This IP address has been reported a total of
74
times from
53 distinct
sources.
104.199.134.153 was first reported on
, and the most recent report was
.
Old Reports:
The most recent abuse report for this IP address is from
. It is possible that this IP is no longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: TW, Attack patterns: Word ...
show moreBlocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: TW, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
133 attacks on PHP URLs, env grabbing URLs, config grabbing URLs (type 2), site downloads, deploymen ...
show more133 attacks on PHP URLs, env grabbing URLs, config grabbing URLs (type 2), site downloads, deployment descriptor URLs, password grabbing URLs:
GET /info.php HTTP/1.1
GET /aws/.env HTTP/1.1
GET /vault.yml HTTP/1.1
GET /db.sql HTTP/1.1
GET /WEB-INF/web.xml HTTP/1.1
GET /admin/config?cmd=cat+/root/.aws/credentials HTTP/1.1
show less
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: TW, Attack patterns: Word ...
show moreBlocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: TW, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
{"level":"info","ts":1786633867.9603314,"logger":"http.log.access.log0","msg":"handled request","req ...
show more{"level":"info","ts":1786633867.9603314,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"104.199.134.153","remote_port":"30868","client_ip":"104.199.134.153","proto":"HTTP/1.1","method":"GET","host":"d1xs.status.updown.io","uri":"/static../etc/passwd","headers":{"Accept":["text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8"],"Accept-Language":["en-US,en;q=0.9"],"Accept-Encoding":["gzip"],"User-Agent":["Mozilla/5.0 (compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot)"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"","server_name":"d1xs.status.updown.io","ech":false}},"bytes_read":0,"user_id":"","duration":0.000363333,"size":0,"status":429,"resp_headers":{"Retry-After":["1"],"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"]}}
{"level":"info","ts":1786633867.9772842,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"104.199.134.153","remote_port":"30794","clien
...
show less
(mod_security) mod_security triggered on hostname [redacted] 104.199.134.153 (TW/Taiwan/153.134.199. ...
show more(mod_security) mod_security triggered on hostname [redacted] 104.199.134.153 (TW/Taiwan/153.134.199.104.bc.googleusercontent.com)
show less
(modsecurity) srv201 ModSecurity 104.199.134.153 (TW/Taiwan/153.134.199.104.bc.googleusercontent.com ...
show more(modsecurity) srv201 ModSecurity 104.199.134.153 (TW/Taiwan/153.134.199.104.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
(mod_security) mod_security (id:210492) triggered by 104.199.134.153 (TW/Taiwan/153.134.199.104.bc.g ...
show more(mod_security) mod_security (id:210492) triggered by 104.199.134.153 (TW/Taiwan/153.134.199.104.bc.googleusercontent.com): 5 in the last 300 secs
show less