AbuseIPDB » 112.203.169.106
112.203.169.106 was found in our database!
This IP was reported 8 times. Confidence of
Abuse
is 39% : ?
ISP
IPG
Usage Type
Fixed Line ISP
ASN
AS9299
Hostname(s)
112.203.169.106.pldt.net
Domain Name
pldthome.com
Country
๐ต๐ญ
Philippines
City
Quezon City, National Capital Region
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 112.203.169.106 :
This IP address has been reported a total of
8
times from
7 distinct
sources.
112.203.169.106 was first reported on
February 28th 2026 , and the most recent report was
1 day ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐ซ๐ท
Coco Bongo
2026-07-27 02:05:30
(1 day ago)
1785117929 - 07/27/2026 04:05:29 Host: 112.203.169.106/112.203.169.106 Port: 445 TCP Blocked
...
Port Scan
Anonymous
2026-07-25 14:19:56
(2 days ago)
denied SMB access attempt. destination port 445.
Port Scan
Hacking
Anonymous
2026-07-25 10:52:28
(2 days ago)
2026-07-25T12:52:27.550644+02:00 vps kernel: [1347602.412012] [PORTSCAN DETECTED] IN=ens3 OUT= MAC=f ...
show more
2026-07-25T12:52:27.550644+02:00 vps kernel: [1347602.412012] [PORTSCAN DETECTED] IN=ens3 OUT= MAC=fa:16:3e:66:f6:24:02:37:19:0d:c2:f3:08:00 SRC=112.203.169.106 DST=54.37.14.118 LEN=52 TOS=0x00 PREC=0x00 TTL=112 ID=29582 DF PROTO=TCP SPT=31595 DPT=445 WINDOW=8192 RES=0x00 SYN URGP=0
...
show less
Port Scan
Brute-Force
๐ต๐ฑ
nfsec.pl
2026-07-23 03:57:58
(5 days ago)
Detected: TCP scan on port: 445 with flags: SYN
Port Scan
๐ซ๐ท
Entalpi.net
2026-07-22 12:18:07
(5 days ago)
Tried to hit sensible closed port commonly used in attacks
Port Scan
Hacking
๐ฉ๐ช
crnpekgoz
2026-07-22 11:52:59
(5 days ago)
[PortScan] Risk=100 ASN=9299 (portscan) Port=445 HoneypotTrap=true | Reported by WardenIPS: https:// ...
show more
[PortScan] Risk=100 ASN=9299 (portscan) Port=445 HoneypotTrap=true | Reported by WardenIPS: https://github.com/msncakma/WardenIPS
show less
Port Scan
๐ช๐ธ
el-brujo
2026-02-28 12:28:09
(4 months ago)
28/Feb/2026:13:28:09.428035 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
28/Feb/2026:13:28:09.428035 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 112.203.169.106] ModSecurity: Warning. detected SQLi using libinjection with fingerprint 'sos' [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "66"] [id "942100"] [msg "SQL Injection Attack Detected via libinjection"] [data "Matched Data: sos found within ARGS:_wp_http_referer: /contacto/)AND/**/GTID_SUBSET(CONCAT('~',(SELECT/**/(ELT(6930=6930,1))),'~'),6930)-- -"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [hostname "hwagm.elhacker.net"] [uri "/contacto/"] [unique_id "aaLfWUUTTiejNWNgp2RfoQAFlhg"]
...
show less
Hacking
Web App Attack
๐ช๐ธ
el-brujo
2026-02-28 12:28:08
(4 months ago)
Cloudflare WAF: Request Path: /contacto/ Request Query: Host: hwagm.elhacker.net userAgent: Mozilla ...
show more
Cloudflare WAF: Request Path: /contacto/ Request Query: Host: hwagm.elhacker.net userAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Action: log Source: firewallManaged ASN Description: IPG-AS-AP Philippine Long Distance Telephone Company Country: PH Method: POST Timestamp: 2026-02-28T12:28:08Z ruleId: 3b0c61407d0b4f7d87e516472116d2fe. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
Showing 1 to
8
of 8 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: