๐ซ๐ฎ
nNordic
2026-06-09 10:19:14
(1 week ago)
Connection attempt blocked by IDS/IPS from 38.135.24.32/32
Hacking
๐ฎ๐น
Progetto1
2026-05-15 09:35:07
(1 month ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ซ๐ฎ
as211431.net
2026-05-14 06:36:01
(1 month ago)
Triggered Cloudflare WAF (firewallCustom) from T1.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from T1.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) SamsungBrowser/29.0 Chrome/136.0.0.0 Mobile Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
FeG Deutschland
2026-05-13 02:54:48
(1 month ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐ง๐ท
ICS Labs
2026-05-12 01:19:02
(1 month ago)
ICS Labs identified 38.135.24.32 as a malicious indicator from threat intelligence.
Hacking
Anonymous
2026-05-11 18:09:05
(1 month ago)
38.135.24.32 - - [11/May/2026:18:09:04 +0000] "GET /bothole/stinkwell.php?t=44302&view=print%27%29%2 ...
show more
38.135.24.32 - - [11/May/2026:18:09:04 +0000] "GET /bothole/stinkwell.php?t=44302&view=print%27%29%20AND%202786%3DCAST%28%28CHR%28113%29%7C%7CCHR%28106%29%7C%7CCHR%28120%29%7C%7CCHR%28118%29%7C%7CCHR%28113%29%29%7C%7C%28SELECT%20%28CASE%20WHEN%20%282786%3D2786%29%20THEN%201%20ELSE%200%20END%29%29%3A%3Atext%7C%7C%28CHR%28113%29%7C%7CCHR%28113%29%7C%7CCHR%28113%29%7C%7CCHR%2898%29%7C%7CCHR%28113%29%29%20AS%20NUMERIC%29%20AND%20%28%27tnON%27%3D%27tnON HTTP/1.1" 307 6661 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4.1 Safari/605.1.15"
...
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-05-08 11:38:10
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 38.135.24.32 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 38.135.24.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 07:38:04.000614 2026] [security2:error] [pid 12277:tid 12277] [client 38.135.24.32:46990] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jerusalem-temple-today.com"] [uri "/.git/config"] [unique_id "af3LHBCc5Vo1X9_PLoxQtwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Globe2
2026-05-08 11:11:15
(1 month ago)
ModSec - Multiple 403s within a short period of time [server: H3]
Web App Attack
๐บ๐ธ
mnsf
2026-05-07 06:05:26
(1 month ago)
Scanning/Probing (12)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-07 01:24:24
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 38.135.24.32 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 38.135.24.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 06 21:24:19.165150 2026] [security2:error] [pid 20796:tid 20796] [client 38.135.24.32:38904] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mackdaddy.smoothg.com"] [uri "/.git/config"] [unique_id "afvpw0E2feis7Lsq7NRCtwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-06 04:04:29
(1 month ago)
2026-05-05 19:00:41,750 fail2ban.actions [3625835]: NOTICE [tor] Ban 38.135.24.32
2026-05-05 ...
show more
2026-05-05 19:00:41,750 fail2ban.actions [3625835]: NOTICE [tor] Ban 38.135.24.32
2026-05-05 22:00:39,089 fail2ban.actions [3625835]: NOTICE [tor] Ban 38.135.24.32
2026-05-06 01:00:38,736 fail2ban.actions [3625835]: NOTICE [tor] Ban 38.135.24.32
2026-05-06 04:00:47,114 fail2ban.actions [3625835]: NOTICE [tor] Ban 38.135.24.32
2026-05-06 07:04:27,708 fail2ban.actions [3625835]: NOTICE [tor] Ban 38.135.24.32
show less
Brute-Force
๐ฆ๐บ
oncord
2026-05-05 04:40:07
(1 month ago)
Form spam
Web Spam
Anonymous
2026-05-03 20:43:18
(1 month ago)
This IP was involved in an brute force and password spray attack on 2026/05/03 15:41:14
Port Scan
Brute-Force
Exploited Host
Web App Attack
๐จ๐ฟ
ddw
2026-05-01 20:12:11
(1 month ago)
WordPress XMLRPC.PHP Access Attempt.
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-01 17:13:17
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 38.135.24.32 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 38.135.24.32 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 01 13:13:10.990438 2026] [security2:error] [pid 6271:tid 6271] [client 38.135.24.32:34228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "play.blueonyx.ca"] [uri "/.git/config"] [unique_id "afTfJhsqOC54eiQeSYfmNwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack