104.28.237.111

Recent Activity This IP has received recent abuse reports, which causes the score to increase.
Abuse confidence score ?
17% Caution
342 reports
189 reporters ยท latest 2 days ago
ISP Cloudflare, Inc.
Usage Type Data Center/Web Hosting/Transit
ASN AS13335
Domain Name cloudflare.com
Country ๐Ÿ‡บ๐Ÿ‡ธ United States of America
City Phoenix, Arizona

ISP, Usage Type, and Location provided by IPInfo. Updated weekly.

Log in to view charts and search reports for this IP. Log In

Reports Activity

Example preview

Report Categories (Last 60 Days)

Example preview

Top Reporter Countries (Last 60 Days)

Example preview
Account required for the enhanced features Log in Sign up

IP Abuse Reports for 104.28.237.111

This IP address has been reported a total of 342 times from 189 distinct sources. 104.28.237.111 was first reported on , and the most recent report was . In the last 60 days, the top reporter locations were: Germany with 1 report; Italy with 1 report; Ukraine with 1 report. The most common categories in these recent reports were: DDoS Attack 1 time; Web Spam 1 time; Web App Attack 1 time; Brute-Force 1 time; Bad Web Bot 1 time.

Reporter IoA Timestamp (UTC) Comment Categories
๐Ÿ‡ฉ๐Ÿ‡ช Packets-Decreaser.NET
Incoming Layer 7 Flood Detected
DDoS Attack Web Spam
๐Ÿ‡ฎ๐Ÿ‡น VHosting
Detected mail brute force attack from different servers
Brute-Force
๐Ÿ‡บ๐Ÿ‡ฆ URAN Publishing Service
[19/Aug/2026:22:40:41 +0300] -- 104.28.237.111 Ban reason: User-Agent curl/
Bad Web Bot Web App Attack
๐Ÿ‡ฉ๐Ÿ‡ช anycast_ac
[DDoS Attacker] This IP was attacking website anycast.ac and sent 480 requests on port 443
DDoS Attack Web App Attack
๐Ÿ‡ง๐Ÿ‡ท ICS Labs
ICS Labs identified 104.28.237.111 as a malicious indicator from threat intelligence.
DDoS Attack Port Scan Hacking Brute-Force Exploited Host
๐Ÿ‡ฎ๐Ÿ‡น VHosting
Detected mail brute force attack from 4 different servers
Brute-Force
๐Ÿ‡จ๐Ÿ‡ณ ้น้น
Port Scan
๐Ÿ‡ซ๐Ÿ‡ฎ danskefilm.dk
IMAP password guessing
Brute-Force
Anonymous
Hacking Web App Attack
Anonymous
Hacking Web App Attack
๐Ÿ‡ท๐Ÿ‡ด Fn4ticHz
DDoS blocked via ZeroGuard.ID
DDoS Attack Exploited Host
๐Ÿ‡ฎ๐Ÿ‡ฉ xveil
Brute-Force
๐Ÿ‡ฎ๐Ÿ‡ณ liveaspankaj
DDoS attack: 340 requests in 5m (GET / or repair.php).
DDoS Attack
๐Ÿ‡ซ๐Ÿ‡ท gooko
SSH brute-force attack detected by fail2ban jail 'sshd'
Brute-Force SSH
๐Ÿ‡ท๐Ÿ‡ด Fn4ticHz
Repeated DDoS targeted -- ZeroGuard X ManagedSRV
DDoS Attack Exploited Host

Showing 1 to 15 of 342 reports

Think this IP has been falsely reported? You may request to have the associated reports reviewed and removed. Request Takedown ๐Ÿšฉ

Recently Reported IPs:

๐Ÿ‡ณ๐Ÿ‡ฑ 109.160.32.36
๐Ÿ‡ซ๐Ÿ‡ฎ 80.223.200.38
๐Ÿ‡บ๐Ÿ‡ธ 72.253.251.3
๐Ÿ‡ฆ๐Ÿ‡บ 206.83.113.171
๐Ÿ‡บ๐Ÿ‡ธ 194.195.210.47
๐Ÿ‡จ๐Ÿ‡ฟ 185.156.174.27
๐Ÿ‡บ๐Ÿ‡ธ 162.158.159.112
๐Ÿ‡บ๐Ÿ‡ธ 162.158.159.111
๐Ÿ‡จ๐Ÿ‡ณ 121.229.13.210
๐Ÿ‡จ๐Ÿ‡ณ 120.48.53.174
๐Ÿ‡จ๐Ÿ‡ณ 116.179.33.14
๐Ÿ‡ป๐Ÿ‡ณ 103.195.236.209
๐Ÿ‡ท๐Ÿ‡ด 92.118.39.50
๐Ÿ‡ท๐Ÿ‡บ 84.201.243.44
๐Ÿ‡ช๐Ÿ‡ธ 83.49.3.138
๐Ÿ‡ธ๐Ÿ‡ฌ 82.102.25.234
๐Ÿ‡บ๐Ÿ‡ธ 44.243.50.136
๐Ÿ‡ธ๐Ÿ‡ฌ 34.21.181.106
๐Ÿ‡ฒ๐Ÿ‡ฆ 2a09:bac5:48ca:2c5a::46b:d
๐Ÿ‡จ๐Ÿ‡ญ 209.99.185.184