AbuseIPDB » 81.101.11.238
81.101.11.238 was found in our database!
This IP was reported 8 times. Confidence of
Abuse
is 25% : ?
ISP
Virgin Media Limited
Usage Type
Fixed Line ISP
ASN
AS5089
Hostname(s)
swin-19-b2-v4wan-172933-cust1005.vm38.cable.virginm.net
Domain Name
virginmedia.com
Country
๐ฌ๐ง
United Kingdom of Great Britain and Northern Ireland
City
Birmingham, England
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 81.101.11.238 :
This IP address has been reported a total of
8
times from
8 distinct
sources.
81.101.11.238 was first reported on
April 19th 2026 , and the most recent report was
1 week ago .
Old Reports:
The most recent abuse report for this IP address is from
1 week ago
. It is possible that this IP is no longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐ฉ๐ช
pltcldvlpr
2026-07-15 13:20:54
(1 week ago)
Bogus Useragent: 81.101.11.238 - - [15/Jul/2026:15:20:53 +0200] "GET /protocol?id=he_17_5¶graph= ...
show more
Bogus Useragent: 81.101.11.238 - - [15/Jul/2026:15:20:53 +0200] "GET /protocol?id=he_17_5¶graph=4842355&seq=1427 HTTP/1.1" 302 5 "-" "Mozilla/5.0 (Windows 95) AppleWebKit/535.0 (KHTML, like Gecko) Chrome/60.0.896.0 Safari/535.0" asn=5089 org="Virgin Media Limited" country=GB
...
show less
Bad Web Bot
๐ฉ๐ช
botreporter
2026-06-27 02:58:02
(4 weeks ago)
botnet ignoring robots.txt
Bad Web Bot
๐บ๐ธ
kosada.com
2026-06-25 22:50:25
(4 weeks ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
Anonymous
2026-06-22 00:38:20
(1 month ago)
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to ...
show more
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to bypass firewall/robots.txt restrictions in email-link.asp
show less
Exploited Host
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-12 21:56:27
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 81.101.11.238 (swin-19-b2-v4wan-172933-cust1005 ...
show more
(mod_security) mod_security (id:225170) triggered by 81.101.11.238 (swin-19-b2-v4wan-172933-cust1005.vm38.cable.virginm.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 17:56:21.754174 2026] [security2:error] [pid 23958:tid 23991] [client 81.101.11.238:46604] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ccgparquitectos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ccgparquitectos.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiyAhdWWIr-H3I7AtQ8j_gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-06-09 20:54:43
(1 month ago)
(Kingcopy.org-AI-IDS-Report):IP automatically blocked after obfuscated redirect. Vegas Security
DDoS Attack
Hacking
Exploited Host
๐บ๐ธ
MPL
2026-04-19 21:20:57
(3 months ago)
tcp/443 (24 or more attempts)
Port Scan
๐ซ๐ท
security.yc3a.com
2026-04-19 17:43:27
(3 months ago)
81.101.11.238 - - [19/Apr/2026:15:48:08 +0000] "GET /api/images/ HTTP/1.1" 401 27 "-" "Mozilla/5.0 ( ...
show more
81.101.11.238 - - [19/Apr/2026:15:48:08 +0000] "GET /api/images/ HTTP/1.1" 401 27 "-" "Mozilla/5.0 (Linux; Android 8.0.0; SAMSUNG SM-G930VL) AppleWebKit/537.36 (KHTML, like Gecko) SamsungBrowser/18.0 Chrome/99.0.4844.88 Mobile Safari/537.36"
show less
Brute-Force
Web App Attack
Showing 1 to
8
of 8 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: