Anonymous
2026-07-28 08:31:51
(3 weeks ago)
104.23.229.75 - - [28/Jul/2026:10:31:10 +0200] "GET //website/wp-includes/wlwmanifest.xml HTTP/1.1" ...
show more
104.23.229.75 - - [28/Jul/2026:10:31:10 +0200] "GET //website/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.229.75 - - [28/Jul/2026:10:31:51 +0200] "GET //2019/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.229.75 - - [28/Jul/2026:10:31:51 +0200] "GET //shop/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.229.75 - - [28/Jul/2026:10:31:51 +0200] "GET //wp1/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.229.75 - - [28/Jul/2026:10:31:51 +0200] "GET //test/wp-includes/wlwmanifest.xml HTT
...
show less
Brute-Force
Web App Attack
πΊπΈ
mawan
2026-07-27 14:30:17
(3 weeks ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
π«π·
dynamix
2026-07-23 17:00:25
(4 weeks ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-07-20 01:44:52
(1 month ago)
104.23.229.75 - - [20/Jul/2026:03:44:51 +0200] "GET //test/wp-includes/wlwmanifest.xml HTTP/1.1" 404 ...
show more
104.23.229.75 - - [20/Jul/2026:03:44:51 +0200] "GET //test/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.229.75 - - [20/Jul/2026:03:44:51 +0200] "GET //media/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.229.75 - - [20/Jul/2026:03:44:52 +0200] "GET //wp2/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.229.75 - - [20/Jul/2026:03:44:52 +0200] "GET //site/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.229.75 - - [20/Jul/2026:03:44:52 +0200] "GET //cms/wp-includes/wlwmanifest.xml HTTP/1
...
show less
Brute-Force
Web App Attack
π·πΊ
DZBOT
2026-07-16 09:40:20
(1 month ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-15 06:31:24
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.229.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.229.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 15 02:28:56.468848 2026] [security2:error] [pid 31899:tid 31899] [client 104.23.229.75:11107] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "scoutmountaindistrict.org"] [uri "/.git/HEAD"] [unique_id "alcoqBvZwsUDGqVdJQHEywAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
UnixPrime
2026-07-14 07:58:38
(1 month ago)
104.23.229.75 - - [14/Jul/2026:09:58:38 +0200] "GET /database/%2eenv HTTP/1.1" 404 1257 "-" "curl/8. ...
show more
104.23.229.75 - - [14/Jul/2026:09:58:38 +0200] "GET /database/%2eenv HTTP/1.1" 404 1257 "-" "curl/8.7.1"
104.23.229.75 - - [14/Jul/2026:09:58:38 +0200] "GET /backups/%2eenv HTTP/1.1" 404 1257 "-" "curl/8.7.1"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-07-13 00:08:15
(1 month ago)
104.23.229.75 - - [13/Jul/2026:02:08:06 +0200] "GET /wp-includes/ HTTP/1.1" 404 184 "-" "Mozilla/5.0 ...
show more
104.23.229.75 - - [13/Jul/2026:02:08:06 +0200] "GET /wp-includes/ HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
104.23.229.75 - - [13/Jul/2026:02:08:09 +0200] "GET /wp-includes/Text/ HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
104.23.229.75 - - [13/Jul/2026:02:08:11 +0200] "GET /wp-includes/Text/Diff/ HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
104.23.229.75 - - [13/Jul/2026:02:08:13 +0200] "GET /wp-includes/css/ HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
104.23.229.75 - - [13/Jul/2026:02:08:15 +0200] "GET /wp-includes/css/dist/ HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like G
...
show less
Brute-Force
Web App Attack
πΊπΈ
mawan
2026-07-08 01:40:22
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
Anonymous
2026-07-07 19:09:25
(1 month ago)
104.23.229.75 - - [07/Jul/2026:21:09:24 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 ...
show more
104.23.229.75 - - [07/Jul/2026:21:09:24 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.229.75 - - [07/Jul/2026:21:09:24 +0200] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.229.75 - - [07/Jul/2026:21:09:24 +0200] "GET //wp/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.229.75 - - [07/Jul/2026:21:09:24 +0200] "GET //2018/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.229.75 - - [07/Jul/2026:21:09:25 +0200] "GET //shop/wp-includes/wlwmanifest.xml HT
...
show less
Brute-Force
Web App Attack
π«π·
dynamix
2026-07-03 02:48:01
(1 month ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-02 14:49:50
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.229.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.229.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 02 10:49:44.530908 2026] [security2:error] [pid 14298:tid 14298] [client 104.23.229.75:9948] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "penisbreath.com"] [uri "/.git/config"] [unique_id "akZ6iEqogFHr9eWqMCXHWQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π―π΅
S.O.B.A. Dev.
2026-06-27 15:03:03
(1 month ago)
Persistent port scanning or vulnerability scanning
Port Scan
πΊπΈ
TPI-Abuse
2026-06-26 07:48:30
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.229.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.229.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 03:48:22.448426 2026] [security2:error] [pid 14540:tid 14540] [client 104.23.229.75:10430] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "axiselectric.net"] [uri "/.git/config"] [unique_id "aj4uxohwmk87U-IgNAhrewAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-25 00:08:00
(1 month ago)
104.23.229.75 - - [25/Jun/2026:02:07:57 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 ...
show more
104.23.229.75 - - [25/Jun/2026:02:07:57 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.229.75 - - [25/Jun/2026:02:07:57 +0200] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.229.75 - - [25/Jun/2026:02:07:58 +0200] "GET //wp/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.229.75 - - [25/Jun/2026:02:07:58 +0200] "GET //2018/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.229.75 - - [25/Jun/2026:02:07:59 +0200] "GET //shop/wp-includes/wlwmanifest.xml HT
...
show less
Brute-Force
Web App Attack