HoneyLabs
iAnonymous lookups: 10/min, 60/hr per source IP. Sign in (free) to lift the limit, run heavier queries, and get an API key for MCP / HTTP.

Filtered actors

query: asn:137718

81 unique IPs · 2.1K events · 1 countries · 1 ASNs

Activity · last 30d

2026-05-14: 4 events2026-05-15: 51 events2026-05-16: 10 events2026-05-17: 484 events2026-05-18: 19 events2026-05-19: 4 events2026-05-20: 235 events2026-05-21: 4 events2026-05-22: 13 events2026-05-24: 154 events2026-05-25: 52 events2026-05-26: 2 events2026-05-27: 57 events2026-05-28: 100 events2026-05-29: 54 events2026-05-30: 213 events2026-05-31: 149 events2026-06-01: 228 events2026-06-02: 24 events2026-06-03: 10 events2026-06-04: 33 events2026-06-05: 56 events2026-06-06: 15 events2026-06-07: 19 events2026-06-08: 9 events2026-06-09: 3 events2026-06-10: 1 events2026-06-11: 14 events2026-06-12: 2 events2026-06-13: 51 events

peak 484 on 2026-05-17

Top source networks · click to refine

Refine
Turn this query into a daily email digest or an IOC feed URL.Save as feed

Sample payloads

top distinct probes matching this query
ProtocolPortProbe / payloadHitsExample
SSH22/SSHSSH-2.0-Go519 · 9 IPs115.190.138.108 →
HTTP3389/RDPGET /61 · 3 IPs101.126.4.215 →
HTTP8188GET /system_stats44 · 8 IPs115.190.85.1 →
HTTP443/HTTPSGET /containers/json
UA: libredtail-http
29 · 10 IPs115.191.34.88 →
Redis6379/Redis*1 $4 info25 · 7 IPs115.190.97.5 →
HTTP80/HTTPPOST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh
UA: libredtail-http
20 · 8 IPs101.126.86.90 →
HTTP80/HTTPPOST /cgi-bin/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/bin/sh
UA: libredtail-http
20 · 8 IPs101.126.86.90 →
HTTP443/HTTPSPOST /hello.world?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input
UA: libredtail-http
18 · 8 IPs115.191.34.88 →
HTTP80/HTTPPOST /?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input
UA: libredtail-http
16 · 7 IPs118.145.245.82 →
HTTP80/HTTPGET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
UA: libredtail-http
16 · 7 IPs118.145.245.82 →
HTTP443/HTTPSGET /vendor/phpunit/phpunit/LICENSE/eval-stdin.php
UA: libredtail-http
15 · 7 IPs115.191.34.88 →
HTTP443/HTTPSGET /www/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
UA: libredtail-http
15 · 7 IPs115.191.34.88 →
IPCountryASNTop portsEvents
Showing top 50 by event count. Window is the last 30d. Add or remove filters by clicking any value on a per-IP report.