This IP address has been reported a total of
75
times from
36 distinct
sources.
104.28.236.165 was first reported on
June 10th 2023 , and the most recent report was
3 weeks ago .
In the last 60 days, the only reporter location was:
Indonesia
with 1
report.
The most common categories in these recent reports were:
Web App Attack
1
time;
DDoS Attack
1
time;
Port Scan
1
time;
Bad Web Bot
1
time.
Old Reports
The most recent abuse report for this IP address is from
3 weeks ago . It is possible that this IP is no
longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐ฎ๐ฉ
RemyLebeau
2026-09-03 07:50:45
(3 weeks ago)
Web App Attack
Port Scan
๐บ๐ธ
kosada.com
2026-07-28 15:17:17
(1 month ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐บ๐ธ
kosada.com
2026-07-16 14:04:00
(2 months ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐บ๐ธ
kosada.com
2026-07-06 19:24:22
(2 months ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐ฎ๐ณ
Genhost
2026-05-15 23:21:24
(4 months ago)
SCANNING OF PHP SHELL FILES
Brute-Force
SSH
๐ง๐ท
hostseries
2026-02-03 11:29:52
(7 months ago)
Trigger: LF_DISTATTACK
Brute-Force
๐ฎ๐ฉ
sockominfo
2025-12-09 21:00:52
(9 months ago)
User login attempt during non-business hours.. Threat Score: 5.9/10 (MEDIUM). Reported by TangerangK ...
show more
User login attempt during non-business hours.. Threat Score: 5.9/10 (MEDIUM). Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2025-12-09 13:51:15
(9 months ago)
[WAZUH] User login attempt during non-business hours.
Hacking
Web App Attack
๐ฎ๐น
VHosting
2025-12-04 05:28:10
(9 months ago)
Detected mail brute force attack from 4 different servers
Brute-Force
๐ฎ๐ฉ
hermawan
2025-11-27 05:36:15
(9 months ago)
[Thu Nov 27 09:07:23.270123 2025] [security2:error] [pid 444937:tid 139899885835968] [client 104.28. ...
show more
[Thu Nov 27 09:07:23.270123 2025] [security2:error] [pid 444937:tid 139899885835968] [client 104.28.236.165:16328] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "public" at REQUEST_FILENAME. [file "/etc/modsecurity/coreruleset-4.20.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "88"] [id "448101"] [msg "BAD REQUEST FILENAME - Detected and Blocked"] [data "Matched Data: public found within REQUEST_FILENAME: /public/javascript/filemanager/dialog.php request_line = GET /public/javascript/filemanager/dialog.php HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/public/javascript/filemanager/dialog.php"] [unique_id "aSeyWzJIlV9BnAz-czSIowAAA4s"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[444975] [ayI/+QnZPUo] [aSeyWzJIlV9BnAz-czSIowAAA4s] keep_alive=[0] [2025-11-27 09:07:23.270127] [R:aSeyWzJIlV9BnAz-czSIowAAA4s] UA:'Go-http-client/1.1' Host:'staklim-jatim.bmkg.go.id' Accept-Encoding:'gzip
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2025-11-26 19:31:08
(9 months ago)
TinyMCE Scan Activities
Web App Attack
๐ฎ๐ฉ
sockominfo
2025-11-21 14:30:39
(10 months ago)
[WAZUH] User login attempt during non-business hours.
Hacking
Web App Attack
Anonymous
2025-11-17 14:17:32
(10 months ago)
scanning http requests from known botnet
Web App Attack
๐ฎ๐ฉ
hermawan
2025-11-17 10:28:15
(10 months ago)
[Mon Nov 17 17:27:29.056223 2025] [security2:error] [pid 890734:tid 140543991367360] [client 104.28. ...
show more
[Mon Nov 17 17:27:29.056223 2025] [security2:error] [pid 890734:tid 140543991367360] [client 104.28.236.165:25045] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/wp" at REQUEST_FILENAME. [file "/etc/modsecurity/coreruleset-4.20.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "83"] [id "448101"] [msg "BAD REQUEST FILENAME - Detected and Blocked"] [data "Matched Data: /wp found within REQUEST_FILENAME: /wp-login.php request_line = GET /wp-login.php HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/wp-login.php"] [unique_id "aRr4kaF1Stu4GEf57eV3DgAAAwA"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[890761] [p8BRywfczBU] [aRr4kaF1Stu4GEf57eV3DgAAAwA] keep_alive=[0] [2025-11-17 17:27:29.056226] [R:aRr4kaF1Stu4GEf57eV3DgAAAwA] UA:'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36' Host:'staklim-jatim.bmkg.go.id' COOKIE:'fb66df88cff4414b0afe6309464db212=cvhr3gco06l
...
show less
Hacking
Web App Attack
๐ซ๐ท
dynamix
2025-11-15 02:52:28
(10 months ago)
Multiple WAF Violations
Web App Attack
Showing 1 to
15
of 75 reports