Anonymous
2026-08-22 06:03:20
(2 weeks ago)
denied Telnet access attempt. destination port 23.
Port Scan
Brute-Force
🇺🇸
NetVexor
2026-08-21 01:40:02
(2 weeks ago)
Attack source identified and submitted via NetVexor BGP Blackhole Network
Port Scan
Hacking
Brute-Force
🇩🇪
Didier Lagaert
2026-08-06 17:50:22
(4 weeks ago)
lie-7 : Trying access unauthorized files/dir=>/tmp/544544.shtml
Hacking
🇺🇸
xmission.com
2026-07-26 16:01:38
(1 month ago)
Blocked by UFW (TCP on 52018)
Source port: 12149
TTL: 47
Packet length: 60
TOS: 0x08
This report (f ...
show more
Blocked by UFW (TCP on 52018)
Source port: 12149
TTL: 47
Packet length: 60
TOS: 0x08
This report (for 104.28.156.39) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
🇺🇸
kosada.com
2026-07-17 23:28:45
(1 month ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
🇺🇸
kosada.com
2026-07-06 07:15:00
(1 month ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
🇷🇺
Agrohim
2026-07-01 00:16:33
(2 months ago)
Gate Inet blocked for categories:
DDoS Attack
Ping of Death
Port Scan
Hacking
Brute-Force
🇩🇪
reznekcs
2026-06-13 20:06:39
(2 months ago)
F2B wordpress ban. Logs: 104.28.156.39 - - [13/Jun/2026:22:04:31 +0200] "POST /xmlrpc.php HTTP/1.1" ...
show more
F2B wordpress ban. Logs: 104.28.156.39 - - [13/Jun/2026:22:04:31 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4477 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.1)"
104.28.156.39 - - [13/Jun/2026:22:06:38 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4477 "-" "WordPress.com; https://wordpress.com"
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-06-08 17:30:13
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 104.28.156.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 104.28.156.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 13:30:09.321919 2026] [security2:error] [pid 23277:tid 23277] [client 104.28.156.39:10609] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 104.28.156.39 (+1 hits since last alert)|fattoria-rendena.it|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "fattoria-rendena.it"] [uri "/xmlrpc.php"] [unique_id "aib8IeAVJh9ScfnyMgoM9wAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
AWW-Admin
2026-06-08 14:32:29
(2 months ago)
(wordpress) Failed wordpress login from 104.28.156.39 (PL/Poland/-)
Brute-Force
🇩🇪
strxmpp
2026-05-29 21:03:42
(3 months ago)
104.28.156.39 - - [29/May/2026:23:03:41 +0200] "GET /api/config HTTP/1.1" 404 546 "-" "node"
...
Bad Web Bot
Anonymous
2026-05-28 06:29:34
(3 months ago)
104.28.156.39 - - [28/May/2026:03:29:31 -0300] "GET /api/tags HTTP/1.1" 404 870 "-" "node"
104.28.15 ...
show more
104.28.156.39 - - [28/May/2026:03:29:31 -0300] "GET /api/tags HTTP/1.1" 404 870 "-" "node"
104.28.156.39 - - [28/May/2026:03:29:32 -0300] "GET /openapi.json HTTP/1.1" 404 870 "-" "node"
104.28.156.39 - - [28/May/2026:03:29:32 -0300] "GET /openapi.json HTTP/1.1" 404 870 "-" "node"
104.28.156.39 - - [28/May/2026:03:29:32 -0300] "GET /openapi.json HTTP/1.1" 404 870 "-" "node"
104.28.156.39 - - [28/May/2026:03:29:33 -0300] "GET /openapi.json HTTP/1.1" 404 870 "-" "node"
...
show less
Port Scan
🇺🇦
URAN Publishing Service
2026-05-16 15:38:33
(3 months ago)
104.28.156.39 - - [16/May/2026:18:38:09 +0300] "GET /cgi-bin/authLogin.cgi HTTP/1.1" 404 3082 "-" "M ...
show more
104.28.156.39 - - [16/May/2026:18:38:09 +0300] "GET /cgi-bin/authLogin.cgi HTTP/1.1" 404 3082 "-" "Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)"
104.28.156.39 - - [16/May/2026:18:38:29 +0300] "GET /wp-content/themes/astra/ HTTP/1.1" 404 3346 "-" "Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)"
...
show less
Web App Attack
🇦🇺
screwlooseit.com.au
2026-05-11 19:52:03
(3 months ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
US/United States/-
Web App Attack
Anonymous
2026-05-11 17:49:09
(3 months ago)
[redacted] 104.28.156.39 - - [11/May/2026:19:48:25 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "J ...
show more
[redacted] 104.28.156.39 - - [11/May/2026:19:48:25 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.1)"
[redacted] 104.28.156.39 - - [11/May/2026:19:48:36 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.1; WordPress/6.4; http://site51725395.com"
[redacted] 104.28.156.39 - - [11/May/2026:19:48:46 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 104.28.156.39 - - [11/May/2026:19:48:57 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.4)"
[redacted] 104.28.156.39 - - [11/May/2026:19:49:08 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
...
show less
Hacking
Web App Attack