๐ฎ๐ช
AutosOnShow
2026-06-21 04:27:05
(2 days ago)
blocked for webapp attack | path requested: /.env | seen at 2026-06-21 04:26:23.756 |
Web App Attack
๐ซ๐ท
bigorre.org
2026-06-16 15:31:53
(1 week ago)
Excessive crawling : exceed crawl-delay defined in robots.txt
Bad Web Bot
๐ฎ๐ช
AutosOnShow
2026-06-14 01:32:05
(1 week ago)
blocked for webapp attack | path requested: /.env | seen at 2026-06-14 01:31:09.695 |
Web App Attack
๐ซ๐ท
bigorre.org
2026-06-01 16:41:07
(3 weeks ago)
Excessive crawling : exceed crawl-delay defined in robots.txt
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-28 18:26:53
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 104.253.48.219 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 104.253.48.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 28 14:26:44.942849 2026] [security2:error] [pid 17687:tid 17687] [client 104.253.48.219:48427] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||register-yacht-hong-kong.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "register-yacht-hong-kong.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahiI5KBW-oCrKeHAKxJGjAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ช
AutosOnShow
2026-05-23 08:15:07
(1 month ago)
blocked for webapp attack | path requested: /.env | seen at 2026-05-23 08:14:24.422 |
Web App Attack
๐ฎ๐ช
Jim Keir
2026-03-06 09:33:00
(3 months ago)
2026-03-06 09:32:59 104.253.48.219 File scanning, blocking 104.253.48.219 for 5 minutes
Web App Attack
๐ช๐ธ
gnom4ik
2026-02-21 12:46:28
(4 months ago)
ban-reviewer auto report; ip=104.253.48.219; scenario=http:scan; verdict=valid_ban; confidence=0.85; ...
show more
ban-reviewer auto report; ip=104.253.48.219; scenario=http:scan; verdict=valid_ban; confidence=0.85; categories=14,15,22; active_decisions=1; lookback_decisions=1; nginx_requests=0; appsec_matches=0; auth_events=0; kernel_events=0; signals=IP flagged for HTTP scanning activity (scenario: http:scan); AbuseIPDB category 14 (Port Scan) is applicable; AbuseIPDB category 15 (Hacking) is applicable; AbuseIPDB category 22 (SSH) is applicable
show less
Port Scan
Hacking
SSH
๐ฎ๐ช
Jim Keir
2026-02-15 09:24:11
(4 months ago)
2026-02-15 09:24:10 104.253.48.219 File scanning, blocking 104.253.48.219 for 5 minutes
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-22 13:04:11
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 104.253.48.219 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 104.253.48.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 08:04:05.888359 2026] [security2:error] [pid 2224:tid 2377] [client 104.253.48.219:52057] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tnccivic.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tnccivic.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aXIgRc5MuRMDqAVMHcaieQAAAdg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
Charles
2025-11-15 21:59:36
(7 months ago)
104.253.48.219 - - [16/Nov/2025:05:59:34 +0800] "GET /.env HTTP/1.1" 404 360 "-" "Mozilla/5.0 (Windo ...
show more
104.253.48.219 - - [16/Nov/2025:05:59:34 +0800] "GET /.env HTTP/1.1" 404 360 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.5845.140 Safari/537.36"
...
show less
Web Spam
Email Spam
Brute-Force
Bad Web Bot
Web App Attack
SSH
๐ธ๐ฌ
Charles
2025-09-12 16:34:50
(9 months ago)
104.253.48.219 - - [13/Sep/2025:00:34:48 +0800] "GET /.env HTTP/1.1" 404 360 "-" "Mozilla/5.0 (Windo ...
show more
104.253.48.219 - - [13/Sep/2025:00:34:48 +0800] "GET /.env HTTP/1.1" 404 360 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.5845.140 Safari/537.36"
...
show less
Web Spam
Email Spam
Brute-Force
Bad Web Bot
Web App Attack
SSH
๐จ๐ณ
ThreatBook.io
2025-09-08 00:12:04
(9 months ago)
ThreatBook Intelligence: Zombie,Spam more details on https://threatbook.io/ip/104.253.48.219
2025-09 ...
show more
ThreatBook Intelligence: Zombie,Spam more details on https://threatbook.io/ip/104.253.48.219
2025-09-07 12:07:33 /.env
2025-09-07 12:07:33 /,{"body":"0x%5B%5D=androxgh0st","content_type":"application/x-www-form-urlencoded","header":{"Accept":["*/*"],"Accept-Encoding":["gzip"],"Connection":["close"],"Content-Length":["20"],"Content-Type":["application/x-www-form-urlencoded"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.5845.140 Safari/537.36"]},"host":"54.179.199.3","method":"POST","proto":"HTTP/1.1","remote_addr":"104.253.48.219:40009","status_code":200,"url":"/","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.5845.140 Safari/537.36"}
show less
Web App Attack
๐จ๐ด
j458rjqwi348fhjq46
2025-07-22 17:52:26
(11 months ago)
Malicious IP detected by WAF with anomaly score 10.0. Attack types: Exposure of environment file (.e ...
show more
Malicious IP detected by WAF with anomaly score 10.0. Attack types: Exposure of environment file (.env), Suspicious URL detected (extended rules). Activity: 4 requests to 1 URLs. Period: 2025-07-22 02:39:38 - 2025-07-22 02:39:38 (America/Bogota). Origin: US. Source: Automated WAF log analysis.
show less
Hacking
Web App Attack