This IP address has been reported a total of
53
times from
28 distinct
sources.
165.227.200.61 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
United States of America
with 23
reports;
Germany
with 7
reports;
Netherlands
with 5
reports.
The most common categories in these recent reports were:
Web App Attack
46
times;
Bad Web Bot
29
times;
Brute-Force
26
times;
Hacking
8
times;
Port Scan
3
times;
Other
6
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[SatOct0307:54:12.6299862026][security2:error][pid1959910:tid1960054][client165.227.200.61:0]ModSecu ...
show more[SatOct0307:54:12.6299862026][security2:error][pid1959910:tid1960054][client165.227.200.61:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"710\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"stmconsulenze.ch\"][uri\"/.git/config\"][unique_id\"asCYhK0StP0_fEOxTzazQwAAAJI\"]
show less
Attack type: wordpress_attack_attempt | Target: /.git/config | UA: Mozilla/5.0 (X11; Linux x86_64) A ...
show moreAttack type: wordpress_attack_attempt | Target: /.git/config | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 | Country: US
show less
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show moreAuto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-10-01.
show less
Automated honeypot detection. honeypot against a Next.js application. Paths: /.git/config. Blocked a ...
show moreAutomated honeypot detection. honeypot against a Next.js application. Paths: /.git/config. Blocked at the edge.
show less
[FriOct0219:11:53.3137732026][security2:error][pid2634023:tid2634048][client165.227.200.61:0]ModSecu ...
show more[FriOct0219:11:53.3137732026][security2:error][pid2634023:tid2634048][client165.227.200.61:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"pytag.ch\"][uri\"/.git/config\"][unique_id\"ar_l2aACQ5d4FsWH-sMf6AAAAA8\"]
show less
Port Scan
Brute-Force
Web App Attack
Anonymous
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1