๐ฉ๐ช
netclix.gr
2026-10-07 12:02:08
(45 minutes ago)
(c5_sensitive_scan) Custom6 Sensitive File Exploit Blocked 172.245.103.91 (US/United States/172-245- ...
show more
(c5_sensitive_scan) Custom6 Sensitive File Exploit Blocked 172.245.103.91 (US/United States/172-245-103-91-host.colocrossing.com)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-07 09:25:36
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.245.103.91 (172-245-103-91-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 172.245.103.91 (172-245-103-91-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 05:25:18.133317 2026] [security2:error] [pid 19915:tid 19915] [client 172.245.103.91:39008] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.creertest.com.creartest.com"] [uri "/.git/HEAD"] [unique_id "asYP_vJe1JLd5WPXKJMGSgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 01:36:50
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.245.103.91 (172-245-103-91-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 172.245.103.91 (172-245-103-91-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 21:36:35.039694 2026] [security2:error] [pid 6585:tid 6639] [client 172.245.103.91:41781] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "notary.brucejoell.com"] [uri "/.git/HEAD"] [unique_id "asWiI-tqZxVttfvCVp6ikQAAAZU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
internetworld
2026-10-03 17:40:34
(3 days ago)
172.245.103.91 - - [03/Oct/2026:17:40:32 +0000] "GET /.git/HEAD HTTP/1.1" 200 513 "-" "Python-urllib ...
show more
172.245.103.91 - - [03/Oct/2026:17:40:32 +0000] "GET /.git/HEAD HTTP/1.1" 200 513 "-" "Python-urllib/3.10"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 13:06:30
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.245.103.91 (172-245-103-91-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 172.245.103.91 (172-245-103-91-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 09:06:21.182735 2026] [security2:error] [pid 12922:tid 12922] [client 172.245.103.91:58546] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nearbyxm.com.15cherryavenue.com"] [uri "/.git/HEAD"] [unique_id "asD9zc9Yq6W6_lmEHCdQ6AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 11:34:34
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.245.103.91 (172-245-103-91-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 172.245.103.91 (172-245-103-91-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 07:34:21.196453 2026] [security2:error] [pid 2189:tid 2189] [client 172.245.103.91:48490] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.3beeze.bridgital.com"] [uri "/.git/HEAD"] [unique_id "asDoPb_VBE3IcnDSEYzNLQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 12:05:50
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.245.103.91 (172-245-103-91-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 172.245.103.91 (172-245-103-91-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 08:05:45.542529 2026] [security2:error] [pid 22773:tid 22794] [client 172.245.103.91:54072] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.paylessformedicine.com"] [uri "/.git/HEAD"] [unique_id "arpYGVvsHe6GTGJjuqIH4wAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 09:27:13
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.245.103.91 (172-245-103-91-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 172.245.103.91 (172-245-103-91-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 05:26:48.745997 2026] [security2:error] [pid 25724:tid 25724] [client 172.245.103.91:34791] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.calendarsprinted.com.piratecostumesonline.com"] [uri "/.git/HEAD"] [unique_id "aroy2IdZsBAekdvlb-CTcgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 01:18:45
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.245.103.91 (172-245-103-91-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 172.245.103.91 (172-245-103-91-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 21:18:42.235866 2026] [security2:error] [pid 11100:tid 11127] [client 172.245.103.91:54690] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "12am.com"] [uri "/.git/HEAD"] [unique_id "arnAcu8pDKTMCVW_FStDGwAAAJA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-24 02:18:37
(1 week ago)
[24/Sep/2026:05:18:37 +0300] -- 172.245.103.91 Ban reason: User-Agent Python-urllib
Bad Web Bot
Web App Attack
๐ญ๐บ
kranem
2026-09-23 18:00:28
(1 week ago)
Triggered Cloudflare WAF from US.
Action taken: BLOCK
ASN: 36352 (HostPapa)
Protocol: HTTP/1.1 (GET ...
show more
Triggered Cloudflare WAF from US.
Action taken: BLOCK
ASN: 36352 (HostPapa)
Protocol: HTTP/1.1 (GET method)
Endpoint: /
Timestamp: 2026-09-23T15:30:19Z
User-Agent: Python-urllib/3.10
show less
Bad Web Bot
๐ฉ๐ช
LRob
2026-09-23 14:03:33
(1 week ago)
This address is looking for secret files on our sites: .git directories, .env files, credential and ...
show more
This address is looking for secret files on our sites: .git directories, .env files, credential and configuration files, database dumps, backups. This is a targeted search for credentials to break into the sites, blocked at the first request. Please check the machine behind it for an attack tool or malware. | method: GET | path: /.git/HEAD | 2026-09-23 14:03 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 10:31:02
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.245.103.91 (172-245-103-91-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 172.245.103.91 (172-245-103-91-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 06:30:58.498469 2026] [security2:error] [pid 11075:tid 11075] [client 172.245.103.91:35127] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rmhpolarracing.com.wolter-hausser.com"] [uri "/.git/HEAD"] [unique_id "arJY4jRZ5ltqYidtfGbY8gAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 07:40:21
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.245.103.91 (172-245-103-91-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 172.245.103.91 (172-245-103-91-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 03:40:16.884774 2026] [security2:error] [pid 30018:tid 30018] [client 172.245.103.91:47487] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.penisbreath.com.whoore.com"] [uri "/.git/HEAD"] [unique_id "arIw4PDwQCPbZloFjK_GPgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-22 06:13:21
(2 weeks ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 2 domain(s) in 0s
Web App Attack