HoneyLabs
iAnonymous lookups: 10/min, 60/hr per source IP. Sign in (free) to lift the limit, run heavier queries, and get an API key for MCP / HTTP.

Filtered actors

query: asn:9808

96 unique IPs · 1.1K events · 1 countries · 1 ASNs

Activity · last 7d

2026-06-14: 46 events2026-06-15: 241 events2026-06-16: 156 events2026-06-17: 138 events2026-06-18: 145 events2026-06-19: 108 events2026-06-20: 130 events2026-06-21: 107 events

peak 241 on 2026-06-15

Top source networks · click to refine

Refine
Turn this query into a daily email digest or an IOC feed URL.Save as feed

Sample payloads

top distinct probes matching this query
ProtocolPortProbe / payloadHitsExample
HTTP88GET /461 · 45 IPs218.203.113.130 →
HTTP30083GET /favicon.ico
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36
332 · 38 IPs111.7.96.153 →
HTTP80/HTTPPOST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh
UA: libredtail-http
9 · 7 IPs112.18.182.202 →
HTTP2375/DockerGET /containers/json
UA: libredtail-http
9 · 6 IPs223.85.102.138 →
HTTP80/HTTPPOST /cgi-bin/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/bin/sh
UA: libredtail-http
8 · 7 IPs112.18.182.202 →
HTTP80/HTTPPOST /hello.world?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input
UA: libredtail-http
8 · 7 IPs112.18.182.202 →
HTTP80/HTTPPOST /?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input
UA: libredtail-http
8 · 7 IPs112.18.182.202 →
SSH2222/SSHSSH-2.0-libssh2_1.11.18 · 7 IPs117.175.140.79 →
HTTP80/HTTPGET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
UA: libredtail-http
7 · 6 IPs112.18.182.202 →
-1433/MSSQL)�U�-6112.44.220.17 →
HTTP80/HTTPGET /vendor/phpunit/src/Util/PHP/eval-stdin.php
UA: libredtail-http
5 · 5 IPs112.18.182.202 →
HTTP80/HTTPGET /phpunit/src/Util/PHP/eval-stdin.php
UA: libredtail-http
5 · 5 IPs112.18.182.202 →
IPCountryASNTop portsEvents
Showing top 50 by event count. Window is the last 7d. Add or remove filters by clicking any value on a per-IP report.