This IP address has been reported a total of
72
times from
34 distinct
sources.
209.38.85.39 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
United States of America
with 33
reports;
Germany
with 9
reports;
Netherlands
with 5
reports.
The most common categories in these recent reports were:
Web App Attack
65
times;
Bad Web Bot
34
times;
Brute-Force
34
times;
Hacking
18
times;
Port Scan
4
times;
Other
11
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[AUTORAVALT][[06/10/2026 - 22:34:03 -03:00 UTC]
Attack from [DigitalOcean, LLC]
[209.38.85.39] Actio ...
show more[AUTORAVALT][[06/10/2026 - 22:34:03 -03:00 UTC]
Attack from [DigitalOcean, LLC]
[209.38.85.39] Action: BLocKed
Hacking... Unauthorized attempts to access the server.
Web App Attack -> Attempts to probe for or exploit installed web applications such as a CMS like WordPress/Drupal, e-commerce solutions, forum software, phpMyAdmin and various other software plugi]
...
show less
[MonOct0513:43:01.2086092026][security2:error][pid2239519:tid2239643][client209.38.85.39:0]ModSecuri ...
show more[MonOct0513:43:01.2086092026][security2:error][pid2239519:tid2239643][client209.38.85.39:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"glass-container.com\"][uri\"/.git/config\"][unique_id\"asONRcKzZfj7ZDioSCkrZwAAAMs\"]
show less
[AUTORAVALT][[05/10/2026 - 03:58:09 -03:00 UTC]
Attack from [DigitalOcean, LLC]
[209.38.85.39] Actio ...
show more[AUTORAVALT][[05/10/2026 - 03:58:09 -03:00 UTC]
Attack from [DigitalOcean, LLC]
[209.38.85.39] Action: BLocKed
Hacking... Unauthorized attempts to access the server.
Web App Attack -> Attempts to probe for or exploit installed web applications such as a CMS like WordPress/Drupal, e-commerce solutions, forum software, phpMyAdmin and various other software plugi]
...
show less
Blocked by WAF: 2 request(s) probing for PHP scripts, WordPress files or secrets on a site without P ...
show moreBlocked by WAF: 2 request(s) probing for PHP scripts, WordPress files or secrets on a site without PHP: GET /.git/config β’ Reported by: github.com/pfstr/cloudflare-abuseipdb-reporter
show less
[SunOct0417:52:57.6464202026][security2:error][pid1080874:tid1080950][client209.38.85.39:0]ModSecuri ...
show more[SunOct0417:52:57.6464202026][security2:error][pid1080874:tid1080950][client209.38.85.39:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"glass-container.com\"][uri\"/.git/config\"][unique_id\"asJ2We3HrOiC9KibG6qKTAAAAEI\"]
show less
[04/Oct/2026:01:39:10 +0300] -- 209.38.85.39 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/ ...
show more[04/Oct/2026:01:39:10 +0300] -- 209.38.85.39 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Blocked by WAF: 2 request(s) probing WordPress/secret paths on a non-WordPress site: GET /.git/confi ...
show moreBlocked by WAF: 2 request(s) probing WordPress/secret paths on a non-WordPress site: GET /.git/config
show less
[SatOct0317:36:50.5013412026][security2:error][pid3927841:tid3927854][client209.38.85.39:0]ModSecuri ...
show more[SatOct0317:36:50.5013412026][security2:error][pid3927841:tid3927854][client209.38.85.39:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"ecosuber.com\"][uri\"/.git/config\"][unique_id\"asEhEmsfU2r95GG_UUVt2wAAAQA\"]
show less
Port Scan
Brute-Force
Web App Attack
Anonymous
209.38.85.39 detected and blocked by apache-modsecurity after 1 try
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show moreWeb scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less