Anonymous
2026-10-01 08:06:29
(37 minutes ago)
104.23.225.55 - - [01/Oct/2026:10:06:27 +0200] "GET /test/.env HTTP/1.1" 403 124 "-" "Mozilla/5.0 (W ...
show more
104.23.225.55 - - [01/Oct/2026:10:06:27 +0200] "GET /test/.env HTTP/1.1" 403 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
104.23.225.55 - - [01/Oct/2026:10:06:27 +0200] "GET /v1/.env HTTP/1.1" 403 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
104.23.225.55 - - [01/Oct/2026:10:06:27 +0200] "GET /production/.env HTTP/1.1" 403 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
104.23.225.55 - - [01/Oct/2026:10:06:27 +0200] "GET /staging/.env HTTP/1.1" 403 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
104.23.225.55 - - [01/Oct/2026:10:06:27 +0200] "GET /settings.json HTTP/1.1" 404 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
104.23.225.55 - - [01/Oct/2026:10:06:27 +0200] "GET /phpinfo HTTP/1.1" 404 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
104.23.225.55 - - [01/Oct/2026:10:06:27 +0200] "GET /web/.env HTTP/1.1" 403 124 "-" "Mozilla/5.0 (Windo
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-26 10:23:21
(4 days ago)
104.23.225.55 - - [26/Sep/2026:12:23:20 +0200] "GET /.boto HTTP/1.1" 403 124 "-" "Mozilla/5.0 (Windo ...
show more
104.23.225.55 - - [26/Sep/2026:12:23:20 +0200] "GET /.boto HTTP/1.1" 403 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
104.23.225.55 - - [26/Sep/2026:12:23:20 +0200] "GET /.docker/config.json HTTP/1.1" 403 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
104.23.225.55 - - [26/Sep/2026:12:23:20 +0200] "GET /.anthropic/config.json HTTP/1.1" 403 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
104.23.225.55 - - [26/Sep/2026:12:23:20 +0200] "GET /.aws/config HTTP/1.1" 403 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
104.23.225.55 - - [26/Sep/2026:12:23:20 +0200] "GET /.claude/settings.local.json HTTP/1.1" 403 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
104.23.225.55 - - [26/Sep/2026:12:23:20 +0200] "GET /.docker/secrets.json HTTP/1.1" 403 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
104.23.225.55 - - [26/Sep/2026:12:23:20 +0200] "GET /.docker/l
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-26 01:43:50
(5 days ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ท
chengkev
2026-09-24 17:38:53
(6 days ago)
Esta IP fue detectada por CrowdSec, activando crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ซ๐ท
dynamix
2026-09-22 13:17:22
(1 week ago)
Multiple WAF Violations
Web App Attack
๐น๐ท
crnpekgoz
2026-09-21 08:31:21
(1 week ago)
Malicious HTTP GET request for '/dump.sql.gz' (HTTP 404) from 104.23.225.55. Threat: Web Gรผvenlik Aรง ...
show more
Malicious HTTP GET request for '/dump.sql.gz' (HTTP 404) from 104.23.225.55. Threat: Web Gรผvenlik Aรงฤฑฤฤฑ Taramasฤฑ (.env/bot). Blocked by WardenGuard Web Shield.
show less
Web App Attack
Anonymous
2026-09-20 16:56:12
(1 week ago)
104.23.225.55 - - [20/Sep/2026:18:56:06 +0200] "GET /api/%2eenv%2eproduction HTTP/1.1" 403 124 "-" " ...
show more
104.23.225.55 - - [20/Sep/2026:18:56:06 +0200] "GET /api/%2eenv%2eproduction HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.23.225.55 - - [20/Sep/2026:18:56:07 +0200] "GET /backup/wp-config%2ebak HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.23.225.55 - - [20/Sep/2026:18:56:07 +0200] "GET /Sources/API/%2eenv HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.23.225.55 - - [20/Sep/2026:18:56:07 +0200] "GET /mercadopago/settings%2ejson HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.23.225.55 - - [20/Sep/2026:18:56:07 +0200] "GET /auth-app/src/%2eenv HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.23.225.55 - - [20/Sep/2026:18:56:08 +0200] "GET /private/mandrill%2eenv HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.23.225.55 - - [20/Sep/2026:18:56:08 +0200] "GET /images/config%2ephp HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.23.225.55 - - [20/Sep/2026:18:56:08 +0200] "GET /assets/%2eenv HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.23.225.55 - - [20/Sep/2026:18:56:09 +0200] "GET /%2essh/private%2ep12%2ebak HTTP/1.1" 403 124 "-" "curl/8.7.1"
104.23.225
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-17 08:17:11
(2 weeks ago)
104.23.225.55 - - [17/Sep/2026:10:17:10 +0200] "GET /.hg/hgrc HTTP/1.1" 403 124 "-" "Mozilla/5.0 (Wi ...
show more
104.23.225.55 - - [17/Sep/2026:10:17:10 +0200] "GET /.hg/hgrc HTTP/1.1" 403 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
104.23.225.55 - - [17/Sep/2026:10:17:10 +0200] "GET /CVS/Root HTTP/1.1" 404 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
104.23.225.55 - - [17/Sep/2026:10:17:10 +0200] "GET /.svn/wc.db HTTP/1.1" 403 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
104.23.225.55 - - [17/Sep/2026:10:17:10 +0200] "GET /_darcs/prefs/binaries HTTP/1.1" 404 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
104.23.225.55 - - [17/Sep/2026:10:17:10 +0200] "GET /.gitmodules HTTP/1.1" 403 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
104.23.225.55 - - [17/Sep/2026:10:17:10 +0200] "GET /.bzr/branch/branch.conf HTTP/1.1" 403 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
104.23.225.55 - - [17/Sep/2026:10:17:10 +0200] "GET /.codeclimate.yml HTTP/1.1" 404 1
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
tsZero
2026-09-16 11:18:24
(2 weeks ago)
Scan example: path=/.git/config status=403
Hacking
๐ซ๐ท
dynamix
2026-09-12 20:51:40
(2 weeks ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 18:43:21
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.55 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 14:43:14.562863 2026] [security2:error] [pid 32115:tid 32115] [client 104.23.225.55:10340] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.lasertherapyoc.com"] [uri "/.git/config"] [unique_id "apHWwqu1MoKhfWyS45PcWwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 01:39:13
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.55 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 21:39:09.965683 2026] [security2:error] [pid 5212:tid 5212] [client 104.23.225.55:10146] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.usaenquirer.com"] [uri "/.git/config"] [unique_id "apDmvfLQETK2ZcwKkFPIHgAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 01:02:45
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.55 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 21:02:41.098311 2026] [security2:error] [pid 10949:tid 10949] [client 104.23.225.55:12637] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.juca.com.mx"] [uri "/.git/HEAD"] [unique_id "apDeMbRM-UWTdtjWybQwygAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-27 13:02:23
(1 month ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 06:58:02
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.55 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 02:57:57.088500 2026] [security2:error] [pid 1847580:tid 1847592] [client 104.23.225.55:12040] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.metastrata.com"] [uri "/.git/HEAD"] [unique_id "ao_f9fQbIeZJGPt3jUe-oAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack