Neutral Activity
There is no recent abuse activity, or the IP address is whitelisted.
Whitelisted Subnet
Whitelisted netblocks are typically owned by trusted entities, such as Google or Microsoft who
may use them for search engine spiders. However, these same entities sometimes also provide cloud
servers and mail services which are easily abused. Pay special attention when trusting or
distrusting these IPs.
This IP address has been reported a total of
80
times from
29 distinct
sources.
104.23.217.162 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
United States of America
with 20
reports;
United Kingdom of Great Britain and Northern Ireland
with 8
reports;
Singapore
with 3
reports.
The most common categories in these recent reports were:
Bad Web Bot
31
times;
Web App Attack
26
times;
Port Scan
9
times;
Brute-Force
6
times;
Hacking
3
times;
Other
2
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Automated honeypot detection. blocked ip against a Next.js application. Paths: /wp-admin/install.php ...
show moreAutomated honeypot detection. blocked ip against a Next.js application. Paths: /wp-admin/install.php?step=1. Blocked at the edge.
show less
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show moreWeb scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Automated honeypot detection. blocked ip against a Next.js application. Paths: /wp-admin/install.php ...
show moreAutomated honeypot detection. blocked ip against a Next.js application. Paths: /wp-admin/install.php?step=1. Blocked at the edge.
show less
Automated honeypot detection. blocked ip against a Next.js application. Paths: /wp-admin/install.php ...
show moreAutomated honeypot detection. blocked ip against a Next.js application. Paths: /wp-admin/install.php?step=1. Blocked at the edge.
show less
[cb-01vi] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more[cb-01vi] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 104.23.217.162 - - [29/Sep/2026:19:47:44 +0200] "GET /.env.production.local HTTP/1.1" 301 507 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.4 Safari/605.1.15"
...
show less
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. ...
show moreAutomated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. Blocked at the edge.
show less
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad ...
show moreFail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad bot behaviour. Technical log details and local server identifiers intentionally omitted for privacy.
show less
Automated honeypot detection. blocked ip against a Next.js application. Paths: /wp-admin/install.php ...
show moreAutomated honeypot detection. blocked ip against a Next.js application. Paths: /wp-admin/install.php?step=1, /wp-admin/install.php. Blocked at the edge.
show less
Automated honeypot detection. blocked ip against a Next.js application. Paths: /wp-admin/install.php ...
show moreAutomated honeypot detection. blocked ip against a Next.js application. Paths: /wp-admin/install.php, /wp-admin/install.php?step=1. Blocked at the edge.
show less
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad ...
show moreFail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad bot behaviour. Technical log details and local server identifiers intentionally omitted for privacy.
show less