๐บ๐ธ
TPI-Abuse
2026-09-08 16:43:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.172.116 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.172.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:43:39.644421 2026] [security2:error] [pid 16143:tid 16143] [client 104.23.172.116:10464] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "infrared-heaters.us"] [uri "/.git/config"] [unique_id "aqA7O2wUdjIjF2IM6MA-EgAAADU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
sandra361
2026-09-06 11:34:32
(3 days ago)
Port scan detected: 6 attempts across 1 port (443). | Evidence: REAPER_TARPIT: IN=enp1s0f0 SRC=104.2 ...
show more
Port scan detected: 6 attempts across 1 port (443). | Evidence: REAPER_TARPIT: IN=enp1s0f0 SRC=104.23.172.116 LEN=40 TOS=0x00 PREC=0x00 TTL=55 ID=17629 DF PROTO=TCP SPT=9797 DPT=443 WINDOW=65535 RES=0x00 ACK RST URGP=0
show less
Port Scan
๐ฏ๐ต
S.O.B.A. Dev.
2026-08-29 08:54:39
(1 week ago)
Persistent port scanning or vulnerability scanning
Port Scan
Anonymous
2026-08-15 05:02:07
(3 weeks ago)
104.23.172.116 - - [15/Aug/2026:07:02:05 +0200] "GET /* HTTP/1.1" 404 445 "-" "Mozilla/5.0 (Windows ...
show more
104.23.172.116 - - [15/Aug/2026:07:02:05 +0200] "GET /* HTTP/1.1" 404 445 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:127.0) Gecko/20100101 Firefox/127.0"
104.23.172.116 - - [15/Aug/2026:07:02:05 +0200] "GET /* HTTP/1.1" 404 249 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:127.0) Gecko/20100101 Firefox/127.0"
104.23.172.116 - - [15/Aug/2026:07:02:05 +0200] "GET /%2egit/%63onfig HTTP/1.1" 404 445 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 Edg/126.0.0.0"
104.23.172.116 - - [15/Aug/2026:07:02:05 +0200] "GET /%2egit/%63onfig HTTP/1.1" 404 249 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 Edg/126.0.0.0"
104.23.172.116 - - [15/Aug/2026:07:02:05 +0200] "GET /%2eenv HTTP/1.1" 404 445 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14.5; rv:127.0) Gecko/20100101 Firefox/127.0"
104.23.172.116 - - [15/Aug/2026:07:02:05 +0200] "GET /%2eenv HTTP/1.1
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-08-06 13:06:02
(1 month ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_admin, ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_admin, shared-egress:cloudflare. Observed by 1 sensor(s); 4 hits.
show less
Brute-Force
Web App Attack
๐ง๐ช
madeit
2026-08-05 14:35:29
(1 month ago)
Web App Attack
๐ท๐บ
DZBOT
2026-08-04 14:10:02
(1 month ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2026-07-29 04:32:49
(1 month ago)
Persistent port scanning or vulnerability scanning
Port Scan
Anonymous
2026-07-27 15:40:26
(1 month ago)
104.23.172.116 - - [27/Jul/2026:17:40:25 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 40 ...
show more
104.23.172.116 - - [27/Jul/2026:17:40:25 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 445 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36"
104.23.172.116 - - [27/Jul/2026:17:40:25 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 249 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36"
104.23.172.116 - - [27/Jul/2026:17:40:26 +0200] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 445 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36"
104.23.172.116 - - [27/Jul/2026:17:40:26 +0200] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 249 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36"
104.23.172.116 - - [27/Jul/2026:17:40:26 +0200] "GET //wp/wp-includes/wlwmanif
...
show less
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-07-23 02:50:37
(1 month ago)
Multiple WAF Violations
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2026-07-20 03:28:03
(1 month ago)
Persistent port scanning or vulnerability scanning
Port Scan
Anonymous
2026-07-19 20:39:38
(1 month ago)
104.23.172.116 - - [19/Jul/2026:22:39:36 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 445 ...
show more
104.23.172.116 - - [19/Jul/2026:22:39:36 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 445 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.172.116 - - [19/Jul/2026:22:39:36 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 249 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.172.116 - - [19/Jul/2026:22:39:37 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 445 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.172.116 - - [19/Jul/2026:22:39:37 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 249 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.172.116 - - [19/Jul/2026:22:39:37 +0200] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/
...
show less
Brute-Force
Web App Attack
Anonymous
2026-07-17 14:42:15
(1 month ago)
104.23.172.116 - - [17/Jul/2026:16:42:14 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 445 ...
show more
104.23.172.116 - - [17/Jul/2026:16:42:14 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 445 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
104.23.172.116 - - [17/Jul/2026:16:42:14 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 249 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
104.23.172.116 - - [17/Jul/2026:16:42:15 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 445 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
104.23.172.116 - - [17/Jul/2026:16:42:15 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 249 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
104.23.172.116 - - [17/Jul/2026:16:42:15 +0200] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/1.1"
...
show less
Brute-Force
Web App Attack
Anonymous
2026-07-16 06:17:36
(1 month ago)
(caddyscan) Scanner path probe from 104.23.172.116 (NL/The Netherlands/-): 5 in the last 3600 secs; ...
show more
(caddyscan) Scanner path probe from 104.23.172.116 (NL/The Netherlands/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 104.23.172.116 - - [16/Jul/2026:06:17:29 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 104.23.172.116 - - [16/Jul/2026:06:17:31 +0000] "GET /.aws/credentials HTTP/1.1"
[REDACTED] 200 2627 104.23.172.116 - - [16/Jul/2026:06:17:31 +0000] "GET /.env.bak HTTP/1.1"
[REDACTED] 200 2627 104.23.172.116 - - [16/Jul/2026:06:17:32 +0000] "GET /.env.aws HTTP/1.1"
[REDACTED] 200 2627 104.23.172.116 - - [16/Jul/2026:06:17:32 +0000] "GET /.env.local HTTP/1.1"
show less
Port Scan
๐ท๐บ
DZBOT
2026-07-07 17:41:54
(2 months ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack