Anonymous
2026-06-13 10:32:01
(1 day ago)
104.23.225.138 - - [13/Jun/2026:12:31:46 +0200] "GET /console/.env HTTP/1.1" 403 124 "-" "curl/8.7.1 ...
show more
104.23.225.138 - - [13/Jun/2026:12:31:46 +0200] "GET /console/.env HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.23.225.138 - - [13/Jun/2026:12:31:46 +0200] "GET /administrator/config/.env HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.23.225.138 - - [13/Jun/2026:12:31:46 +0200] "GET /sysadmin/.env HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.23.225.138 - - [13/Jun/2026:12:31:46 +0200] "GET /dbadmin/.env HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.23.225.138 - - [13/Jun/2026:12:31:47 +0200] "GET /master/.env HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.23.225.138 - - [13/Jun/2026:12:31:47 +0200] "GET /tmp/.env HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.23.225.138 - - [13/Jun/2026:12:31:47 +0200] "GET /cgi-bin/.env HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.23.225.138 - - [13/Jun/2026:12:31:47 +0200] "GET /blogs/.env HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.23.225.138 - - [13/Jun/2026:12:31:48 +0200] "GET /forum/.env HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.23.225.138 - - [13/Jun/2026:12:31:48 +0200] "GET /store/.env HTTP/1.1" 40
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 18:50:47
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.138 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 14:50:41.010991 2026] [security2:error] [pid 2987:tid 2987] [client 104.23.225.138:13909] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webtestbed.com.convoyforkids.com"] [uri "/.git/config"] [unique_id "aicPAe-sGVB4pBkPGyFN5gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 17:57:53
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.138 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 13:57:46.206995 2026] [security2:error] [pid 5820:tid 5820] [client 104.23.225.138:9444] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "htaautosales.com.modeltdr.com"] [uri "/.git/config"] [unique_id "aicCmmEB3_MWY-TplKYSGQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
cg-design.co.uk
2026-06-07 14:49:49
(1 week ago)
(mod_security) mod_security triggered on hostname [redacted] 104.23.225.138 (FR/France/-)
SQL Injection
๐ง๐พ
lns.bz
2026-06-05 06:25:51
(1 week ago)
.env scanning [BY]
Web App Attack
๐ง๐พ
lns.bz
2026-05-12 20:17:15
(1 month ago)
.env scanning [BY]
Web App Attack
Anonymous
2026-05-09 09:58:58
(1 month ago)
104.23.225.138 - - [09/May/2026:11:58:57 +0200] "GET //wp/wp-includes/wlwmanifest.xml HTTP/1.0" 404 ...
show more
104.23.225.138 - - [09/May/2026:11:58:57 +0200] "GET //wp/wp-includes/wlwmanifest.xml HTTP/1.0" 404 455 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.225.138 - - [09/May/2026:11:58:57 +0200] "GET //wp/wp-includes/wlwmanifest.xml HTTP/1.1" 404 243 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.225.138 - - [09/May/2026:11:58:57 +0200] "GET //news/wp-includes/wlwmanifest.xml HTTP/1.0" 404 455 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.225.138 - - [09/May/2026:11:58:57 +0200] "GET //news/wp-includes/wlwmanifest.xml HTTP/1.1" 404 243 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.225.138 - - [09/May/2026:11:58:58 +0200] "GET //2018/wp-includes/wlwmanifest.xml HTTP
...
show less
Brute-Force
Web App Attack
Anonymous
2026-04-27 08:37:38
(1 month ago)
104.23.225.138 - - [27/Apr/2026:10:37:37 +0200] "GET //wp1/wp-includes/wlwmanifest.xml HTTP/1.0" 404 ...
show more
104.23.225.138 - - [27/Apr/2026:10:37:37 +0200] "GET //wp1/wp-includes/wlwmanifest.xml HTTP/1.0" 404 455 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.225.138 - - [27/Apr/2026:10:37:37 +0200] "GET //wp1/wp-includes/wlwmanifest.xml HTTP/1.1" 404 243 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.225.138 - - [27/Apr/2026:10:37:38 +0200] "GET //test/wp-includes/wlwmanifest.xml HTTP/1.0" 404 455 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.225.138 - - [27/Apr/2026:10:37:38 +0200] "GET //test/wp-includes/wlwmanifest.xml HTTP/1.1" 404 243 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.225.138 - - [27/Apr/2026:10:37:38 +0200] "GET //media/wp-includes/wlwmanifest.xml H
...
show less
Brute-Force
Web App Attack
๐ง๐พ
lns.bz
2026-04-18 10:19:00
(1 month ago)
.env scanning [BY]
Web App Attack
Anonymous
2026-04-17 22:28:35
(1 month ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-04-15 18:02:51
(1 month ago)
104.23.225.138 - - [15/Apr/2026:21:02:37 +0300] "GET /Socketio/.env HTTP/1.1" 404 762 "-" "curl/8.7. ...
show more
104.23.225.138 - - [15/Apr/2026:21:02:37 +0300] "GET /Socketio/.env HTTP/1.1" 404 762 "-" "curl/8.7.1"
104.23.225.138 - - [15/Apr/2026:21:02:50 +0300] "GET /src/__tests__/__fixtures__/instanceWithDependentSteps/.env HTTP/1.1" 404 762 "-" "curl/8.7.1"
...
show less
Web App Attack
๐ง๐พ
lns.bz
2026-04-14 19:06:28
(2 months ago)
.env scanning [BY]
Web App Attack
๐ฌ๐ง
cg-design.co.uk
2026-04-11 17:10:34
(2 months ago)
(mod_security) mod_security triggered on hostname [redacted] 104.23.225.138 (FR/France/-)
SQL Injection
Anonymous
2026-04-06 18:25:40
(2 months ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
Anonymous
2026-03-28 20:18:09
(2 months ago)
104.23.225.138 - - [28/Mar/2026:22:16:22 +0200] "GET /wp-includes/ HTTP/1.0" 404 455 "-" "python-req ...
show more
104.23.225.138 - - [28/Mar/2026:22:16:22 +0200] "GET /wp-includes/ HTTP/1.0" 404 455 "-" "python-requests/2.32.5"
104.23.225.138 - - [28/Mar/2026:22:16:22 +0200] "GET /wp-includes/ HTTP/1.1" 404 243 "-" "python-requests/2.32.5"
104.23.225.138 - - [28/Mar/2026:22:17:55 +0200] "GET /wp-content/themes/config.bak.php HTTP/1.0" 404 455 "www.google.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36"
104.23.225.138 - - [28/Mar/2026:22:17:55 +0200] "GET /wp-content/themes/config.bak.php HTTP/1.1" 404 243 "www.google.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36"
104.23.225.138 - - [28/Mar/2026:22:18:09 +0200] "GET /wp-content/wp-admin.php HTTP/1.0" 404 455 "-" "python-requests/2.32.5"
...
show less
Brute-Force
Web App Attack