🇩🇪
mondor.ro
2026-09-12 18:30:10
(2 hours ago)
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 34.168.2.96, Reason:[( ...
show more
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 34.168.2.96, Reason:[(mod_security) mod_security (id:210492) triggered by 34.168.2.96 (US/United States/96.2.168.34.bc.googleusercontent.com): 3 in the last 3600 secs]; Ports: *; Direction: inout; Trigger: LF_CLUSTER; Logs:
show less
Port Scan
🇺🇸
TPI-Abuse
2026-09-12 17:46:45
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.168.2.96 (96.2.168.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.168.2.96 (96.2.168.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 13:46:41.957486 2026] [security2:error] [pid 11717:tid 11778] [client 34.168.2.96:58902] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.cookmanufacturinggroup.com"] [uri "/.git/config"] [unique_id "aqWQAd4oZ51OAfzbm4GOPgAAAdc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 15:19:18
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.168.2.96 (96.2.168.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.168.2.96 (96.2.168.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 11:19:11.159152 2026] [security2:error] [pid 25579:tid 25602] [client 34.168.2.96:46174] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.colinkyffinmusic.com"] [uri "/.git/config"] [unique_id "aqVtb68ihKSXqMP_8VgDsQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇰
HostingGroup
2026-09-12 14:51:53
(5 hours ago)
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shiel ...
show more
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shield. Offenses: 10. First blocked: 2026-09-12.
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 14:42:41
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.168.2.96 (96.2.168.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.168.2.96 (96.2.168.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 10:42:35.952142 2026] [security2:error] [pid 21229:tid 21229] [client 34.168.2.96:52094] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.wa211.org"] [uri "/.git/config"] [unique_id "aqVk227ZDkqS4zeEMqtV0wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
rubixstudios
2026-09-12 06:13:02
(14 hours ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 05:54:57
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.168.2.96 (96.2.168.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.168.2.96 (96.2.168.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 01:54:47.857885 2026] [security2:error] [pid 3847:tid 3847] [client 34.168.2.96:47158] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.vespaitaliancafe.com"] [uri "/.git/config"] [unique_id "aqTpJ-Gpz5B1HbArQJOeZgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 04:51:17
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.168.2.96 (96.2.168.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.168.2.96 (96.2.168.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 00:51:11.520902 2026] [security2:error] [pid 1188331:tid 1188331] [client 34.168.2.96:59092] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.catherineseress.com"] [uri "/.git/config"] [unique_id "aqTaPyRiU-hIKikr36KC8gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-12 02:50:03
(17 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-11 22:02:00
(22 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-10.
show less
Web App Attack
SSH
Hacking
🇩🇪
pcpiefke
2026-09-11 18:45:24
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 34.168.2.96 (US/United States/96.2.168. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.168.2.96 (US/United States/96.2.168.34.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-11 15:25:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.168.2.96 (96.2.168.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.168.2.96 (96.2.168.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 11:25:06.180012 2026] [security2:error] [pid 26926:tid 26926] [client 34.168.2.96:44598] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.tempsetters.com"] [uri "/.git/config"] [unique_id "aqQdUt3hHEKyjn8vJkPxMgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 11:26:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.168.2.96 (96.2.168.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.168.2.96 (96.2.168.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 07:26:34.429171 2026] [security2:error] [pid 9855:tid 9855] [client 34.168.2.96:37670] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.sympalais.com"] [uri "/.git/config"] [unique_id "aqPlaont5GcGx3UdrPC2XQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 10:37:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.168.2.96 (96.2.168.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.168.2.96 (96.2.168.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 06:37:30.115260 2026] [security2:error] [pid 13195:tid 13195] [client 34.168.2.96:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.swarnar.com"] [uri "/.git/config"] [unique_id "aqPZ6hZ83IzQcn7G88z5lQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 09:13:11
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.168.2.96 (96.2.168.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.168.2.96 (96.2.168.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 05:13:05.761568 2026] [security2:error] [pid 25876:tid 25876] [client 34.168.2.96:43330] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.sunsettrailsardmore.com"] [uri "/.git/config"] [unique_id "aqPGIbxn2sluWeVJH2AFugAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack