This IP address has been reported a total of
25
times from
21 distinct
sources.
103.113.18.39 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[rede-arem1] 07/02/2026-05:56:47.289681, 103.113.18.39, Protocol: 6, ET SCAN Suspicious inbound to M ...
show more[rede-arem1] 07/02/2026-05:56:47.289681, 103.113.18.39, Protocol: 6, ET SCAN Suspicious inbound to MSSQL port 1433
show less
[rede-168-134] 07/02/2026-04:43:21.762410, 103.113.18.39, Protocol: 6, ET SCAN Suspicious inbound to ...
show more[rede-168-134] 07/02/2026-04:43:21.762410, 103.113.18.39, Protocol: 6, ET SCAN Suspicious inbound to MSSQL port 1433
show less
Honeypot port triggered: HONEYPOT PORT 1433 touched. Automatic permanent ban. Mercurius-Guide automa ...
show moreHoneypot port triggered: HONEYPOT PORT 1433 touched. Automatic permanent ban. Mercurius-Guide automated detection.
show less
Port Scan
Hacking
Brute-Force
Anonymous
2026-07-01T14:54:37.982105+01:00 vps kernel: [44654217.222627] [PORTSCAN DETECTED] IN=ens3 OUT= MAC= ...
show more2026-07-01T14:54:37.982105+01:00 vps kernel: [44654217.222627] [PORTSCAN DETECTED] IN=ens3 OUT= MAC=fa:16:3e:66:f6:24:02:37:19:0d:c2:f3:08:00 SRC=103.113.18.39 DST=54.37.14.118 LEN=52 TOS=0x00 PREC=0x00 TTL=110 ID=34800 DF PROTO=TCP SPT=11513 DPT=1433 WINDOW=64240 RES=0x00 SYN URGP=0
...
show less
PortSentry honeypot: unsolicited TCP connection to closed decoy port 1433 (MSSQL) on a host running ...
show morePortSentry honeypot: unsolicited TCP connection to closed decoy port 1433 (MSSQL) on a host running no such service. Automated port-scan detection at 2026-07-01T13:09:42Z.
show less
2026-07-01T13:00:45.641104+0000 inbound port scan detected by Suricata. src=103.113.18.39:39014 dst= ...
show more2026-07-01T13:00:45.641104+0000 inbound port scan detected by Suricata. src=103.113.18.39:39014 dst=51.68.231.122:1433 proto=TCP. signature="ET SCAN Suspicious inbound to MSSQL port 1433" category="Potentially Bad Traffic" sid=2010935 reason=scan_signature.
show less
Network port/address scan: probed 1 distinct port(s) across 64 host(s); 100% of connections received ...
show moreNetwork port/address scan: probed 1 distinct port(s) across 64 host(s); 100% of connections received no service (SYN, no reply) -- passive network sensor.
show less
Honeypot [nx-infrastructure]: MSSQL traffic (on 1433) without login credentials
Reported by: Justin ...
show moreHoneypot [nx-infrastructure]: MSSQL traffic (on 1433) without login credentials
Reported by: Justin F.
show less