๐ซ๐ท
dynamix
2026-09-12 16:57:48
(8 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-09 10:33:25
(3 days ago)
104.22.104.63 - - [09/Sep/2026:12:33:10 +0200] "GET /site/.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (M ...
show more
104.22.104.63 - - [09/Sep/2026:12:33:10 +0200] "GET /site/.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.22.104.63 - - [09/Sep/2026:12:33:22 +0200] "GET /microservice/.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.22.104.63 - - [09/Sep/2026:12:33:22 +0200] "GET /service/.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.22.104.63 - - [09/Sep/2026:12:33:22 +0200] "GET /api/v3/.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.22.104.63 - - [09/Sep/2026:12:33:22 +0200] "GET /api/dev/.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, lik
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 13:53:09
(1 week ago)
104.22.104.63 - - [05/Sep/2026:15:53:01 +0200] "GET /html/.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (W ...
show more
104.22.104.63 - - [05/Sep/2026:15:53:01 +0200] "GET /html/.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.22.104.63 - - [05/Sep/2026:15:53:02 +0200] "GET /live/.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.22.104.63 - - [05/Sep/2026:15:53:02 +0200] "GET /prod/.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.22.104.63 - - [05/Sep/2026:15:53:02 +0200] "GET /dev/.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.22.104.63 - - [05/Sep/2026:15:53:03 +0200] "GET /opt/.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.22.
...
show less
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-29 13:46:48
(2 weeks ago)
Web App Attack
๐ฎ๐ฉ
securejdprop
2026-08-21 06:05:34
(3 weeks ago)
This IP was detected by CrowdSec triggering custom/vpatch-bad-cloudflare.
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-16 10:25:25
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.22.104.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.104.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 06:25:20.380085 2026] [security2:error] [pid 9710:tid 9710] [client 104.22.104.63:9868] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "uosmikveh.passy.us"] [uri "/.git/HEAD"] [unique_id "aoGQEFBcFEUUubXrz7TrswAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 07:59:46
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.104.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.104.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 03:59:40.482005 2026] [security2:error] [pid 3875861:tid 3875861] [client 104.22.104.63:11886] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.kathleenhazlett.com"] [uri "/.git/HEAD"] [unique_id "anrWbLZ9brBxaOy6TWSRLAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-08 08:20:30
(1 month ago)
Web App Attack
๐ฉ๐ช
abdubhai
2026-07-19 12:38:07
(1 month ago)
104.22.104.63 - - [19/Jul/2026:1
...
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-15 08:16:10
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.22.104.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.104.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:15:45.154988 2026] [security2:error] [pid 30985:tid 30985] [client 104.22.104.63:12271] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "moanddoyle.michaelprussin.com"] [uri "/.env.development.local"] [unique_id "agbWMbpGD_gCmKINdBhLcQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 06:40:50
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.22.104.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.104.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 02:39:30.972142 2026] [security2:error] [pid 7837:tid 7837] [client 104.22.104.63:13213] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "atlanticcitypartybuses.com"] [uri "/.env.dev"] [unique_id "aga_ouimxmFNeibaLxSc1QAAADQ"], referer: https://www.google.com/search?q=atlanticcitypartybuses.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-14 04:23:18
(3 months ago)
(caddyscan) Scanner path probe from 104.22.104.63 (US/United States/-): 5 in the last 3600 secs; Por ...
show more
(caddyscan) Scanner path probe from 104.22.104.63 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 104.22.104.63 - - [14/May/2026:03:52:04 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.22.104.63 - - [14/May/2026:04:02:59 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.22.104.63 - - [14/May/2026:04:03:09 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.22.104.63 - - [14/May/2026:04:06:31 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.22.104.63 - - [14/May/2026:04:23:14 +0000] "GET /.git/config HTTP/1.1"
show less
Port Scan
๐ณ๐ฑ
wolfemium
2026-05-11 21:54:03
(4 months ago)
104.22.104.63 - - [12/May/2026:00:53:59 +0300] "GET /layout.php HTTP/1.1" 502 150 "-" "-"
104.22.104 ...
show more
104.22.104.63 - - [12/May/2026:00:53:59 +0300] "GET /layout.php HTTP/1.1" 502 150 "-" "-"
104.22.104.63 - - [12/May/2026:00:54:01 +0300] "GET /simple.php HTTP/1.1" 502 150 "-" "-"
104.22.104.63 - - [12/May/2026:00:54:02 +0300] "GET /ws81.php HTTP/1.1" 502 150 "-" "-"
104.22.104.63 - - [12/May/2026:00:54:02 +0300] "GET //av.php HTTP/1.1" 502 150 "-" "-"
104.22.104.63 - - [12/May/2026:00:54:02 +0300] "GET //xfile25.php HTTP/1.1" 502 150 "-" "-"
104.22.104.63 - - [12/May/2026:00:54:02 +0300] "GET /wpxml.php HTTP/1.1" 502 150 "-" "-"
...
show less
DDoS Attack
๐ฆ๐บ
trentwiles.com
2026-05-10 06:22:25
(4 months ago)
Unauthorized connection attempt detected from IP address 104.22.104.63 to port 443 [SYD]
Port Scan