AbuseIPDB » 189.28.91.128
189.28.91.128 was found in our database!
This IP was reported 9 times. Confidence of
Abuse
is 13% : ?
ISP
Telefonica Celular de Bolivia S.A
Usage Type
Fixed Line ISP
ASN
AS27882
Hostname(s)
LPZ-189-28-91-00128.tigo.bo
Domain Name
tigo.com.bo
Country
๐ง๐ด
Bolivia (Plurinational State of)
City
La Paz, La Paz Department
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 189.28.91.128 :
This IP address has been reported a total of
9
times from
9 distinct
sources.
189.28.91.128 was first reported on
September 10th 2024 , and the most recent report was
2 days ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐ฎ๐น
A000Z
2026-07-21 00:03:18
(2 days ago)
Fail2Ban: 189.28.91.128 was banned for Aggressive Bad Bot detected by Nginx/Fail2Ban. UA: Mozilla/5. ...
show more
Fail2Ban: 189.28.91.128 was banned for Aggressive Bad Bot detected by Nginx/Fail2Ban. UA: Mozilla/5.0 (Linux; Android 5.0; SM-G900P Build/LRX21T) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.9727.1106 Mobile Safari/537.36
show less
Bad Web Bot
๐บ๐ธ
kosada.com
2026-07-06 10:42:37
(2 weeks ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-17 16:41:51
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 189.28.91.128 (LPZ-189-28-91-00128.tigo.bo): 1 ...
show more
(mod_security) mod_security (id:210730) triggered by 189.28.91.128 (LPZ-189-28-91-00128.tigo.bo): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 17 12:41:47.087169 2026] [security2:error] [pid 12941:tid 12941] [client 189.28.91.128:44516] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.et.lobibilisim.com|F|2"] [data ".bat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.et.lobibilisim.com"] [uri "/vendor/bin/jsonlint.bat"] [unique_id "agnvyygplD-b8TYUL8f5-AAAAAc"], referer: https://www.et.lobibilisim.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
vtchost.com
2026-05-04 01:33:05
(2 months ago)
requested honeypot page - ignored robots.txt - scraping botnet or virus
...
Bad Web Bot
Exploited Host
๐ฉ๐ช
SMARTNET
2025-11-30 18:38:00
(7 months ago)
Aisuru(Mirai variant) DDoS
DDoS Attack
Anonymous
2025-11-15 23:39:26
(8 months ago)
scanning http requests from known botnet
Web App Attack
๐ญ๐บ
ksol-hostmaster
2025-10-19 22:04:30
(9 months ago)
Massive botnet baited into scraping tarpit
Bad Web Bot
๐ฌ๐ง
comerford
2024-09-14 20:01:02
(1 year ago)
Sep 14 21:00:59 mail postfix/smtpd[166932]: NOQUEUE: reject: RCPT from unknown[189.28.91.128]: 450 4 ...
show more
Sep 14 21:00:59 mail postfix/smtpd[166932]: NOQUEUE: reject: RCPT from unknown[189.28.91.128]: 450 4.7.1 Client host rejected: cannot find your reverse hostname, [189.28.91.128]; from=<[email protected] > to=<[email protected] > proto=ESMTP helo=<[189.28.91.128]>
Sep 14 21:01:00 mail postfix/smtpd[166932]: NOQUEUE: reject: RCPT from unknown[189.28.91.128]: 450 4.7.1 Client host rejected: cannot find your reverse hostname, [189.28.91.128]; from=<[email protected] > to=<[email protected] > proto=ESMTP helo=<[189.28.91.128]>
Sep 14 21:01:02 mail postfix/smtpd[166932]: NOQUEUE: reject: RCPT from unknown[189.28.91.128]: 450 4.7.1 Client host rejected: cannot find your reverse hostname, [189.28.91.128]; from=<[email protected] > to=<[email protected] > proto=ESMTP helo=<[189.28.91.128]>
...
show less
Phishing
Email Spam
Anonymous
2024-09-10 11:45:10
(1 year ago)
Ports: *; Direction: 0; Trigger: LF_DISTSMTP
Brute-Force
SSH
Showing 1 to
9
of 9 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: