This IP address has been reported a total of
8
times from
6 distinct
sources.
159.148.62.76 was first reported on
July 18th 2024 , and the most recent report was
1 day ago .
In the last 60 days, the top reporter locations were:
France
with 2
reports;
Germany
with 1
report.
The most common categories in these recent reports were:
Bad Web Bot
2
times;
DDoS Attack
2
times;
Exploited Host
1
time;
Web App Attack
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐ซ๐ท
Tilellit.PRO
2026-10-07 00:22:03
(1 day ago)
PrestaShop faceted search filter flooding attempt
DDoS Attack
Bad Web Bot
๐ซ๐ท
vtchost.com
2026-09-28 18:02:55
(1 week ago)
requested HTTP honeypot page - ignored robots.txt - bad crawler
...
Bad Web Bot
Exploited Host
๐ฉ๐ช
LRob
2026-08-23 15:19:24
(1 month ago)
L7 DDoS: distributed flood on a shop's faceted search โ automated requests to search/sort URLs, one ...
show more
L7 DDoS: distributed flood on a shop's faceted search โ automated requests to search/sort URLs, one or two per address from thousands of addresses, no page assets loaded | path: /18-velo-route | query: q=Stock+magasin-Cycling+H%C3%A9nin%5C-Beaumont-Cycling+Montpellier/Taille-XXS-XL/Marque-Scott/Famille-Addict-Foil+RC&resultsPerP | 2026-08-23 15:19 UTC
show less
DDoS Attack
Web App Attack
๐ช๐ธ
el-brujo
2026-04-13 19:25:05
(5 months ago)
Cloudflare WAF: Request Path: /geolocalizacion.html Request Query: ?host=32.122.195.63 Host: elhacke ...
show more
Cloudflare WAF: Request Path: /geolocalizacion.html Request Query: ?host=32.122.195.63 Host: elhacker.net userAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36 Action: managed_challenge Source: firewallCustom ASN Description: BITE-US Country: US Method: GET Timestamp: 2026-04-13T19:25:05Z ruleId: 3c55069d689d450eb591f3b84da7ce04. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
ipblock.com
2025-12-29 17:01:00
(9 months ago)
IPBlock protected site ID [1365-l].
Robotic site crawling, undeclared spider
Bad Web Bot
Web App Attack
๐บ๐ธ
ipblock.com
2025-12-29 16:57:00
(9 months ago)
IPBlock protected site ID [1365-l].
Persistent 404, vulnerability scanner
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-24 19:46:07
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 159.148.62.76 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 159.148.62.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 24 15:46:00.859869 2025] [security2:error] [pid 14704:tid 14704] [client 159.148.62.76:55516] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.vangentholding.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.vangentholding.com"] [uri "/wp-json/wp/v2/users/280804"] [unique_id "aPvXeIQJ_yG2s1EyXqzSqgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-07-18 15:41:16
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 159.148.62.76 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 159.148.62.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 18 11:41:10.991320 2024] [security2:error] [pid 20603:tid 20603] [client 159.148.62.76:58356] [client 159.148.62.76] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.vangentholding.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.vangentholding.com"] [uri "/wp-json/wp/v2/users/128383"] [unique_id "Zpk3lrOsx4nJ6G4k2wod8gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Showing 1 to
8
of 8 reports