This IP address has been reported a total of
9
times from
8 distinct
sources.
138.226.96.128 was first reported on
November 11th 2025 , and the most recent report was
1 month ago .
In the last 60 days, the only reporter location was:
Germany
with 1
report.
The most common categories in these recent reports were:
Web App Attack
1
time;
DDoS Attack
1
time.
Old Reports
The most recent abuse report for this IP address is from
1 month ago . It is possible that this IP is no
longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
π©πͺ
LRob
2026-08-21 15:32:22
(1 month ago)
L7 DDoS: distributed flood on a shop's faceted search β automated requests to search/sort URLs, one ...
show more
L7 DDoS: distributed flood on a shop's faceted search β automated requests to search/sort URLs, one or two per address from thousands of addresses, no page assets loaded | path: /18-velo-route | query: q=Stock+magasin-Cycling+Cavaillon-Cycling+H%C3%A9nin%5C-Beaumont/Taille-S-XL/Famille-Metrix-Pulsium-Xelius/Mat%C3%A9riau-Alumini
show less
DDoS Attack
Web App Attack
π«π·
FRANCKY IV
2026-05-08 19:34:00
(4 months ago)
Probably part of a botnet
Bad Web Bot
π©πͺ
EGP Abuse Dept
2026-04-15 00:36:00
(5 months ago)
Scraping webshop URLs (www.qusedpallets.com), likely botnet drone
Bad Web Bot
Exploited Host
πΊπΈ
kosada.com
2026-03-10 21:55:26
(6 months ago)
Web bot: DDoS
DDoS Attack
Bad Web Bot
πΊπΈ
ipblock.com
2026-01-01 09:31:00
(9 months ago)
IPBlock protected site ID [1365-l].
Persistent 404, vulnerability scanner
Hacking
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-12-19 03:26:11
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 138.226.96.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 138.226.96.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 18 22:26:06.230757 2025] [security2:error] [pid 3405:tid 3405] [client 138.226.96.128:25876] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.scoutinsignia.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.scoutinsignia.com"] [uri "/images/Thumbs.db"] [unique_id "aUTFzgJv1r8iq3tMrZN2kwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
MAGIC
2025-12-17 01:12:45
(9 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
πΊπΈ
TPI-Abuse
2025-12-12 18:16:28
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 138.226.96.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 138.226.96.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 12 13:16:22.675178 2025] [security2:error] [pid 32226:tid 32226] [client 138.226.96.128:42642] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.vangentholding.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.vangentholding.com"] [uri "/wp-json/wp/v2/users/246357"] [unique_id "aTxb9ojoTPh2fC91wGCkRgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
backslash
2025-11-11 16:45:15
(10 months ago)
block ruleset 798ECF92F12ADC636D3520C2890AF17ADEFDE3BE
Bad Web Bot
Showing 1 to
9
of 9 reports