Check an IP Address, Domain Name, Subnet, or ASN
103.103.23.241 has a threat confidence score of 99%. This IP address from Indonesia (AS133800, PT Biznet Gio Nusantara) has been observed in 35 honeypot sessions targeting REDIS protocols. Detected attack patterns include redis cron persistence multi variant payload. First observed on February 26, 2026, most recently active March 1, 2026.
Detects Redis configuration abuse where an exposed instance is reconfigured to write cron entries that execute remote payloads via curl or wget/variant binaries (including root-executed variants), followed by SAVE to persist the malicious cron file to disk. Covers multiple backup job names and pipe-to-shell download techniques used for automated persistence and recurring remote code execution.