This IP address has been reported a total of
7
times from
6 distinct
sources.
185.122.141.54 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Germany
with 1
report;
Ukraine
with 1
report.
The most common categories in these recent reports were:
Web App Attack
2
times;
DDoS Attack
1
time;
Bad Web Bot
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[09/Oct/2026:06:59:17 +0300] -- 185.122.141.54 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp- ...
show more[09/Oct/2026:06:59:17 +0300] -- 185.122.141.54 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-content/uploads/2016/03/ELCONF-2015.pdf HTTP/1.1
show less
L7 DDoS: distributed flood on a shop's faceted search โ automated requests to search/sort URLs, one ...
show moreL7 DDoS: distributed flood on a shop's faceted search โ automated requests to search/sort URLs, one or two per address from thousands of addresses, no page assets loaded | path: /18-velo-route | query: q=Stock+magasin-Cycling+H%C3%A9nin%5C-Beaumont-Cycling+Montpellier/Taille-S/Marque-Scott/Famille-Metrix-Speester-Speedster&resul
show less
Coordinated application-layer DDoS against git.mills.io (self-hosted Gitea), 2026-06-12 ~20:30-21:10 ...
show moreCoordinated application-layer DDoS against git.mills.io (self-hosted Gitea), 2026-06-12 ~20:30-21:10 UTC. Deliberately expensive multi-label Gitea issue-search queries (/issues?type=all&state=closed&sort=...&labels=<multiple IDs>, ~60-113s CPU each) flooded the backend via proxy/hosting networks. ~36,700 source IPs, ~1 request per IP, identical TLS fingerprint (TLS1.3 0x1301) and one spoofed Chrome UA = single automated tool.
show less