AbuseIPDB » 211.251.203.14
211.251.203.14 was found in our database!
This IP was reported 7 times. Confidence of
Abuse
is 22% : ?
ISP
Korea Telecom
Usage Type
Fixed Line ISP
ASN
AS4766
Domain Name
kt.com
Country
π°π·
Korea (the Republic of)
City
Kyosai, Gyeongsangnam-do
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 211.251.203.14 :
This IP address has been reported a total of
7
times from
7 distinct
sources.
211.251.203.14 was first reported on
May 25th 2026 , and the most recent report was
18 hours ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
π¨π³
pengpeng
2026-09-18 03:58:04
(18 hours ago)
monitor: on VM-0-7-ubuntu | port: 22 | ttl: 250 script: github.com/sefinek/UFW-AbuseIPDB-Reporter
Port Scan
SSH
π―π΅
knock
2026-09-17 21:36:27
(1 day ago)
Knock-Knock honeypot brute-force: SSH (1 total hits)
Brute-Force
SSH
π¨π
backslash
2026-07-27 17:21:03
(1 month ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-07-21 23:59:10
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 211.251.203.14 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 211.251.203.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 19:59:04.264287 2026] [security2:error] [pid 590395:tid 590395] [client 211.251.203.14:43684] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.staben.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.staben.com"] [uri "/wp-login.php"] [unique_id "amAHyJ5c-sqz5gLLSS6hMQAAABs"], referer: https://www.staben.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
pltcldvlpr
2026-07-19 07:14:04
(1 month ago)
CMS/framework probe: 211.251.203.14 - - [19/Jul/2026:09:14:02 +0200] "GET /wp-login.php HTTP/1.1" 30 ...
show more
CMS/framework probe: 211.251.203.14 - - [19/Jul/2026:09:14:02 +0200] "GET /wp-login.php HTTP/1.1" 301 178 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:138.0) Gecko/20100101 Firefox/138.0" asn=4766 org="Korea Telecom" country=KR
...
show less
Web App Attack
π¨π
Origon
2026-06-21 15:52:15
(2 months ago)
http-admin-interface-probing - IP: 211.251.203.14 - time="2026-06-21T17:52:15+02:00" level=info msg ...
show more
http-admin-interface-probing - IP: 211.251.203.14 - time="2026-06-21T17:52:15+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-admin-interface-probing by ip 211.251.203.14 (KR/4766) : 4h ban on Ip 211.251.203.14" module=db
show less
Web App Attack
π©πͺ
MusicLibrary
2026-05-25 12:03:04
(3 months ago)
Attempted access to non existent wordpress urls
Bad Web Bot
Showing 1 to
7
of 7 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown π©
Recently Reported IPs: