This IP address has been reported a total of
8
times from
4 distinct
sources.
104.28.231.164 was first reported on
August 18th 2026 , and the most recent report was
43 minutes ago .
In the last 60 days, the top reporter locations were:
United States of America
with 7
reports;
Russian Federation
with 1
report.
The most common categories in these recent reports were:
Web App Attack
7
times;
Brute-Force
6
times;
Bad Web Bot
5
times;
Port Scan
2
times;
DDoS Attack
1
time;
Other
2
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐ท๐บ
Agrohim
2026-10-06 07:00:30
(43 minutes ago)
Gate Inet blocked for categories:
DDoS Attack
Ping of Death
Port Scan
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-18 05:28:29
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.28.231.164 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.231.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 01:28:22.216579 2026] [security2:error] [pid 9123:tid 9123] [client 104.28.231.164:50031] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "communitycontrol.com"] [uri "/.env"] [unique_id "aoPtdr3dUKnMO6EkzK2ZywAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nationaleventpros.com
2026-08-18 04:42:01
(1 month ago)
vulnerability scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 04:28:33
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.28.231.164 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.231.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 00:28:26.083699 2026] [security2:error] [pid 30023:tid 30023] [client 104.28.231.164:49892] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cles-fonctionnel.com"] [uri "/.env"] [unique_id "aoPfamtkYACiIPs0rEoojQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 03:43:16
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.28.231.164 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.231.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 23:43:10.901206 2026] [security2:error] [pid 15183:tid 15183] [client 104.28.231.164:50095] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cosplayculture.com"] [uri "/.env"] [unique_id "aoPUzpmhyGC7kgMM2a4lmwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 02:45:16
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.28.231.164 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.231.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 22:45:10.274368 2026] [security2:error] [pid 21836:tid 21836] [client 104.28.231.164:49702] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "coalminer.com"] [uri "/.env"] [unique_id "aoPHNgvEUkrcE55hdIvVlAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 00:27:34
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.28.231.164 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.231.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 20:27:26.481596 2026] [security2:error] [pid 13951:tid 13951] [client 104.28.231.164:49865] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "computersraleigh.com"] [uri "/.env"] [unique_id "aoOm7tmmksk6ZxPLyjubqQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Rip
2026-08-18 00:20:26
(1 month ago)
Restricted File Access Attempts
Port Scan
Web App Attack
Showing 1 to
8
of 8 reports