This IP address has been reported a total of
42
times from
20 distinct
sources.
27.21.28.252 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[TueAug1812:58:05.6751132026][security2:error][pid2975481:tid2975774][client27.21.28.252:0]ModSecuri ...
show more[TueAug1812:58:05.6751132026][security2:error][pid2975481:tid2975774][client27.21.28.252:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"465\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"www.marcionetti.es\"][uri\"/.env\"][unique_id\"aoQ6vSrS4TUOffT3Wa6PzAAAABg\"]
show less
Credential and secrets file probing | req: /.env | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) App ...
show moreCredential and secrets file probing | req: /.env | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0
show less
Hacking
Web App Attack
Anonymous
Bot / scanning and/or hacking attempts: PATCH / HTTP/1.1, GET /_ignition/health-check HTTP/1.1, GET ...
show moreBot / scanning and/or hacking attempts: PATCH / HTTP/1.1, GET /_ignition/health-check HTTP/1.1, GET /geoserver/rest/about/version.json HTTP/1.1, GET /wp-login.php HTTP/1.1, GET /login/index.php HTTP/1.1, GET /openbaar-vervoer-op-terschelling/ HTTP/1.1, GET /geoserver/web/ HTTP/1.1, GET /login/ HTTP/1.1, GET / HTTP/1.1, GET /telescope HTTP/1.1
show less
| [Dangerous/China] Aggressive IP 27.21.28.252 (~30 hits). Type: DoS Defender- Web server 400 error ...
show more| [Dangerous/China] Aggressive IP 27.21.28.252 (~30 hits). Type: DoS Defender- Web server 400 error code
show less