AbuseIPDB » 85.203.15.248
IP info including ISP, Usage Type, and Location provided by IPInfo. Updated weekly.
Top Reporter Countries (Last 60 Days)
Example previewReport Categories (Last 60 Days)
Example previewIP Abuse Reports for 85.203.15.248:
This IP address has been reported a total of 198 times from 109 distinct sources. 85.203.15.248 was first reported on , and the most recent report was . In the last 60 days, the top reporter locations were: United Kingdom of Great Britain and Northern Ireland with 2 reports; Ukraine with 2 reports; Czechia with 1 report. The most common categories in these recent reports were: Web App Attack 9 times; Bad Web Bot 3 times; Hacking 2 times; Brute-Force 1 time.
| Reporter | IoA Timestamp (UTC) | Comment | Categories | |
|---|---|---|---|---|
| 🇩🇪 raph |
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
|
Bad Web Bot Web App Attack | ||
| 🇺🇦 URAN Publishing Service |
[24/Aug/2026:08:46:20 +0300] -- 85.203.15.248 Ban reason: User-Agent Go-http-client
|
Bad Web Bot Web App Attack | ||
| 🇺🇦 URAN Publishing Service |
[05/Aug/2026:21:07:10 +0300] -- 85.203.15.248 Ban reason: User-Agent Go-http-client
|
Bad Web Bot Web App Attack | ||
| 🇬🇧 consul.to |
Web attack/malicious scanning detected
|
Web App Attack | ||
| 🇨🇿 ptlab |
Detected php_null_array_access attack from WP-host.
|
Hacking Web App Attack | ||
| 🇬🇧 consul.to |
Web attack/malicious scanning detected
|
Web App Attack | ||
| 🇹🇷 neron |
CrowdSec blocked: http:exploit detected via OPNsense firewall
|
Hacking Web App Attack | ||
| 🇿🇦 conure.sh |
csagent: score 15.2: php 404 x3, 404 noise floor x3, webshell name x1; 1 domain(s) in 0s
|
Web App Attack | ||
| 🇮🇱 Dolphi |
POST //xmlrpc.php
|
Brute-Force Web App Attack | ||
| 🇵🇾 armandosaucedo.me |
Threat Intelligence via ARMTI, Web Attack: GET /adminer.php
|
Web App Attack | ||
| 🇩🇪 Ba-Yu |
General hacking/exploits/scanning
|
Web Spam Hacking Brute-Force Exploited Host Web App Attack | ||
| 🇺🇸 Alvino |
Blocked due to using a VPN or data center IP with abuse: 45
|
Web Spam VPN IP | ||
| 🇨🇭 blinx |
Suspicious activity detected by Modsecurity
|
Web Spam Port Scan Hacking Bad Web Bot Web App Attack | ||
| 🇬🇧 consul.to |
Web attack/malicious scanning detected
|
Web App Attack | ||
| 🇩🇪 Hazzard |
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
|
SQL Injection |
Think this IP has been falsely reported? You may request to have the associated reports reviewed and removed. Request Takedown 🚩