This IP address has been reported a total of
30
times from
22 distinct
sources.
104.196.123.105 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
Anonymous
Bot / scanning and/or hacking attempts: GET /var/www/.git/config HTTP/1.1, GET /public/.git/config H ...
show moreBot / scanning and/or hacking attempts: GET /var/www/.git/config HTTP/1.1, GET /public/.git/config HTTP/1.1, GET /api/.git/config HTTP/1.1, GET /.git/config HTTP/1.1, GET /www/.git/config HTTP/1.1, GET /html/.git/config HTTP/1.1
show less
[FriAug2822:44:33.3690602026][security2:error][pid2942629:tid2943057][client104.196.123.105:0]ModSec ...
show more[FriAug2822:44:33.3690602026][security2:error][pid2942629:tid2943057][client104.196.123.105:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"duoacaja.com\"][uri\"/site/.git/config\"][unique_id\"apHzMYAfJufQZkUDuZmtJgAAAQg\"]
show less
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show moreAuto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-26.
show less