This IP address has been reported a total of
25
times from
17 distinct
sources.
27.147.224.115 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Germany
with 3
reports;
United States of America
with 3
reports;
Switzerland
with 1
report.
The most common categories in these recent reports were:
Bad Web Bot
4
times;
DDoS Attack
4
times;
Exploited Host
3
times;
Web App Attack
3
times;
Hacking
2
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
HTTP application-layer DoS / botnet traffic from 27.147.224.115: repeated high-cost dynamic page and ...
show moreHTTP application-layer DoS / botnet traffic from 27.147.224.115: repeated high-cost dynamic page and feed requests (profile/tag views, forums, tracker, RSS) at abusive rates via completed TCP/HTTPS. Likely compromised end-user host.
show less
Botnet UDP flood (DDoS) against a hosted game server at 185.143.177.x in AS203136 (LLC Ordunet), Geo ...
show moreBotnet UDP flood (DDoS) against a hosted game server at 185.143.177.x in AS203136 (LLC Ordunet), Georgia. On 2026-09-05 from 20:01 local time (+04:00) this host received 1,231,350 packets/sec, of which 1,220,538 packets/sec were discarded at our border - the largest attack we have recorded. The flood hit udp 4444, 44444 and 80 simultaneously from 2412 distinct sources in 1091 networks and 125 countries; small uniform UDP datagrams of 29-48 bytes, a pure packet-rate attack. This source sustained more than 600 packets/sec toward the host, against about 200 packets/sec for a legitimate player. Detected on a MikroTik RouterOS router by per-source rate accounting in the raw/prerouting chain (dst-limit 600,200,src-address/10s); the timestamp is when this source crossed the threshold. Not a scan and not brute force - the host is almost certainly compromised. Evidence on request to [email protected].
show less
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Sa ...
show moreMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
show less
WebKnight blocked malicious web request on johnkarlhill.com
Brute-Force
SSH
Anonymous
DDoS botnet 510.000+ IPs; URL with bing/trustpilot/githubhelp and %C2%A4 or \xc2\xa4. NEW 09/2025: a ...
show moreDDoS botnet 510.000+ IPs; URL with bing/trustpilot/githubhelp and %C2%A4 or \xc2\xa4. NEW 09/2025: amplification attacks via third-parties e.g. HTTP_USER_AGENT facebookexternalhit/meta-externalagent/meta-externalfetcher or IPs from googleusercontent.com with fake HTTP_REFERER foxnews.com/newsweek.com/upwork.com/activision.com/... Port 443.
show less