🇩🇪
bogdanv
2026-08-27 17:51:57
(2 weeks ago)
$f2bV_matches
DDoS Attack
Web Spam
SQL Injection
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
bogdanv
2026-07-23 13:29:20
(1 month ago)
$f2bV_matches
DDoS Attack
Web Spam
SQL Injection
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
bogdanv
2026-07-22 04:53:21
(1 month ago)
$f2bV_matches
DDoS Attack
Web Spam
SQL Injection
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
bogdanv
2026-06-28 08:18:57
(2 months ago)
$f2bV_matches
DDoS Attack
Web Spam
SQL Injection
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
bogdanv
2026-05-27 13:53:21
(3 months ago)
$f2bV_matches
DDoS Attack
Web Spam
SQL Injection
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
bogdanv
2026-03-29 13:44:09
(5 months ago)
$f2bV_matches
DDoS Attack
Web Spam
SQL Injection
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
robotstxt
2026-03-05 16:32:53
(6 months ago)
14.225.5.148 - - [05/Mar/2026:16:30:14 +0000] "GET /phpMyAdmin-4.8.0-all-languages HTTP/1.1" 404 258 ...
show more
14.225.5.148 - - [05/Mar/2026:16:30:14 +0000] "GET /phpMyAdmin-4.8.0-all-languages HTTP/1.1" 404 25819 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.6367.201 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" "35.247.243.250"
14.225.5.148 - - [05/Mar/2026:16:31:29 +0000] "GET /phpMyAdmin-4.6.3-all-languages HTTP/1.1" 404 25821 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.6367.201 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" "34.96.162.49"
14.225.5.148 - - [05/Mar/2026:16:31:59 +0000] "GET /phpMyAdmin-5.1.3-all-languages HTTP/1.1" 404 25820 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.6367.201 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" "34.96.162.57"
14.225.5.148 - - [05/Ma
...
show less
Bad Web Bot
🇬🇧
consul.to
2026-03-03 03:32:01
(6 months ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-03-01 13:03:00
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 14.225.5.148 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 14.225.5.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 01 08:02:51.716294 2026] [security2:error] [pid 22113:tid 22113] [client 14.225.5.148:33482] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||stkm.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "stkm.com"] [uri "/php.bak"] [unique_id "aaQ4-wLIz4mUD9cKRq7xOQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-26 01:46:57
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 14.225.5.148 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 14.225.5.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 25 20:46:54.231066 2026] [security2:error] [pid 31763:tid 31763] [client 14.225.5.148:35110] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||oxyveg.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "oxyveg.com"] [uri "/admin.bak"] [unique_id "aZ-mDoFXgO1I9PIo8FOYnQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
konseptit
2026-02-10 06:31:06
(7 months ago)
(mod_security) mod_security triggered on hostname [redacted] 14.225.5.148 (-)
SQL Injection
🇺🇸
TPI-Abuse
2026-02-01 01:44:44
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 14.225.5.148 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 14.225.5.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 31 20:44:36.730374 2026] [security2:error] [pid 32033:tid 32033] [client 14.225.5.148:37180] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "angelaridgwaydressage.com"] [uri "/.env"] [unique_id "aX6wBG2f9IDJ2TD7uAW1LQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-01 01:27:20
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 14.225.5.148 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 14.225.5.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 31 20:27:13.950244 2026] [security2:error] [pid 28238:tid 28238] [client 14.225.5.148:58190] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||elgautobody.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "elgautobody.com"] [uri "/data.bak"] [unique_id "aX6r8VmhQsRQ-yWaqvg-cgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-01-26 19:05:03
(7 months ago)
Blocked: Reason='Auto-block'; Requests=0
Hacking
🇺🇸
TPI-Abuse
2026-01-24 17:03:11
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 14.225.5.148 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 14.225.5.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 24 12:03:03.832582 2026] [security2:error] [pid 2624151:tid 2624151] [client 14.225.5.148:41204] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||makeupandwardrobe.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "makeupandwardrobe.com"] [uri "/master.bak"] [unique_id "aXT7R6Slsc0j_fWcwaojDgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack