AbuseIPDB » 103.127.48.200
103.127.48.200 was found in our database!
This IP was reported 10 times. Confidence of
Abuse
is 36% : ?
ISP
FIBERTEL FIBERNET PVT. LTD
Usage Type
Fixed Line ISP
ASN
AS138500
Domain Name
fibertel.com
Country
π³π΅
Nepal
City
Dhangadhi, Sudurpashchim Pradesh
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 103.127.48.200 :
This IP address has been reported a total of
10
times from
7 distinct
sources.
103.127.48.200 was first reported on
May 3rd 2026 , and the most recent report was
7 hours ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
π¦πΉ
urnilxfgbez
2026-08-22 22:45:00
(7 hours ago)
Last 24 Hours suspicious: (DPT=445|DPT=3389|DPT=22|DPT=3306|DPT=8080|DPT=23|DPT=5900|DPT=1433)
Port Scan
πΊπΈ
xmission.com
2026-08-21 22:55:26
(1 day ago)
Blocked by UFW (TCP on 22)
Source port: 37760
TTL: 40
Packet length: 60
TOS: 0x08
This report (for ...
show more
Blocked by UFW (TCP on 22)
Source port: 37760
TTL: 40
Packet length: 60
TOS: 0x08
This report (for 103.127.48.200) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
SSH
Brute-Force
πΊπΈ
kosada.com
2026-08-16 15:47:04
(6 days ago)
Web bot: DDoS
DDoS Attack
Bad Web Bot
Anonymous
2026-08-15 01:15:32
(1 week ago)
denied traffic to a honeypot network. destination port 22.
Port Scan
Hacking
πΉπ·
SeczarSecureOps
2026-08-12 02:50:23
(1 week ago)
Auto-blocked by Seczar SecureOps β SSH Brute Force (6 events in 5min) at 2026-08-12 02:50
Web App Attack
πΊπΈ
kosada.com
2026-07-28 14:22:02
(3 weeks ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
πΊπΈ
kosada.com
2026-06-29 14:16:59
(1 month ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-05-15 20:48:42
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 103.127.48.200 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 103.127.48.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 16:48:35.358385 2026] [security2:error] [pid 13714:tid 13714] [client 103.127.48.200:58501] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.127.48.200 (+1 hits since last alert)|indiahouseportland.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "indiahouseportland.com"] [uri "/xmlrpc.php"] [unique_id "ageGo_1a0DjbZlC5cX_yZAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-15 18:13:10
(3 months ago)
Attac
Brute-Force
πΊπΈ
TPI-Abuse
2026-05-03 16:06:52
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 103.127.48.200 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 103.127.48.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 03 12:06:47.818450 2026] [security2:error] [pid 7343:tid 7343] [client 103.127.48.200:54759] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.127.48.200 (+1 hits since last alert)|whodatnation.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "whodatnation.com"] [uri "/xmlrpc.php"] [unique_id "afdyl0z1wrR4PwlwqVMkigAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Showing 1 to
10
of 10 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown π©
Recently Reported IPs: