AbuseIPDB » 104.22.1.61
Whitelisted netblocks are typically owned by trusted entities, such as Google or Microsoft who may use them for search engine spiders. However, these same entities sometimes also provide cloud servers and mail services which are easily abused. Pay special attention when trusting or distrusting these IPs.
104.22.1.61 is an IP address from within our whitelist belonging to the subnet 104.16.0.0/13, which we identify as "Cloudflare Reverse Proxy".
IP info including ISP, Usage Type, and Location provided by IPInfo. Updated weekly.
Top Reporter Countries (Last 60 Days)
Example previewReport Categories (Last 60 Days)
Example previewIP Abuse Reports for 104.22.1.61:
This IP address has been reported a total of 16 times from 13 distinct sources. 104.22.1.61 was first reported on , and the most recent report was . In the last 60 days, the top reporter locations were: Netherlands with 2 reports; United States of America with 2 reports; Belgium with 1 report. The most common categories in these recent reports were: Web App Attack 7 times; Port Scan 2 times; Brute-Force 1 time; DDoS Attack 1 time; Email Spam 1 time; Other 3 times.
| Reporter | IoA Timestamp (UTC) | Comment | Categories | |
|---|---|---|---|---|
| ๐ณ๐ฑ BlueWire Hosting |
High-confidence malicious configuration/VCS probe
|
Web App Attack | ||
| ๐ซ๐ท chengkev |
Esta IP fue detectada por CrowdSec, activando crowdsecurity/http-probing
|
Web App Attack Hacking | ||
| ๐ณ๐ฑ debestelapp |
|
Web App Attack | ||
| ๐ฉ๐ช gadix |
|
Web App Attack | ||
| ๐ง๐ช madeit |
|
Web App Attack | ||
| ๐บ๐ธ Lee Daniel |
104.22.1.61 - - [16/Jul/2026:17:40:27 -0400] "GET /.aws/credentials HTTP/1.1" 403 4821 "-" "-"
...
|
DDoS Attack Web Spam Email Spam Port Scan Brute-Force Bad Web Bot Web App Attack | ||
| ๐บ๐ธ micropedro |
|
Port Scan Web App Attack | ||
| ๐บ๐ธ kosada.com |
Web vulnerability probing: /settings.py
|
Web App Attack | ||
| ๐บ๐ธ TPI-Abuse |
|
Brute-Force Bad Web Bot Web App Attack | ||
| ๐ณ๐ฑ homeshowdomain.nl |
Auto-ban: >3000 req/min op 2026-06-17
|
Web App Attack SSH Hacking | ||
| ๐บ๐ธ mawan |
Suspected of having performed illicit activity on LAX server.
|
Web App Attack | ||
| ๐บ๐ธ myagent.site |
Blocking for trying to access an exploit file: /.env.docker
|
Hacking | ||
| ๐บ๐ธ myagent.site |
Blocking for trying to access an exploit file: /.env.production.local
|
Hacking | ||
| ๐ฉ๐ช andrepcg |
Port scanning (104.22.1.61 -> :8443)
|
Port Scan Brute-Force | ||
| ๐บ๐ธ mawan |
Suspected of having performed illicit activity on LAX server.
|
Web App Attack |
Think this IP has been falsely reported? You may request to have the associated reports reviewed and removed. Request Takedown ๐ฉ