General Information

Submitter Diversity: Low
Risk (0-10)details: 0
IP Address (click for more detail): 45.148.10.230
Hostname: 45.148.10.230
Country:  RO
ASN: 48090
AS Name:  DMZHOST - TECHOFF SRV LIMITED, GB
Network:  45.148.10.0/24 (45.148.10.0-45.148.10.255) 45.148.11.0
Reports:  - none -
Targets:  - none -
First Reported: N/A
Most Recent Report: N/A
Comment: - none -
Abuse Contact for AS48090: [email protected]
Links to articles about the IP from rosti.bin.re
https://blog.xlab.qianxin.com/gayfemboy-en/ (Mirai)
https://blog.xlab.qianxin.com/gayfemboy/ (Mirai)
https://hivepro.com/threat-advisory/gayfemboy-botnet-evolution-of-a-potent-threat/?utm_sr=(direct)&utm_cmd=(none)&utm_ccn=(not set) (Mirai)

Note: We update the data once an hour. To refresh the data, click here. Not all source IPs in our database are "attackers". There are a few common false positives. For example, hosts that participate in P2P networks, mail servers, load balancers and DNS servers are some of the most common issues. For details, click on the number of reports. Clicking on the number of reports may allow you to conclude if a report is a false positive or not. Scroll down for information from other data feeds.

SSH/Telnet Logs

no ssh logs.

Web Honeypot Logs

Date Reports Different URLs Different User Agents
2024-10-14111
2024-10-121011
2024-10-02111
2024-09-2030511
2024-09-19118623
2024-09-183032
2024-09-16111
2024-09-15111
2024-09-13711
2024-09-11211
2024-09-07209221
2024-09-0679721
2024-09-05711
2024-07-29313

For more details about the web honeypot, see the Weblogs Page. Do not use these reports to identify IP addresses as "bad" for now.

External Threat Feeds

This data was retrieved from various external data feeds.

First Seen Last Seen Feed
2024-07-142026-10-01Port 443 Scanner
2024-07-142026-10-01Port 80 Scanner
2024-07-142026-10-01Apache Web Server Scanner
2024-07-122026-10-01Suspect Bots/Infected
2024-07-142026-10-01Bruteforce
2020-06-302026-10-01CI Army List
2024-07-232026-10-01Forum Spammers
2025-01-072026-10-01Rosti
2025-01-092026-10-01Threatview Blocklist
Check Threatstop for more data link arrow