This IP address has been reported a total of
6
times from
5 distinct
sources.
148.113.246.168 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
United States of America
with 3
reports;
France
with 2
reports;
Korea (the Republic of)
with 1
report.
The most common categories in these recent reports were:
Brute-Force
4
times;
Hacking
3
times;
SSH
3
times;
Exploited Host
2
times;
Port Scan
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
SSH honeypot: automated intrusion attempts against a personal decoy server (Server Guardian Warboard ...
show moreSSH honeypot: automated intrusion attempts against a personal decoy server (Server Guardian Warboard). Read-only capture.
show less
Attempted SSH login with hadoop/_i!vJ3=t#d2Tc+T, then ran recon and persistence setup. Commands chec ...
show moreAttempted SSH login with hadoop/_i!vJ3=t#d2Tc+T, then ran recon and persistence setup. Commands checked system info and CPU count (uname -a, /proc/cpuinfo, ps -eo pid,pcpu,comm --sort=-pcpu | head), searched writable locations, and changed into /tmp. The attacker dropped w.sh (script, 1.4 KB, sha256:bc36e729c6463e7120677c0d59b9d793401b320520201043048577d4d94cee28), made it executable, and wrote a crontab @reboot entry to execute /tmp/w.sh with arguments "astats" "netai" "kstats" "ssh 2 az". They also created ~/.config/systemd/user/watcher-netai.service and used systemctl --user daemon-reload plus enable --now to start a user service for persistence. No downloads, lateral movement, or additional payloads were observed.
show less
Observed 2 SSH sessions over SSH-2.0-Go using credential hadoop/_i!vJ3=t#d2Tc+T. Attacker ran basic ...
show moreObserved 2 SSH sessions over SSH-2.0-Go using credential hadoop/_i!vJ3=t#d2Tc+T. Attacker ran basic host recon (uname -a, CPU core count, ps -eo pid,pcpu,comm --sort=-pcpu | head -n 10) and searched for a writable directory by cycling through /dev/shm, /tmp, /var/run, /mnt, /root, /. In /tmp, they prepared w.sh with chmod +x, checked crontab, and attempted persistence via an @reboot cron entry referencing /tmp/w.sh and strings "astats" "netai" "kstats" "ssh 2 az". They also attempted user-level systemd persistence by creating ~/.config/systemd/user/watcher-netai.service, then running systemctl --user daemon-reload and enable --now. No downloads, lateral movement, or dropped file artifacts were observed.
show less
[2026-09-29 11:10:22] Attempted port scan on port 2222 by IP 148.113.246.168 (Reported by SysWarden ...
show more[2026-09-29 11:10:22] Attempted port scan on port 2222 by IP 148.113.246.168 (Reported by SysWarden https://github.com/duggytuxy/syswarden)
show less
Port Scan
Showing 1 to
6
of 6 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ