This IP address has been reported a total of
22
times from
19 distinct
sources.
37.238.115.148 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
(mod_security) mod_security (id:210350) triggered by 37.238.115.148 (-): 1 in the last 300 secs; Por ...
show more(mod_security) mod_security (id:210350) triggered by 37.238.115.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 00:02:17.213515 2026] [security2:error] [pid 29363:tid 29363] [client 37.238.115.148:41096] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||doctorbalog.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "doctorbalog.com"] [uri "/"] [unique_id "ars4SYiFkq1tuVo4c9AyCgAAABQ"], referer: https://backlinkservice.store/dir/seo-boosting-backlinks-56836
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
Large-scale coordinated botnet (6M+ IPs). Ordered by Alexander Pen'kov (alexander-pen-kov-7b41aa6a/S ...
show moreLarge-scale coordinated botnet (6M+ IPs). Ordered by Alexander Pen'kov (alexander-pen-kov-7b41aa6a/Shursky [yordim|LIS|MOW]): Retaliation after theft; Attacker: Mikhail Smirnov (mikhail-smirnov-79830323/Aidan [MOW]): Employed by Angara Technologies Group | Offpeak: Sessionless Catalog Access Blocked: /wishlist/index/add/product/499/form_key/c6CTKQQmwDI6ZJ30/ | UA: Mozilla/5.0 (Macintosh; U; PPC Mac OS X 10_7_2 rv:6.0; hak-TW) AppleWebKit/532.35.1 (KHTML, like Gecko) Version/4.0.5 Safari/532.35.1 | (Magento Site)
show less
Botnet UDP flood (DDoS) against a hosted game server at 185.143.177.x:5555/udp in AS203136 (LLC Ordu ...
show moreBotnet UDP flood (DDoS) against a hosted game server at 185.143.177.x:5555/udp in AS203136 (LLC Ordunet), Georgia. This source sustained more than 600 packets/sec toward that single UDP port - the server's whole legitimate load is about 200 packets/sec per player - during a flood that peaked at 53,054 packets/sec on this port, of which 36,662 packets/sec were discarded at our border. It was one of 239 sources from 154 networks in 52 countries recorded in a ten-minute window on 2026-09-04, and the same botnet hit this host from 3,229 addresses the night before. Detected on a MikroTik RouterOS router by per-source rate accounting in the raw/prerouting chain (dst-limit 600,200,src-address/10s); the timestamp is when this source crossed the threshold, timezone +04:00. Not a scan and not brute force - a packet flood, so the host is almost certainly compromised. Evidence on request to [email protected].
show less
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Sa ...
show moreMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36
show less
Fail2Ban: 37.238.115.148 was banned for Aggressive Bad Bot detected by Nginx/Fail2Ban. UA: Mozilla/5 ...
show moreFail2Ban: 37.238.115.148 was banned for Aggressive Bad Bot detected by Nginx/Fail2Ban. UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36
show less
Bad Web Bot
Anonymous
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to ...
show moreDistributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to bypass firewall/robots.txt restrictions in printer-friendly.asp
show less