AbuseIPDB » 3.27.190.63
3.27.190.63 was found in our database!
This IP was reported 11 times. Confidence of
Abuse
is 0% : ?
ISP
Amazon Corporate Services Pty Ltd
Usage Type
Data Center/Web Hosting/Transit
ASN
AS16509
Hostname(s)
ec2-3-27-190-63.ap-southeast-2.compute.amazonaws.com
Domain Name
amazon.com.au
Country
๐ฆ๐บ
Australia
City
Sydney, New South Wales
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 3.27.190.63 :
This IP address has been reported a total of
11
times from
10 distinct
sources.
3.27.190.63 was first reported on
December 1st 2025 , and the most recent report was
7 months ago .
Old Reports:
The most recent abuse report for this IP address is from
7 months ago
. It is possible that this IP is no longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐บ๐ธ
mnsf
2025-12-02 08:05:36
(7 months ago)
Too many Status 40X (12)
Brute-Force
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2025-12-02 07:46:55
(7 months ago)
3.27.190.63 - - [02/Dec/2025:09:46:38 +0200] "GET /.env HTTP/1.1" 404 2815 "-" "python-httpx/0.28.1" ...
show more
3.27.190.63 - - [02/Dec/2025:09:46:38 +0200] "GET /.env HTTP/1.1" 404 2815 "-" "python-httpx/0.28.1"
3.27.190.63 - - [02/Dec/2025:09:46:54 +0200] "GET /vendor/.env HTTP/1.1" 404 2814 "-" "python-httpx/0.28.1"
...
show less
Web App Attack
๐ฉ๐ช
FeG Deutschland
2025-12-02 06:33:10
(7 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
Anonymous
2025-12-02 00:41:43
(7 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฉ๐ช
Hydra-Shield.fr
2025-12-01 22:22:22
(7 months ago)
Directory Traversal on: /.git/config
Web App Attack
Anonymous
2025-12-01 21:57:27
(7 months ago)
(mod_security) mod_security triggered on hostname [redacted] 3.27.190.63 (AU/Australia/ec2-3-27-190- ...
show more
(mod_security) mod_security triggered on hostname [redacted] 3.27.190.63 (AU/Australia/ec2-3-27-190-63.ap-southeast-2.compute.amazonaws.com)
show less
SQL Injection
๐จ๐ญ
zynex
2025-12-01 14:55:39
(7 months ago)
URL Probing: /i.php
Web App Attack
๐ฎ๐น
clamehost.it
2025-12-01 14:00:31
(7 months ago)
Automatic report - Brute Force attack using this IP address
Brute-Force
๐ซ๐ฎ
mnazibo
2025-12-01 12:13:09
(7 months ago)
Date: Dec 01 15:12:44
Reported IP: 3.27.190.63 mod_security
id:960035
AU/Australia/ec2-3-27-190-63.a ...
show more
Date: Dec 01 15:12:44
Reported IP: 3.27.190.63 mod_security
id:960035
AU/Australia/ec2-3-27-190-63.ap-southeast-2.compute.amazonaws.com
Connections: 5
Blocked: Permanent Block: [LF_MODSEC]
Logs: [Mon Dec 01 15:12:44.529539 2025] [:error] [pid 25552:tid 25581] [client 3.27.190.63:43322] [client 3.27.190.63] ModSecurity: Access denied with code 403 (phase 2). String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .resources/ .resx/ .sql/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/usr/local/apache/modsecurity-owasp-old/base_rules/modsecurity_crs_30_http_policy.conf"] [line "88"] [id "960035"] [rev "2"] [msg "URL file extension is restricted by policy"] [data ".config"] [severity "CRITICAL"] [ver "OWASP_CRS/2.2.9"] [maturity "9"]
show less
SQL Injection
๐ซ๐ท
masterguru
2025-12-01 11:07:02
(7 months ago)
BAD BOT - Detected and Blocked.. Matched phrase "python" at REQUEST_HEADERS:User-Agent. (1100000-196 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "python" at REQUEST_HEADERS:User-Agent. (1100000-196)
show less
Bad Web Bot
๐ซ๐ท
masterguru
2025-12-01 10:07:44
(7 months ago)
BAD BOT - Detected and Blocked.. Matched phrase "python" at REQUEST_HEADERS:User-Agent. (1100000-193 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "python" at REQUEST_HEADERS:User-Agent. (1100000-193)
show less
Bad Web Bot
Showing 1 to
11
of 11 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: