This IP address has been reported a total of
34
times from
26 distinct
sources.
185.213.155.245 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
2026-06-21 11:35:21,661 fail2ban.actions\[3956\]: WARNING \[asterisk-iptables\] Ban 185.213.155.2452 ...
show more2026-06-21 11:35:21,661 fail2ban.actions\[3956\]: WARNING \[asterisk-iptables\] Ban 185.213.155.2452026-06-21 13:35:33,613 fail2ban.actions\[3956\]: WARNING \[asterisk-iptables\] Ban 185.213.155.2452026-06-21 15:35:44,636 fail2ban.actions\[3956\]: WARNING \[asterisk-iptables\] Ban 185.213.155.2452026-06-21 17:35:55,548 fail2ban.actions\[3956\]: WARNING \[asterisk-iptables\] Ban 185.213.155.2452026-06-21 19:36:07,269 fail2ban.actions\[3956\]: WARNING \[asterisk-iptables\] Ban 185.213.155.2452026-06-21 21:36:19,139 fail2ban.actions\[3956\]: WARNING \[asterisk-iptables\] Ban 185.213.155.2452026-06-21 23:36:30,979 fail2ban.actions\[3956\]: WARNING \[asterisk-iptables\] Ban 185.213.155.2452026-06-22 01:36:42,884 fail2ban.actions\[3956\]: WARNING \[asterisk-iptables\] Ban 185.213.155.2452026-06-22 03:36:54,751 fail2ban.actions\[3956\]: WARNING \[asterisk-iptables\] Ban 185.213.155.245
...
show less
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 185.213.155.245 (DE/Germany/-): 2 in ...
show moreLF_MODSEC: (mod_security) mod_security (id:949110) triggered by 185.213.155.245 (DE/Germany/-): 2 in the last 3600 secs
show less
[SunMay3109:42:51.5001242026][security2:error][pid2598649:tid2598985][client185.213.155.245:0]ModSec ...
show more[SunMay3109:42:51.5001242026][security2:error][pid2598649:tid2598985][client185.213.155.245:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"swisservers.com\"][uri\"/\"][unique_id\"ahvmezr3jqk7EipgfMZNQgAAAQ8\"]\,referer:https://swisservers.com
show less
[SatMay3009:52:17.9787552026][security2:error][pid3473315:tid3473489][client185.213.155.245:0]ModSec ...
show more[SatMay3009:52:17.9787552026][security2:error][pid3473315:tid3473489][client185.213.155.245:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"monteco-suisse.ch\"][uri\"/\"][unique_id\"ahqXMbbc3zC41KF7U23FyQAAARA\"]\,referer:https://monteco-suisse.ch
show less
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show moreTriggered Cloudflare WAF (firewallCustom) from DE.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Fedora; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 185.213.155.245 (DE/Germany/-): 1 in ...
show more(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 185.213.155.245 (DE/Germany/-): 1 in the last 3600 secs (0-195)
show less
[FriMay2912:44:35.4362592026][security2:error][pid1012895:tid1013119][client185.213.155.245:0]ModSec ...
show more[FriMay2912:44:35.4362592026][security2:error][pid1012895:tid1013119][client185.213.155.245:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"retepastoralebelli.ch\"][uri\"/favicon.ico\"][unique_id\"ahluEzgESv_nZ3UY73mzMAAAAQg\"]\,referer:https://retepastoralebelli.ch
show less
[FriMay2902:14:36.5786482026][security2:error][pid1381489:tid1381572][client185.213.155.245:0]ModSec ...
show more[FriMay2902:14:36.5786482026][security2:error][pid1381489:tid1381572][client185.213.155.245:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"www.restaurantgandria.ch\"][uri\"/\"][unique_id\"ahjabOgjp70KyXzCY9BoUwAAAJY\"]\,referer:https://restaurantgandria.ch
show less
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 185.213.155.245 (DE/Germany/-): 1 in ...
show moreLF_MODSEC: (mod_security) mod_security (id:949110) triggered by 185.213.155.245 (DE/Germany/-): 1 in the last 3600 secs
show less
Web App Attack
Showing 1 to
15
of 34 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ