User sergio.faraldo joined AbuseIPDB in April 2022 and has reported 38 IP addresses.

Standing (weight) is good.

INACTIVE USER
IP Date Comment Categories
๐Ÿ‡ณ๐Ÿ‡ฑ 159.223.13.188
Hosts file used in attempted GPON RCE attack, URL: http://159.223.13.188/bin
Hacking
๐Ÿ‡ฑ๐Ÿ‡น 141.98.10.141
Attempted Log4j RCE attack
Hacking
๐Ÿ‡บ๐Ÿ‡ธ 209.141.62.68
Hosts malware used in GPON router hacking attempt: http://209.141.62.68/bin
Hacking
๐Ÿ‡บ๐Ÿ‡ธ 172.245.6.139
Hosts malware used in GPON router attack attempt: http://172.245.6.139/bins/Rakitin.sh
Hacking
๐Ÿ‡บ๐Ÿ‡ธ 198.98.57.120
IP hosts malware used in gpon router attack attempt: http://198.98.57.120/colddbvkcvajf34
Hacking
๐Ÿ‡บ๐Ÿ‡ธ 209.141.60.229
Hacking
๐Ÿ‡บ๐Ÿ‡ธ 134.195.138.33
hosts malware in http://134.195.138.33/.nCKx/zx.mips
Hacking
๐Ÿ‡ฉ๐Ÿ‡ช 91.218.67.131
hosts malware in http://91.218.67.131/reaper/reap.mpsl
Hacking
๐Ÿ‡จ๐Ÿ‡ณ 111.43.114.94
Hacking
๐Ÿ‡จ๐Ÿ‡ณ 111.43.114.69
Hacking
๐Ÿ‡จ๐Ÿ‡ณ 111.43.114.49
Hacking
๐Ÿ‡ญ๐Ÿ‡ฐ 20.24.74.36
IP serves malware on URL http://networkmapping.xyz/bin
Hacking
๐Ÿ‡ณ๐Ÿ‡ฑ 195.133.18.183
Hosts malware in port 80 195.133.18.183/Gpon.sh
Hacking
๐Ÿ‡จ๐Ÿ‡ญ 179.43.149.130
Hosting malware in port 80, used in attack atempts against GPON Routers. Uses the URL "tigoinari.tk"
Hacking
๐Ÿ‡บ๐Ÿ‡ธ 150.136.111.68
Malicious LDAP server used in Log4j attacks
Hacking
๐Ÿ‡ญ๐Ÿ‡ฐ 156.234.211.155
Serves malware, under URL jx.qingdaosheng.com, port 80.
Hacking
๐Ÿ‡ณ๐Ÿ‡ฑ 2.56.57.238
Stores malicious scripts (at port 80). Possible C2 server.
Hacking
๐Ÿ‡จ๐Ÿ‡ณ 42.51.55.69
GPON Remote Code Execution attempt. Payload is served from jx.qingdaosheng.com
Hacking Web App Attack
๐Ÿ‡บ๐Ÿ‡ธ 23.95.0.211
GPON Router remote code execution attempt. Payload served from payload.krakenbit.net
Hacking Web App Attack
๐Ÿ‡ฎ๐Ÿ‡ณ 223.130.31.79
Netgear DGN1000 series routers auth. bypass/remote code execution attempt.
Hacking Web App Attack
๐Ÿ‡ญ๐Ÿ‡ฐ 203.86.235.141
PHPUnit PHP remote code execution attempt
Hacking Web App Attack
๐Ÿ‡บ๐Ÿ‡ธ 23.94.50.159
Hosts malware in port 80
Hacking
๐Ÿ‡ช๐Ÿ‡ฌ 197.33.89.132
GPON Router remote code execution attempt. Payload served by 23.94.50.159, port 80
Hacking Web App Attack
๐Ÿ‡ญ๐Ÿ‡ฐ 154.204.26.87
GPON Router remote code execution attack. Payload is served by 91.122.37.169, port 80
Hacking Web App Attack
๐Ÿ‡ฏ๐Ÿ‡ต 123.198.243.230
GPON Router remote code execution attempt. Payload would be downloaded from port 80, IP 185.44.81.9
Hacking Web App Attack