🇩🇪
FD-IX
2026-09-12 19:14:19
(17 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 15:11:06
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.91.166 (166.91.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.91.166 (166.91.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 11:10:59.223326 2026] [security2:error] [pid 30908:tid 30908] [client 34.39.91.166:51852] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pharmaceuticalsalescertifications.com"] [uri "/.git/config"] [unique_id "aqVrg1ISvoxAjdPDpqwYCAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Hazzard
2026-09-12 14:29:15
(22 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
🇺🇸
TPI-Abuse
2026-09-12 13:43:37
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.91.166 (166.91.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.91.166 (166.91.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 09:43:32.399097 2026] [security2:error] [pid 2388:tid 2388] [client 34.39.91.166:35550] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "phantomquailkennel.com"] [uri "/.git/config"] [unique_id "aqVXBJYAvqSclD7Ja2dRuwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Alt255
2026-09-12 13:08:02
(23 hours ago)
34.39.91.166 - - [12/Sep/2026:15:08:01 +0200] "GET /.env.remote HTTP/1.1" 301 558 "-" "Mozilla/5.0 ( ...
show more
34.39.91.166 - - [12/Sep/2026:15:08:01 +0200] "GET /.env.remote HTTP/1.1" 301 558 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-12 12:24:07
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 12:11:02
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.39.91.166 (166.91.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.91.166 (166.91.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 08:10:55.907208 2026] [security2:error] [pid 16564:tid 16564] [client 34.39.91.166:54780] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "phalanxemail.axiomemail.net"] [uri "/.git/config"] [unique_id "aqVBT1pf17rTiN5NHCuMqAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇿
Prcek
2026-09-12 10:46:45
(1 day ago)
PortScan:HOST=34.39.91.166,DPORTS=443
Port Scan
🇩🇪
FeG Deutschland
2026-09-12 10:40:16
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
Anonymous
2026-09-12 08:36:44
(1 day ago)
[server.tmg.gr] httpd-config-scan: sites=www.ph-achd2024.com; logs=/var/log/httpd/domains/ph-achd202 ...
show more
[server.tmg.gr] httpd-config-scan: sites=www.ph-achd2024.com; logs=/var/log/httpd/domains/ph-achd2024.com.log; samples=/.git/config | /.env | /.env.local
show less
Hacking
Web App Attack
🇧🇪
cmbplf
2026-09-12 08:34:19
(1 day ago)
7.920 requests with url.path *.env
128 requests with url.path *.php.bak
Brute-Force
Bad Web Bot
🇳🇱
Site.eu
2026-09-12 08:09:43
(1 day ago)
Excessive multi-domain requests
Brute-Force
🇫🇷
masterguru
2026-09-12 07:57:14
(1 day ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 05:00:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.39.91.166 (166.91.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.91.166 (166.91.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 01:00:04.736750 2026] [security2:error] [pid 12067:tid 12067] [client 34.39.91.166:46964] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "petsnality.com"] [uri "/.git/config"] [unique_id "aqTcVJ6FOONZrYBN5T99YwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
elcruzado.es
2026-09-12 03:39:18
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 34.39.91.166 (GB/United Kingdom/166.91. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.39.91.166 (GB/United Kingdom/166.91.39.34.bc.googleusercontent.com)
show less
SQL Injection