AbuseIPDB » 172.68.111.28
172.68.111.28 was found in our database!
This IP was reported 7 times. Confidence of
Abuse
is 0% : ?
ISP
Cloudflare, Inc.
Usage Type
Data Center/Web Hosting/Transit
ASN
AS13335
Domain Name
cloudflare.com
Country
π©πͺ
Germany
City
Munich, Bavaria
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
Important Note: 172.68.111.28 is an IP address from within
our whitelist belonging to the subnet
172.64.0.0/13 ,
which we identify as: "Cloudflare Reverse Proxy" .
Whitelisted netblocks are typically owned by trusted entities, such as Google
or Microsoft who may use them for search engine spiders. However, these same entities
sometimes also provide cloud servers and mail services which are easily abused. Pay special
attention when trusting or distrusting these IPs.
IP Abuse Reports for 172.68.111.28 :
This IP address has been reported a total of
7
times from
6 distinct
sources.
172.68.111.28 was first reported on
October 25th 2024 , and the most recent report was
1 day ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
π§πͺ
madeit
2026-09-14 19:48:09
(1 day ago)
Web App Attack
π«π·
domainemporium
2026-01-21 14:58:36
(7 months ago)
(plesk-panel) Failed plesk-panel login with username [redacted] from 172.68.111.28 (DE/Germany/-): ...
show more
(plesk-panel) Failed plesk-panel login with username [redacted] from 172.68.111.28 (DE/Germany/-): (CF_ENABLE)
show less
Brute-Force
πͺπΈ
robotstxt
2025-05-23 16:14:05
(1 year ago)
172.68.111.28 - - [23/May/2025:16:13:14 +0000] "GET /phpmyadmin2021/?lang=en HTTP/2.0" 404 17138 "ht ...
show more
172.68.111.28 - - [23/May/2025:16:13:14 +0000] "GET /phpmyadmin2021/?lang=en HTTP/2.0" 404 17138 "https://ccoo.app/phpmyadmin2021/index.php?lang=en" rt="0.435" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36" "2a02:3100:af26:8d00:e766:7326:5f22:9cd8" h="ccoo.app" sn="ccoo.app" ru="/phpmyadmin2021/?lang=en" u="/index.php" ucs="-" ua="unix:/var/run/php/ccooapp82.sock" us="404" uct="0.000" urt="0.435"
172.68.111.28 - - [23/May/2025:16:13:18 +0000] "GET /phpMyAdmin6.0/?lang=en HTTP/2.0" 404 17138 "https://ccoo.app/phpMyAdmin6.0/index.php?lang=en" rt="0.380" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36" "2a02:3100:af26:8d00:e766:7326:5f22:9cd8" h="ccoo.app" sn="ccoo.app" ru="/phpMyAdmin6.0/?lang=en" u="/index.php" ucs="-" ua="unix:/var/run/php/ccooapp82.sock" us="404" uct="0.000" urt="0.380"
172.68.111.28 - - [23/May/2025:16:13:29 +0000] "GET /phpMyAdmin-5.1.2
...
show less
Bad Web Bot
Anonymous
2025-04-26 09:51:31
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2024-11-29 03:40:02
(1 year ago)
| CMS (WordPress or Joomla) brute force attempt 10 times (rewritten)
Hacking
SQL Injection
Web App Attack
πΊπΈ
TPI-Abuse
2024-11-18 17:10:18
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 172.68.111.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.111.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 18 12:10:10.936794 2024] [security2:error] [pid 10631:tid 10631] [client 172.68.111.28:40382] [client 172.68.111.28] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.pixacast.com"] [uri "/.git/config"] [unique_id "Zzt08gyVPh29AfGLOqmIwQAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-10-25 00:06:08
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 172.68.111.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 172.68.111.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 24 20:06:01.993070 2024] [security2:error] [pid 13543:tid 13543] [client 172.68.111.28:53072] [client 172.68.111.28] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.upskirtcrazy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.upskirtcrazy.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "Zxrg6VxkT952Hh9E3DuDiwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Showing 1 to
7
of 7 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown π©
Recently Reported IPs: