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 22:19:12.555917 2026] [security2:error] [pid 21673:tid 21673] [client 34.166.190.195:60806] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.hvacs-aircon.com"] [uri "/.git/config"] [unique_id "aqyfoP4HmS96lK-IV_aPlQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 01:44:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.166.190.195 (195.190.166.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.190.195 (195.190.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 21:44:46.293367 2026] [security2:error] [pid 13567:tid 13607] [client 34.166.190.195:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.humanet.io"] [uri "/.git/config"] [unique_id "aqyXjnsaVwESBgewbJTaDgAAAMo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-09-17 14:44:17
(1 day ago)
[ThuSep1716:44:15.2167592026][security2:error][pid2307439:tid2307519][client34.166.190.195:0]ModSecu ...
show more
[ThuSep1716:44:15.2167592026][security2:error][pid2307439:tid2307519][client34.166.190.195:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"cpcalendars.hdcadvisory.ch\"][uri\"/.env.bak\"][unique_id\"aqv8v_zAlwc36RFj4dgs-gAAAJM\"]
show less
Port Scan
Brute-Force
Web App Attack
Anonymous
2026-09-17 11:46:45
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ต๐ฑ
Budyn
2026-09-16 16:59:51
(2 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: cpanel.goblinpot.online | URI: /.git/config | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 16:44:58
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.166.190.195 (195.190.166.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.190.195 (195.190.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 12:44:52.063724 2026] [security2:error] [pid 3621:tid 3621] [client 34.166.190.195:50618] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.globalpackets.net"] [uri "/.git/config"] [unique_id "aqrHhAhGvREGtwZPURB9NAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-09-16 15:49:15
(2 days ago)
[WedSep1617:49:11.6466772026][security2:error][pid922097:tid922140][client34.166.190.195:0]ModSecuri ...
show more
[WedSep1617:49:11.6466772026][security2:error][pid922097:tid922140][client34.166.190.195:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"cpanel.orabonastudio.it\"][uri\"/.env.bak\"][unique_id\"aqq6d6RS-14pA5ts1PIApAAAAMs\"]
show less
Port Scan
Brute-Force
Web App Attack