π―π΅
S.O.B.A. Dev.
2026-10-04 15:31:55
(7 hours ago)
Persistent port scanning or vulnerability scanning
Port Scan
π§π·
chronos
2026-10-03 14:30:52
(1 day ago)
2026-10-03 11:04:47 UTC-3||Unauthorized connection attempt detected for port scanning
Port Scan
πΊπΈ
TPI-Abuse
2026-09-30 00:33:38
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.103 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 20:33:32.699872 2026] [security2:error] [pid 24532:tid 24532] [client 104.23.225.103:11416] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crr-construction.com"] [uri "/.git/config"] [unique_id "arxY3A5t5_ABbXEYxDSfSAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
netclix.gr
2026-09-29 22:26:48
(5 days ago)
(PERMBLOCK) 104.23.225.103 (FR/France/-) has had more than 2 temp blocks in the last 604800 secs; Po ...
show more
(PERMBLOCK) 104.23.225.103 (FR/France/-) has had more than 2 temp blocks in the last 604800 secs; Ports: *; Direction: inout; Trigger: LF_PERMBLOCK_COUNT; Logs:
show less
Port Scan
π©πͺ
robotstxt
2026-09-28 20:09:12
(6 days ago)
104.23.225.103 - - [28/Sep/2026:20:08:40 +0000] "GET /.git/config.orig.bak HTTP/2.0" 403 95761 "-" " ...
show more
104.23.225.103 - - [28/Sep/2026:20:08:40 +0000] "GET /.git/config.orig.bak HTTP/2.0" 403 95761 "-" "curl/8.7.1" "127.0.0.1,185.177.72.69" edge="104.23.225.103"
104.23.225.103 - - [28/Sep/2026:20:08:43 +0000] "GET /var/www/html/routes/.env HTTP/2.0" 403 95747 "-" "curl/8.7.1" "127.0.0.1,185.177.72.69" edge="104.23.225.103"
104.23.225.103 - - [28/Sep/2026:20:08:44 +0000] "GET /.aws/credentials_service HTTP/2.0" 403 95525 "-" "curl/8.7.1" "127.0.0.1,185.177.72.69" edge="104.23.225.103"
104.23.225.103 - - [28/Sep/2026:20:08:43 +0000] "GET /var/www/html/routes/.env HTTP/2.0" 403 95747 "-" "curl/8.7.1" "127.0.0.1,185.177.72.69" edge="104.23.225.103"
104.23.225.103 - - [28/Sep/2026:20:08:44 +0000] "GET /.aws/credentials_service HTTP/2.0" 403 95525 "-" "curl/8.7.1" "127.0.0.1,185.177.72.69" edge="104.23.225.103"
...
show less
Web App Attack
π©πͺ
robotstxt
2026-09-28 16:40:13
(6 days ago)
104.23.225.103 - - [28/Sep/2026:16:39:36 +0000] "GET /src/.env.production.local HTTP/2.0" 403 95552 ...
show more
104.23.225.103 - - [28/Sep/2026:16:39:36 +0000] "GET /src/.env.production.local HTTP/2.0" 403 95552 "-" "curl/8.7.1" "127.0.0.1,185.177.72.56" edge="104.23.225.103"
104.23.225.103 - - [28/Sep/2026:16:39:38 +0000] "GET /usr/bin/.env HTTP/2.0" 403 95928 "-" "curl/8.7.1" "127.0.0.1,185.177.72.56" edge="104.23.225.103"
104.23.225.103 - - [28/Sep/2026:16:39:41 +0000] "GET /.env.sendgrid HTTP/2.0" 403 95728 "-" "curl/8.7.1" "127.0.0.1,185.177.72.56" edge="104.23.225.103"
104.23.225.103 - - [28/Sep/2026:16:39:45 +0000] "GET /.aws/credentials.orig HTTP/2.0" 403 95665 "-" "curl/8.7.1" "127.0.0.1,185.177.72.56" edge="104.23.225.103"
104.23.225.103 - - [28/Sep/2026:16:39:58 +0000] "GET /rails-app/server/.env HTTP/2.0" 403 95605 "-" "curl/8.7.1" "127.0.0.1,185.177.72.56" edge="104.23.225.103"
...
show less
Web App Attack
π©πͺ
netclix.gr
2026-09-27 12:58:29
(1 week ago)
(bot_kill_mega) Aggressive Bot Blocked: Go-http-client 104.23.225.103 (FR/France/-): 1 in the last 4 ...
show more
(bot_kill_mega) Aggressive Bot Blocked: Go-http-client 104.23.225.103 (FR/France/-): 1 in the last 4600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 104.23.225.103 - - [27/Sep/2026:15:58:01 +0300] "GET /login_up.php HTTP/2.0" 200 29661 "-" "Go-http-client/1.1" "90.24.14.227"'/login_up.php' '' '/opt/psa/admin/htdocs'
show less
Port Scan
π©πͺ
robotstxt
2026-09-26 05:33:13
(1 week ago)
104.23.225.103 - - [26/Sep/2026:05:32:11 +0000] "GET /.aws/credentials HTTP/2.0" 403 0 "-" "Mozilla/ ...
show more
104.23.225.103 - - [26/Sep/2026:05:32:11 +0000] "GET /.aws/credentials HTTP/2.0" 403 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" "35.241.202.92" edge="104.23.225.103"
104.23.225.103 - - [26/Sep/2026:05:32:11 +0000] "GET /.docker/.env HTTP/2.0" 403 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" "35.241.202.92" edge="104.23.225.103"
104.23.225.103 - - [26/Sep/2026:05:32:11 +0000] "GET /.aws/credentials.bak HTTP/2.0" 403 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" "35.241.202.92" edge="104.23.225.103"
104.23.225.103 - - [26/Sep/2026:05:32:11 +0000] "GET /.config/gcloud/application_default_credentials.json HTTP/2.0" 403 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" "35.241.202.92" edge="104.23.225.103"
104.23.225.103 - - [26/Sep/2026:05:32:11 +0000] "GET /.claude/settings.json HTTP/2.0" 403 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" "35.241.202.92" edge="104.23.225.103"
...
show less
Web App Attack
π©πͺ
netclix.gr
2026-09-25 18:22:31
(1 week ago)
(bot_kill_mega) Aggressive Bot Blocked: Go-http-client 104.23.225.103 (FR/France/-): 1 in the last 4 ...
show more
(bot_kill_mega) Aggressive Bot Blocked: Go-http-client 104.23.225.103 (FR/France/-): 1 in the last 4600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 104.23.225.103 - - [25/Sep/2026:21:22:05 +0300] "GET /login_up.php HTTP/2.0" 200 29663 "-" "Go-http-client/1.1" "62.210.70.254"'/login_up.php' '' '/opt/psa/admin/htdocs'
show less
Port Scan
π³π±
hxsain
2026-09-25 13:16:59
(1 week ago)
Blocked by UFW [443/tcp] | SPT: 14204 | TTL: 56 | LEN: 60 | TOS: 0x00 β’ Reported by: github.com/sefi ...
show more
Blocked by UFW [443/tcp] | SPT: 14204 | TTL: 56 | LEN: 60 | TOS: 0x00 β’ Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-09-25 12:28:14
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.103 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 08:28:07.130524 2026] [security2:error] [pid 24586:tid 24586] [client 104.23.225.103:10338] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "conveyorizedovens.com"] [uri "/.git/config"] [unique_id "arZo1-thK0J4mP5mn0H4BQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π―π΅
S.O.B.A. Dev.
2026-09-25 11:11:56
(1 week ago)
Persistent port scanning or vulnerability scanning
Port Scan
π©πͺ
robotstxt
2026-09-21 00:40:33
(1 week ago)
104.23.225.103 - - [21/Sep/2026:00:39:26 +0000] "GET /.aws/credentials HTTP/2.0" 403 95136 "-" "curl ...
show more
104.23.225.103 - - [21/Sep/2026:00:39:26 +0000] "GET /.aws/credentials HTTP/2.0" 403 95136 "-" "curl/8.7.1" "127.0.0.1,185.177.72.31" edge="104.23.225.103"
104.23.225.103 - - [21/Sep/2026:00:39:28 +0000] "GET /.aws/config HTTP/2.0" 403 95088 "-" "curl/8.7.1" "127.0.0.1,185.177.72.31" edge="104.23.225.103"
104.23.225.103 - - [21/Sep/2026:00:39:29 +0000] "GET /.ssh HTTP/2.0" 403 95073 "-" "curl/8.7.1" "127.0.0.1,185.177.72.31" edge="104.23.225.103"
104.23.225.103 - - [21/Sep/2026:00:39:32 +0000] "GET /.ssh/authorized_keys HTTP/2.0" 403 95110 "-" "curl/8.7.1" "127.0.0.1,185.177.72.31" edge="104.23.225.103"
104.23.225.103 - - [21/Sep/2026:00:39:39 +0000] "GET /.rediscli_history HTTP/2.0" 403 95440 "-" "curl/8.7.1" "127.0.0.1,185.177.72.31" edge="104.23.225.103"
...
show less
Web App Attack
Anonymous
2026-09-18 06:29:29
(2 weeks ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
π«π·
dynamix
2026-09-17 23:22:37
(2 weeks ago)
Multiple WAF Violations
Web App Attack