This IP address has been reported a total of
131
times from
40 distinct
sources.
104.28.196.108 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Blocked by UFW (TCP on 55553)
Source port: 9629
TTL: 48
Packet length: 60
TOS: 0x00
This report (fo ...
show moreBlocked by UFW (TCP on 55553)
Source port: 9629
TTL: 48
Packet length: 60
TOS: 0x00
This report (for 104.28.196.108) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Anonymous
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Blocked by UFW (TCP on 53912)
Source port: 9449
TTL: 42
Packet length: 60
TOS: 0x08
This report (fo ...
show moreBlocked by UFW (TCP on 53912)
Source port: 9449
TTL: 42
Packet length: 60
TOS: 0x08
This report (for 104.28.196.108) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Blocked by UFW (TCP on 6969)
Source port: 40653
TTL: 43
Packet length: 60
TOS: 0x08
This report (fo ...
show moreBlocked by UFW (TCP on 6969)
Source port: 40653
TTL: 43
Packet length: 60
TOS: 0x08
This report (for 104.28.196.108) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Blocked by UFW (TCP on 8999)
Source port: 44834
TTL: 43
Packet length: 60
TOS: 0x08
This report (fo ...
show moreBlocked by UFW (TCP on 8999)
Source port: 44834
TTL: 43
Packet length: 60
TOS: 0x08
This report (for 104.28.196.108) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Reconnaissance or port-scan activity observed on a honeypot sensor. Honeypot decoy type: P0f. Decoy ...
show moreReconnaissance or port-scan activity observed on a honeypot sensor. Honeypot decoy type: P0f. Decoy listen port: 33900/tcp. Observed event time: 2026-04-19 11:06:24 UTC. Report from passive honeypot only; no payload or credentials included.
show less
Reconnaissance or port-scan activity observed on a honeypot sensor. Honeypot decoy type: P0f. Decoy ...
show moreReconnaissance or port-scan activity observed on a honeypot sensor. Honeypot decoy type: P0f. Decoy listen port: 33900/tcp. Observed event time: 2026-04-19 10:59:57 UTC. Report from passive honeypot only; no payload or credentials included.
show less
Reconnaissance or port-scan activity observed on a honeypot sensor. Honeypot decoy type: Suricata. D ...
show moreReconnaissance or port-scan activity observed on a honeypot sensor. Honeypot decoy type: Suricata. Decoy listen port: 33900/tcp. Observed event time: 2026-04-19 10:34:02 UTC. Report from passive honeypot only; no payload or credentials included.
show less
Reconnaissance or port-scan activity observed on a honeypot sensor. Honeypot decoy type: Suricata. D ...
show moreReconnaissance or port-scan activity observed on a honeypot sensor. Honeypot decoy type: Suricata. Decoy listen port: 33900/tcp. Observed event time: 2026-04-19 10:27:02 UTC. Report from passive honeypot only; no payload or credentials included.
show less
Port Scan
Showing 1 to
15
of 131 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ