This IP address has been reported a total of
13
times from
10 distinct
sources.
145.223.144.165 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
United States of America
with 10
reports;
Germany
with 2
reports;
Sweden
with 1
report.
The most common categories in these recent reports were:
Bad Web Bot
10
times;
DDoS Attack
6
times;
Exploited Host
2
times;
Web App Attack
2
times;
SSH
2
times;
Other
4
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Repeated requests classified as pathological web bot behavior, for example: /[redacted]/search?field ...
show moreRepeated requests classified as pathological web bot behavior, for example: /[redacted]/search?field_article_edition%5B504%5D=504&%3Bamp%3Bamp%3Bamp%3Bfield_key_terms%5B340%5D=340&%3Bamp%3Bamp%3Bamp%3Bk=&%3Bamp%3Bamp%3Bamp%3Btitle=&%3Bamp%3Bamp%3Bamp%3Bfield_article_date=&%3Bamp%3Bamp%3Bamp%3Bfield_article_date_1=&%3Bamp%3Bamp%3Bamp%3Bsort_by=search_api_relevance&%3Bamp%3Bamp%3Bamp%3Bpage=3&%3Bamp%3Bamp%3Bf%5B0%5D=digest_publication_type%3A932&%3Bamp%3Bf%5B0%5D=digest_key_terms%3A526&%3Bf%5B0%5D=digest_key_terms%3A796 (HTTP/1.1 port 443, user agent: "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36")
show less
(mod_security) mod_security (id:210730) triggered by 145.223.144.165 (-): 1 in the last 300 secs; Po ...
show more(mod_security) mod_security (id:210730) triggered by 145.223.144.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 20:55:15.193298 2026] [security2:error] [pid 3227:tid 3227] [client 145.223.144.165:33238] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.trinitydent.com|F|2"] [data ".axd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.trinitydent.com"] [uri "/WebResource.axd"] [unique_id "ar8A8xQpCQHX5BXtxpCBKQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
Attacks websites by trying to access known vulnerables of plugins, brute-force of backends or probin ...
show moreAttacks websites by trying to access known vulnerables of plugins, brute-force of backends or probing of administrative tools
show less
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show moreTriggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /kerko.php
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show moreTriggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /sport/e-fundit-zhbllokohet-sfida-inter-atalanta-video/567505/
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
This address requests our sites over plain http, is answered with a redirect to https, and never fol ...
show moreThis address requests our sites over plain http, is answered with a redirect to https, and never follows it β over and over. A browser follows redirects; a scanner enumerating hosts does not. It reads nothing it asks for and only loads the server; blocked. Please check what runs on this address. | method: GET | path: /MEX/securite-incendie-v.jpg | 2026-09-26 10:08 UTC
show less
Blocked abusive HTTP application-layer DoS / botnet traffic from 145.223.144.165: traffic from this ...
show moreBlocked abusive HTTP application-layer DoS / botnet traffic from 145.223.144.165: traffic from this address continues high-cost dynamic page and feed requests at abusive rates via TCP/HTTPS despite edge block responses. Likely compromised end-user host.
show less
Repeated requests classified as pathological web bot behavior, for example: /[redacted]/search?field ...
show moreRepeated requests classified as pathological web bot behavior, for example: /[redacted]/search?field_article_edition%5B504%5D=504&%3Bamp%3Bamp%3Bamp%3Bfield_key_terms%5B321%5D=321&%3Bamp%3Bamp%3Bamp%3Bk=&%3Bamp%3Bamp%3Bamp%3Btitle=&%3Bamp%3Bamp%3Bamp%3Bfield_article_date=&%3Bamp%3Bamp%3Bamp%3Bfield_article_date_1=&%3Bamp%3Bamp%3Bamp%3Bsort_by=search_api_relevance&%3Bamp%3Bamp%3Bamp%3Bpage=0&%3Bamp%3Bamp%3Bf%5B0%5D=digest_key_terms%3A494&%3Bamp%3Bf%5B0%5D=digest_key_terms%3A524&%3Bf%5B0%5D=digest_key_terms%3A514 (HTTP/1.1 port 443, user agent: "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36")
show less