This IP address has been reported a total of
72
times from
36 distinct
sources.
209.38.27.208 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
United States of America
with 29
reports;
Germany
with 14
reports;
Netherlands
with 8
reports.
The most common categories in these recent reports were:
Web App Attack
65
times;
Bad Web Bot
34
times;
Brute-Force
32
times;
Hacking
18
times;
Port Scan
9
times;
Other
17
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
DDoS Attack
FTP Brute-Force
Ping of Death
Port Scan
Hacking
SQL Injection
Spoofing
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
IoT Targeted
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show moreWeb scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
[05/Oct/2026:02:56:00 +0300] -- 209.38.27.208 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git ...
show more[05/Oct/2026:02:56:00 +0300] -- 209.38.27.208 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
Anonymous
209.38.27.208 - - [04/Oct/2026:20:13:46 +0000] "GET /.git/config HTTP/1.1" 302 495 "-" "Mozilla/5.0 ...
show more209.38.27.208 - - [04/Oct/2026:20:13:46 +0000] "GET /.git/config HTTP/1.1" 302 495 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
...
show less
[SunOct0413:56:33.8005552026][security2:error][pid3473251:tid3473346][client209.38.27.208:0]ModSecur ...
show more[SunOct0413:56:33.8005552026][security2:error][pid3473251:tid3473346][client209.38.27.208:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"710\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"pmprogettazione.ch\"][uri\"/.git/config\"][unique_id\"asI-8QOY-sEwijR_Yq8zfQAAABc\"]
show less
1x HTTP 403 to krynox.dev from AU, method GET, path /.git/config. Blocked by Cloudflare action block ...
show more1x HTTP 403 to krynox.dev from AU, method GET, path /.git/config. Blocked by Cloudflare action block (firewallCustom). Repeated L7 flood traffic.
show less
[SunOct0406:57:02.2851352026][security2:error][pid473052:tid473117][client209.38.27.208:0]ModSecurit ...
show more[SunOct0406:57:02.2851352026][security2:error][pid473052:tid473117][client209.38.27.208:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"special-home.ch\"][uri\"/.git/config\"][unique_id\"asHcnkRwq02O8nTdph3HqQAAAIE\"]
show less
Blocked abusive HTTP application-layer DoS / botnet traffic from 209.38.27.208: traffic from this ad ...
show moreBlocked abusive HTTP application-layer DoS / botnet traffic from 209.38.27.208: traffic from this address continues high-cost dynamic page and feed requests at abusive rates via TCP/HTTPS despite edge block responses. Likely compromised end-user host.
show less
[03/Oct/2026:20:13:38 +0300] -- 209.38.27.208 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git ...
show more[03/Oct/2026:20:13:38 +0300] -- 209.38.27.208 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
Anonymous
209.38.27.208 - - [03/Oct/2026:16:21:47 +0000] "GET /.git/config HTTP/1.1" 302 495 "-" "Mozilla/5.0 ...
show more209.38.27.208 - - [03/Oct/2026:16:21:47 +0000] "GET /.git/config HTTP/1.1" 302 495 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
...
show less
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show moreWeb scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
2026-10-03 00:27 UTC HTTPS/443 - exploit and credential scanning. 2 GET requests to 1 distinct paths ...
show more2026-10-03 00:27 UTC HTTPS/443 - exploit and credential scanning. 2 GET requests to 1 distinct paths that do not exist on this application, across 2 hostnames, first seen 2026-10-01 20:07. Sample paths: /.git/config. User-agent: "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko)". Block cycle 2 for this address.
show less
[FriOct0223:01:32.7811852026][security2:error][pid1386066:tid1386082][client209.38.27.208:0]ModSecur ...
show more[FriOct0223:01:32.7811852026][security2:error][pid1386066:tid1386082][client209.38.27.208:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"710\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"pmprogettazione.ch\"][uri\"/.git/config\"][unique_id\"asAbrB18Q2G7PXPhx4cAKAAAAQ4\"]
show less