๐ฉ๐ช
4server
2026-09-17 15:36:57
(6 hours ago)
[ThuSep1717:36:53.8617882026][security2:error][pid2370771:tid2370851][client34.166.197.112:0]ModSecu ...
show more
[ThuSep1717:36:53.8617882026][security2:error][pid2370771:tid2370851][client34.166.197.112:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"cpcalendars.pietroviviani.ch\"][uri\"/.env.bak\"][unique_id\"aqwJFXOGTMH4EURSy9zrkQAAAJM\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 12:31:11
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.166.197.112 (112.197.166.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.197.112 (112.197.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 08:31:05.252225 2026] [security2:error] [pid 18449:tid 18449] [client 34.166.197.112:53308] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.perlcreative.com"] [uri "/.git/config"] [unique_id "aqvdiWrkOIh_PMI4PKKBxAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Lennart Kramer
2026-09-17 02:09:47
(19 hours ago)
Restricted File Access Attempt | Matched phrase "*env*" at /.env.production | Mozilla/5.0 (X11; Linu ...
show more
Restricted File Access Attempt | Matched phrase "*env*" at /.env.production | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 18:36:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.166.197.112 (112.197.166.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.197.112 (112.197.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 14:36:18.348688 2026] [security2:error] [pid 7887:tid 7887] [client 34.166.197.112:60808] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.novobeads.com"] [uri "/.git/config"] [unique_id "aqrhohE2WI3gt51Ir1_W4AAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 17:25:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.166.197.112 (112.197.166.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.197.112 (112.197.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 13:25:12.697677 2026] [security2:error] [pid 13356:tid 13356] [client 34.166.197.112:52480] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.nflelectronics.com"] [uri "/.git/config"] [unique_id "aqrQ-ONYnkyXfCz-Wi9oKAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 16:48:11
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.166.197.112 (112.197.166.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.197.112 (112.197.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 12:48:07.452973 2026] [security2:error] [pid 19215:tid 19215] [client 34.166.197.112:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ndanetworks.com"] [uri "/.git/config"] [unique_id "aqrIR3CvnKUT_MM1BTeRagAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-09-16 16:06:41
(1 day ago)
[WedSep1618:06:38.4287662026][security2:error][pid937930:tid938010][client34.166.197.112:0]ModSecuri ...
show more
[WedSep1618:06:38.4287662026][security2:error][pid937930:tid938010][client34.166.197.112:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"cpanel.thilyatecnologie.ch\"][uri\"/.env.bak\"][unique_id\"aqq-jgmnXncnW4WF0UrquAAAAdM\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-09-16 16:05:03
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 15:28:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.166.197.112 (112.197.166.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.197.112 (112.197.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 11:28:03.410108 2026] [security2:error] [pid 22407:tid 22407] [client 34.166.197.112:53572] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.mumawvickers.com"] [uri "/.git/config"] [unique_id "aqq1g7l8HxgXWoUsc519mQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 14:17:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.166.197.112 (112.197.166.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.197.112 (112.197.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 10:17:10.281332 2026] [security2:error] [pid 4406:tid 4406] [client 34.166.197.112:55880] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.therealseska.com"] [uri "/.git/config"] [unique_id "aqqk5m8qsdzG0ZpbjsbYrwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
rubixstudios
2026-09-16 13:37:03
(1 day ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 09:55:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.166.197.112 (112.197.166.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.197.112 (112.197.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 05:55:02.790585 2026] [security2:error] [pid 29068:tid 29068] [client 34.166.197.112:43674] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.thebestac.com"] [uri "/.git/config"] [unique_id "aqpndpgkyWn5NB4_jlAYuAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 09:26:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.166.197.112 (112.197.166.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.197.112 (112.197.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 05:26:07.367316 2026] [security2:error] [pid 16422:tid 16422] [client 34.166.197.112:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.theabstractpress.com"] [uri "/.git/config"] [unique_id "aqpgr8tKrK_fyBqmiMKZLwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 07:11:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.166.197.112 (112.197.166.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.197.112 (112.197.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 03:11:50.545870 2026] [security2:error] [pid 11249:tid 11249] [client 34.166.197.112:42366] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.tempsetters.com"] [uri "/.git/config"] [unique_id "aqpBNkGeHia88ayn7_H40gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-09-16 06:57:19
(1 day ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/112.197.166.34.bc.googleuserconte ...
show more
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/112.197.166.34.bc.googleusercontent.com
show less
Web App Attack