Anonymous
2026-09-28 17:42:34
(3 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
Anonymous
2026-09-18 04:01:09
(1 week ago)
IP matched detection query many 3xx errors.
Brute-Force
Anonymous
2026-09-16 22:16:15
(2 weeks ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
Anonymous
2026-09-13 15:44:13
(2 weeks ago)
(caddyscan) Scanner path probe from 104.23.245.133 (US/United States/-): 5 in the last 3600 secs; Po ...
show more
(caddyscan) Scanner path probe from 104.23.245.133 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 104.23.245.133 - - [13/Sep/2026:15:44:09 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 104.23.245.133 - - [13/Sep/2026:15:44:10 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 104.23.245.133 - - [13/Sep/2026:15:44:10 +0000] "GET /.env.old HTTP/1.1"
[REDACTED] 200 2627 104.23.245.133 - - [13/Sep/2026:15:44:10 +0000] "GET /.ssh/id_ecdsa HTTP/1.1"
[REDACTED] 200 2627 104.23.245.133 - - [13/Sep/2026:15:44:11 +0000] "GET /@fs/app/.env?raw?? HTTP/1.1"
show less
Port Scan
๐ฏ๐ต
S.O.B.A. Dev.
2026-08-29 17:02:51
(1 month ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐ฉ๐ช
abdubhai
2026-08-25 08:57:34
(1 month ago)
104.23.245.133 - - [25/Aug/2026:
...
Brute-Force
๐บ๐ธ
micropedro
2026-08-21 12:16:28
(1 month ago)
8 incidents: web scanning/attack. First: 2026-08-21 08:16, Last: 2026-08-21 08:16 UTC. Triggers: fir ...
show more
8 incidents: web scanning/attack. First: 2026-08-21 08:16, Last: 2026-08-21 08:16 UTC. Triggers: firewall-http.
show less
Port Scan
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-08-15 14:41:04
(1 month ago)
Probing websites for vulnerabilities
Web App Attack
๐ฉ๐ช
bescared
2026-08-11 17:35:00
(1 month ago)
WAF (1) - URL probing.
Hacking
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-05 15:17:43
(1 month ago)
Web App Attack
๐บ๐ธ
interbiznw.com
2026-08-04 02:00:59
(1 month ago)
fail2ban-ban
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 13:58:34
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.245.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.245.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 09:58:18.644402 2026] [security2:error] [pid 740533:tid 740533] [client 104.23.245.133:10171] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thingstodonude.com"] [uri "/.git/HEAD"] [unique_id "amyp-vamrLuA2gzvAjRs1AAAABo"], referer: https://www.google.com/search?q=thingstodonude.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 01:45:14
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.245.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.245.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 21:44:57.712437 2026] [security2:error] [pid 22561:tid 22561] [client 104.23.245.133:9258] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kevinjewell.com"] [uri "/.env.backup"] [unique_id "amqsmZSCoDt6JiGNBRSzpQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 18:48:01
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.245.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.245.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 14:47:48.298938 2026] [security2:error] [pid 2956191:tid 2956191] [client 104.23.245.133:13153] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "og.gmacguffin.com"] [uri "/.env.backup"] [unique_id "ampK1AZ7RcIWzdSHodo0vwAAAAA"], referer: https://www.google.com/search?q=og.gmacguffin.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 11:59:36
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.245.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.245.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 07:59:25.490143 2026] [security2:error] [pid 3417547:tid 3417547] [client 104.23.245.133:9316] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elizabeth-furlow.com"] [uri "/.env"] [unique_id "amnrHZrF7ckjPzt6H7zUeQAAAAU"], referer: https://www.google.com/search?q=elizabeth-furlow.com
show less
Brute-Force
Bad Web Bot
Web App Attack