This IP address has been reported a total of
41
times from
33 distinct
sources.
104.197.125.225 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[FriAug2813:29:57.6595812026][security2:error][pid2575142:tid2575221][client104.197.125.225:0]ModSec ...
show more[FriAug2813:29:57.6595812026][security2:error][pid2575142:tid2575221][client104.197.125.225:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"www.alessandrolucchini.ch\"][uri\"/storage/logs/laravel.log\"][unique_id\"apFxNVqhII4bt42uSksbCgAAAMM\"]
show less
Wazuh Alert | Rule ID: 110100 | Desc: Suricata: Exploit (ET WEB_SERVER Tilde in URI - potential .php ...
show moreWazuh Alert | Rule ID: 110100 | Desc: Suricata: Exploit (ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability) 104.197.125.225
show less
{"transaction":{"client_ip":"104.197.125.225","time_stamp":"Thu Aug 27 22:11:04 2026","server_id":"4 ...
show more{"transaction":{"client_ip":"104.197.125.225","time_stamp":"Thu Aug 27 22:11:04 2026","server_id":"46824fc494f03034e6b98e26d7a2d7a06b25f0b7","client_port":56276,"host_ip":"212.186.116.154","host_port":443,"unique_id":"17878614648.710288","is_interrupted":true,"request":{"method":"GET","http_version":"1.1","hostname":"212.186.116.154","uri":"/.env.local","headers":{"accept":"*/*","user-agent":"crusader-worker/1.0","host":"212.186.116.154"}},"response":{"http_code":403,"headers":{"Server":"nginx\u0000","Date":"Thu, 27 Aug 2026 20:11:04 GMT","Content-Length":"146","Content-Type":"text/html","Connection":"keep-alive"}},"producer":{"modsecurity":"ModSecurity v3.0.16 (Linux)","connector":"ModSecurity-nginx v1.0.4","secrules_engine":"Enabled","components":["OWASP_CRS/4.30.0-dev\""]},"messages":[{"message":"Host header is a numeric IP address","details":{"match":"Matched \"Operator `Rx' with parameter `(?:^([\\d.]+|\\[[\\da-f:]+\\]|[\\da-f:]+)(:[\\d]+)?$)' against variable `REQUEST_HEADERS:hos
...
show less
(mod_security) mod_security (id:210492) triggered by 104.197.125.225 (225.125.197.104.bc.googleuserc ...
show more(mod_security) mod_security (id:210492) triggered by 104.197.125.225 (225.125.197.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:47:47.790537 2026] [security2:error] [pid 19468:tid 19468] [client 104.197.125.225:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.empoweruamerica.org"] [uri "/.env.dev"] [unique_id "apCGUyQ58pTsdA3eFDrXxQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
Bot / scanning and/or hacking attempts: GET /.env.local HTTP/1.1, GET /.env.backup HTTP/1.1, GET /.e ...
show moreBot / scanning and/or hacking attempts: GET /.env.local HTTP/1.1, GET /.env.backup HTTP/1.1, GET /.env HTTP/1.1, GET /wp-config.php~ HTTP/1.1
show less
Hacking
Web App Attack
Showing 1 to
15
of 41 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ