๐ง๐ท
maviei
2026-07-21 12:28:27
(18 hours ago)
2026-07-21T09:28:24.657018-03:00 srv1251771 kernel: [128258.982629] [UFW BLOCK] IN=eth0 OUT= MAC=40: ...
show more
2026-07-21T09:28:24.657018-03:00 srv1251771 kernel: [128258.982629] [UFW BLOCK] IN=eth0 OUT= MAC=40:e8:d4:b8:29:bb:44:38:39:ff:ff:41:08:00 SRC=104.23.245.104 DST=72.61.36.27 LEN=60 TOS=0x00 PREC=0x00 TTL=56 ID=30111 DF PROTO=TCP SPT=9834 DPT=8080 WINDOW=65535 RES=0x00 SYN URGP=0
2026-07-21T09:28:25.701845-03:00 srv1251771 kernel: [128260.026799] [UFW BLOCK] IN=eth0 OUT= MAC=40:e8:d4:b8:29:bb:44:38:39:ff:ff:41:08:00 SRC=104.23.245.104 DST=72.61.36.27 LEN=60 TOS=0x00 PREC=0x00 TTL=56 ID=30112 DF PROTO=TCP SPT=9834 DPT=8080 WINDOW=65535 RES=0x00 SYN URGP=0
2026-07-21T09:28:26.724179-03:00 srv1251771 kernel: [128261.049804] [UFW BLOCK] IN=eth0 OUT= MAC=40:e8:d4:b8:29:bb:44:38:39:ff:ff:41:08:00 SRC=104.23.245.104 DST=72.61.36.27 LEN=60 TOS=0x00 PREC=0x00 TTL=56 ID=30113 DF PROTO=TCP SPT=9834 DPT=8080 WINDOW=65535 RES=0x00 SYN URGP=0
...
show less
Port Scan
๐ท๐บ
Andrey Ganichvili
2026-07-17 17:10:07
(4 days ago)
Unauthorized sitemap access (/sitemap.xml) from 104.23.245.104
Web App Attack
๐ง๐ท
maviei
2026-07-04 07:00:57
(2 weeks ago)
2026-07-04T04:00:55.058339-03:00 srv1251771 kernel: [2915280.148029] [UFW BLOCK] IN=eth0 OUT= MAC=40 ...
show more
2026-07-04T04:00:55.058339-03:00 srv1251771 kernel: [2915280.148029] [UFW BLOCK] IN=eth0 OUT= MAC=40:e8:d4:b8:29:bb:44:38:39:ff:ff:41:08:00 SRC=104.23.245.104 DST=72.61.36.27 LEN=60 TOS=0x00 PREC=0x00 TTL=56 ID=54960 DF PROTO=TCP SPT=11509 DPT=8080 WINDOW=65535 RES=0x00 SYN URGP=0
2026-07-04T04:00:56.110432-03:00 srv1251771 kernel: [2915281.201261] [UFW BLOCK] IN=eth0 OUT= MAC=40:e8:d4:b8:29:bb:44:38:39:ff:ff:41:08:00 SRC=104.23.245.104 DST=72.61.36.27 LEN=60 TOS=0x00 PREC=0x00 TTL=56 ID=54961 DF PROTO=TCP SPT=11509 DPT=8080 WINDOW=65535 RES=0x00 SYN URGP=0
2026-07-04T04:00:57.133264-03:00 srv1251771 kernel: [2915282.225039] [UFW BLOCK] IN=eth0 OUT= MAC=40:e8:d4:b8:29:bb:44:38:39:ff:ff:41:08:00 SRC=104.23.245.104 DST=72.61.36.27 LEN=60 TOS=0x00 PREC=0x00 TTL=56 ID=54962 DF PROTO=TCP SPT=11509 DPT=8080 WINDOW=65535 RES=0x00 SYN URGP=0
...
show less
Port Scan
๐ฏ๐ต
S.O.B.A. Dev.
2026-06-30 10:58:41
(3 weeks ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐ง๐ท
maviei
2026-06-20 15:44:50
(1 month ago)
2026-06-20T12:44:47.596163-03:00 srv1251771 kernel: [1737115.798280] [UFW BLOCK] IN=eth0 OUT= MAC=40 ...
show more
2026-06-20T12:44:47.596163-03:00 srv1251771 kernel: [1737115.798280] [UFW BLOCK] IN=eth0 OUT= MAC=40:e8:d4:b8:29:bb:44:38:39:ff:ff:41:08:00 SRC=104.23.245.104 DST=72.61.36.27 LEN=60 TOS=0x00 PREC=0x00 TTL=56 ID=13337 DF PROTO=TCP SPT=11266 DPT=8443 WINDOW=65535 RES=0x00 SYN URGP=0
2026-06-20T12:44:48.629434-03:00 srv1251771 kernel: [1737116.831468] [UFW BLOCK] IN=eth0 OUT= MAC=40:e8:d4:b8:29:bb:44:38:39:ff:ff:41:08:00 SRC=104.23.245.104 DST=72.61.36.27 LEN=60 TOS=0x00 PREC=0x00 TTL=56 ID=13338 DF PROTO=TCP SPT=11266 DPT=8443 WINDOW=65535 RES=0x00 SYN URGP=0
2026-06-20T12:44:49.654612-03:00 srv1251771 kernel: [1737117.856694] [UFW BLOCK] IN=eth0 OUT= MAC=40:e8:d4:b8:29:bb:44:38:39:ff:ff:41:08:00 SRC=104.23.245.104 DST=72.61.36.27 LEN=60 TOS=0x00 PREC=0x00 TTL=56 ID=13339 DF PROTO=TCP SPT=11266 DPT=8443 WINDOW=65535 RES=0x00 SYN URGP=0
...
show less
Port Scan
๐ณ๐ฑ
homeshowdomain.nl
2026-06-17 21:59:53
(1 month ago)
Auto-ban: >3000 req/min op 2026-06-17
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-17 00:51:03
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.245.104 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.245.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 20:50:55.322485 2026] [security2:error] [pid 16766:tid 16766] [client 104.23.245.104:13970] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.thebestac.com"] [uri "/.env.backup"] [unique_id "ajHvb9w32usqB6_kTfJq8QAAAAQ"], referer: https://www.google.com/search?q=webdisk.thebestac.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-09 18:39:40
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.245.104 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.245.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 14:39:33.485842 2026] [security2:error] [pid 9602:tid 9606] [client 104.23.245.104:12316] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blastfuturepress.com"] [uri "/.git/config"] [unique_id "af9_ZZaw1l1AV1izq9ByWwAAAIE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-09 16:11:56
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.245.104 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.245.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 12:11:50.706258 2026] [security2:error] [pid 27367:tid 27367] [client 104.23.245.104:11765] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dualspiralsystems.com"] [uri "/.git/config"] [unique_id "af9cxrb3jRumF2D0BA0iYAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
Tokolosh Hunters
2026-05-03 18:17:14
(2 months ago)
AutoBlockWindow-Known bad useragent query-2026-05-03 18:17:13
Bad Web Bot
๐บ๐ธ
myagent.site
2026-04-08 14:14:36
(3 months ago)
Blocking for trying to access an exploit file: /www/.env
Hacking
๐บ๐ธ
myagent.site
2026-03-29 17:46:23
(3 months ago)
Blocking for trying to access an exploit file: /.env.dev.local
Hacking
๐บ๐ธ
chrisj
2026-03-24 06:40:19
(3 months ago)
[Tue Mar 24 06:39:59.642068 2026] [proxy_fcgi:error] [pid 1581057:tid 1581057] [client 104.23.245.10 ...
show more
[Tue Mar 24 06:39:59.642068 2026] [proxy_fcgi:error] [pid 1581057:tid 1581057] [client 104.23.245.104:11252] AH01071: Got error 'Primary script unknown'
[Tue Mar 24 06:40:19.292113 2026] [proxy_fcgi:error] [pid 1582304:tid 1582304] [client 104.23.245.104:11513] AH01071: Got error 'Primary script unknown'
[Tue Mar 24 06:40:19.461080 2026] [proxy_fcgi:error] [pid 1582304:tid 1582304] [client 104.23.245.104:11513] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
๐ฉ๐ช
403veli
2025-12-30 06:24:39
(6 months ago)
Confirmed malicious activity observed via T-Pot honeypot Observed 31 events on port 80 (unknown) fro ...
show more
Confirmed malicious activity observed via T-Pot honeypot Observed 31 events on port 80 (unknown) from 2025-12-30T06:24:39+00:00 to 2025-12-30T06:25:48.671000+00:00. Sample: {"dest_port": 80, "src_port": 35607, "src_ip": "104.23.245.104"}
show less
Port Scan
๐ซ๐ท
Campus France
2025-11-25 21:55:51
(7 months ago)
104.23.245.104 - - [25/Nov/2025:22:55:50 +0100] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 412 ...
show more
104.23.245.104 - - [25/Nov/2025:22:55:50 +0100] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 412 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.245.104 - - [25/Nov/2025:22:55:50 +0100] "GET /xmlrpc.php?rsd HTTP/1.1" 404 412 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.245.104 - - [25/Nov/2025:22:55:51 +0100] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 412 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.245.104 - - [25/Nov/2025:22:55:51 +0100] "GET /web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 412 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
104.23.245.104 - - [25/Nov/2025:22:55:51 +0100] "GET /wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 412 "-" "M
...
show less
Brute-Force
Web App Attack