This IP address has been reported a total of
25
times from
19 distinct
sources.
147.78.241.50 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[WedAug2621:08:28.5526032026][security2:error][pid127766:tid127869][client147.78.241.50:0]ModSecurit ...
show more[WedAug2621:08:28.5526032026][security2:error][pid127766:tid127869][client147.78.241.50:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"server8.4host.ch\"][uri\"/\"][unique_id\"ao85rDHMdCyPqtp6iopIywAAAMc\"]\,referer:https://server8.4host.ch
show less
Blocked by https://aegis.hr โ WAF: ModSec rule match - (MITRE T1190), 1 attempts, Period: 2026-08-25 ...
show moreBlocked by https://aegis.hr โ WAF: ModSec rule match - (MITRE T1190), 1 attempts, Period: 2026-08-25 16:36:36 to 2026-08-25 16:36:36
show less
2026-08-25T15:17:47Z - Recognized attacks\bad behavior from IP address 147.78.241.50 on port 443\80 ...
show more2026-08-25T15:17:47Z - Recognized attacks\bad behavior from IP address 147.78.241.50 on port 443\80 (4 daily hits): HTTP header is restricted by policy (/accept-charset/), Request Missing an Accept Header
show less
{"ClientAddr":"172.69.109.32:9333","ClientHost":"147.78.241.50","ClientPort":"9333","ClientUsername" ...
show more{"ClientAddr":"172.69.109.32:9333","ClientHost":"147.78.241.50","ClientPort":"9333","ClientUsername":"-","DownstreamContentSize":113,"DownstreamStatus":401,"Duration":814623,"GzipRatio":0,"OriginContentSize":0,"OriginDuration":0,"OriginStatus":0,"Overhead":814623,"RequestAddr":"navidrome.timvdberg.dev","RequestContentSize":0,"RequestCount":192738,"RequestHost":"navidrome.timvdberg.dev","RequestMethod":"GET","RequestPath":"/","RequestPort":"-","RequestProtocol":"HTTP/2.0","RequestScheme":"https","RetryAttempts":0,"RouterName":"navidrome@file","StartLocal":"2026-08-25T01:29:45.641528334Z","StartUTC":"2026-08-25T01:29:45.641528334Z","TLSCipher":"TLS_AES_128_GCM_SHA256","TLSVersion":"1.3","entryPointName":"https","level":"info","msg":"","request_Cf-Connecting-Ip":"147.78.241.50","request_X-Forwarded-For":"147.78.241.50","request_X-Real-Ip":"172.69.109.32","time":"2026-08-25T01:29:45Z"}
{"ClientAddr":"172.71.102.66:14236","ClientHost":"147.78.241.50","ClientPort":"14236","ClientUsername":"-
...
show less
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 147.78.241.50 (DE/Germany/-): 2 in t ...
show moreLF_MODSEC: (mod_security) mod_security (id:949110) triggered by 147.78.241.50 (DE/Germany/-): 2 in the last 3600 secs
show less
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 147.78.241.50 (DE/Germany/-): 1 in t ...
show moreLF_MODSEC: (mod_security) mod_security (id:949110) triggered by 147.78.241.50 (DE/Germany/-): 1 in the last 3600 secs
show less
Web App Attack
Showing 1 to
15
of 25 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ