๐ซ๐ท
dynamix
2026-09-18 00:37:44
(49 minutes ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-17 09:59:28
(15 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
Anonymous
2026-09-17 09:58:12
(15 hours ago)
104.23.225.155 - - [17/Sep/2026:11:58:11 +0200] "GET /.git/logs/HEAD HTTP/1.1" 403 124 "-" "Mozilla/ ...
show more
104.23.225.155 - - [17/Sep/2026:11:58:11 +0200] "GET /.git/logs/HEAD HTTP/1.1" 403 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
104.23.225.155 - - [17/Sep/2026:11:58:11 +0200] "GET /.gitmodules HTTP/1.1" 403 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
104.23.225.155 - - [17/Sep/2026:11:58:11 +0200] "GET /.git-credentials HTTP/1.1" 404 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
104.23.225.155 - - [17/Sep/2026:11:58:11 +0200] "GET /.git/COMMIT_EDITMSG HTTP/1.1" 403 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
104.23.225.155 - - [17/Sep/2026:11:58:11 +0200] "GET /.git/index HTTP/1.1" 403 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
104.23.225.155 - - [17/Sep/2026:11:58:11 +0200] "GET /.svn/entries HTTP/1.1" 403 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
104.23.225.155 - - [17/Sep/2026:11:58:11 +0200] "GET /.git/HEAD HTTP/1.1" 403
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
hxsain
2026-09-15 02:08:42
(2 days ago)
Blocked by UFW [443/tcp] | SPT: 11457 | TTL: 56 | LEN: 60 | TOS: 0x00 โข Reported by: github.com/sefi ...
show more
Blocked by UFW [443/tcp] | SPT: 11457 | TTL: 56 | LEN: 60 | TOS: 0x00 โข Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
Starburst SysOp Team
2026-09-08 08:45:06
(1 week ago)
(CT) IP 104.23.225.155 (FR/France/Paris Department/Paris/-) found to have 102 connections (0-mnz6-7)
Hacking
Anonymous
2026-09-02 12:34:55
(2 weeks ago)
104.23.225.155 - - [02/Sep/2026:14:34:47 +0200] "GET /tmp/phpinfo.php HTTP/1.1" 403 183 "-" "Mozilla ...
show more
104.23.225.155 - - [02/Sep/2026:14:34:47 +0200] "GET /tmp/phpinfo.php HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.23.225.155 - - [02/Sep/2026:14:34:47 +0200] "GET /public/phpinfo.php HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.23.225.155 - - [02/Sep/2026:14:34:47 +0200] "GET /php-info.php HTTP/1.1" 404 184 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.23.225.155 - - [02/Sep/2026:14:34:48 +0200] "GET /_phpinfo.php HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.23.225.155 - - [02/Sep/2026:14:34:48 +0200] "GET /server-info.php HTTP/1.1" 404 184 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.23.225.155 - - [02/
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-08-30 17:29:27
(2 weeks ago)
[SunAug3019:29:23.6599342026][security2:error][pid1557679:tid1557732][client104.23.225.155:0]ModSecu ...
show more
[SunAug3019:29:23.6599342026][security2:error][pid1557679:tid1557732][client104.23.225.155:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"respiratrentino.it\"][uri\"/.git/config\"][unique_id\"apRoc4GhTr8PiPLhzy31HgAAAIU\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2026-08-29 12:32:17
(2 weeks ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-29 12:19:57
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.155 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.155 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 08:19:50.180093 2026] [security2:error] [pid 13300:tid 13307] [client 104.23.225.155:10904] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "killyourattitude.com"] [uri "/.git/config"] [unique_id "apLOZq6oHidt2SyDYWrnlQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-08-29 02:21:35
(2 weeks ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 1 hits.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 20:36:49
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.155 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.155 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 16:36:44.908926 2026] [security2:error] [pid 16817:tid 16817] [client 104.23.225.155:11038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.rimworld.com"] [uri "/.git/config"] [unique_id "apHxXGNb9nUGW7P6g-4VQAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 20:04:04
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.155 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.155 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 16:03:58.723745 2026] [security2:error] [pid 23115:tid 23115] [client 104.23.225.155:12724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.advantstudio.com"] [uri "/.git/config"] [unique_id "apHprutwblgeh4IueMM-YgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 18:44:02
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.155 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.155 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 14:43:58.704246 2026] [security2:error] [pid 21974:tid 21974] [client 104.23.225.155:13228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.howardherrell.com"] [uri "/.git/config"] [unique_id "apHW7pRHAv7mmDiq7ft2_gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
mail.avx.gr
2026-08-28 17:17:57
(2 weeks ago)
(nginxGITSCAN) nginx Git repository scanner detected from 104.23.225.155 (FR/France/รle-de-France/Pa ...
show more
(nginxGITSCAN) nginx Git repository scanner detected from 104.23.225.155 (FR/France/รle-de-France/Paris/-)
show less
Hacking
๐ฉ๐ช
FeG Deutschland
2026-08-28 03:51:03
(2 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack