This IP address has been reported a total of
3
times from
3 distinct
sources.
38.137.48.65 was first reported on
, and the most recent report was
.
Old Reports:
The most recent abuse report for this IP address is from
. It is possible that this IP is no longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to ...
show moreDistributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to bypass firewall/robots.txt restrictions in thread-skip.asp
show less
Exploited Host
Bad Web Bot
Anonymous
Botnet activity. Attribution: Angara Technologies Group / mikhail-smirnov-79830322 | Attack Signatur ...
show moreBotnet activity. Attribution: Angara Technologies Group / mikhail-smirnov-79830322 | Attack Signature Blocked: /wishlist/index/add/product/11361/form_key/1gcr8HRg7lGyUWAl/ | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like G...
show less
Subject: SQL Injection Attack from IP 38.137.48.65
We have detected a SQL injection attack originat ...
show moreSubject: SQL Injection Attack from IP 38.137.48.65
We have detected a SQL injection attack originating from IP address 38.137.48.65 targeting our web server at domatengineering.com on February 27, 2026 at approximately 16:45 UTC.
The attacker sent a crafted Oracle SQL injection payload via an HTTP GET request attempting to exploit our search functionality:
DBMS_UTILITY.SQLID_TO_SQLHASH(CHR(126)||'~'||(SELECT/**/(CASE/**/WHEN/**/(4839=4839)/**/THEN/**/1/**/ELSE/**/0/**/END)/**/FROM/**/DUAL)
Attack type: SQL Injection + Remote Command Execution attempt
Target: /index.php?dispatch=products.search
Source IP: 38.137.48.65
Date/Time: 2026-02-27 ~16:45 UTC
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36
Result: Blocked by ModSecurity (OWASP CRS rules 942100, 932115, 933160)
Please investigate and take appropriate action against this IP address.
show less
Brute-Force
Bad Web Bot
Exploited Host
Hacking
SQL Injection
Showing 1 to
3
of 3 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ