This IP address has been reported a total of
72
times from
42 distinct
sources.
64.227.2.241 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[WedSep3005:56:43.1306612026][security2:error][pid1738556:tid1738646][client64.227.2.241:0]ModSecuri ...
show more[WedSep3005:56:43.1306612026][security2:error][pid1738556:tid1738646][client64.227.2.241:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"710\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"ch-garantie.ch\"][uri\"/.git/config\"][unique_id\"aryIe-ZU81knAUq5eAvEtwAAAIM\"]
show less
[WedSep3004:48:41.5147382026][security2:error][pid3110506:tid3110681][client64.227.2.241:0]ModSecuri ...
show more[WedSep3004:48:41.5147382026][security2:error][pid3110506:tid3110681][client64.227.2.241:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"fondazionepetronillapontirone.ch\"][uri\"/.git/config\"][unique_id\"arx4ibuvQc3xrunfYQaU1QAAAAo\"]
show less
Port Scan
Brute-Force
Web App Attack
Anonymous
64.227.2.241 - - [30/Sep/2026:04:36:10 +0200] "GET /.git/config HTTP/1.1" 402 861 "-" "Mozilla/5.0 ( ...
show more64.227.2.241 - - [30/Sep/2026:04:36:10 +0200] "GET /.git/config HTTP/1.1" 402 861 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" ...
show less
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show moreCrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-09-30T00:47:11.798699299Z. Context: http_status=200
show less
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of ...
show moreAutomated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of admin/backdoor paths (e.g. wp-login.php, known CMS shell filenames) on an Apache web server, on 2026-09-30 00:34 UTC.
show less
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show moreCrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-09-29T16:07:37.937016623Z. Context: http_status=200
show less