Check an IP Address, Domain Name, Subnet, or ASN
37.148.212.108 has a threat confidence score of 96%. This IP address from Türkiye (AS34619, Cizgi Telekomunikasyon Anonim Sirketi) has been observed in 15 honeypot sessions targeting REDIS protocols. Detected attack patterns include redis cron persistence multi variant payload. First observed on February 27, 2026, most recently active March 1, 2026.
Detects Redis configuration abuse where an exposed instance is reconfigured to write cron entries that execute remote payloads via curl or wget/variant binaries (including root-executed variants), followed by SAVE to persist the malicious cron file to disk. Covers multiple backup job names and pipe-to-shell download techniques used for automated persistence and recurring remote code execution.