Check an IP Address, Domain Name, Subnet, or ASN
45.230.66.116 has a threat confidence score of 72%. This IP address from Argentina (AS266702, MEGALINK S.R.L.) has been observed in 5 honeypot sessions targeting HTTP protocols. Detected attack patterns include http gpon mozi botnet rce chain, http boaform admin formlogin auth attempt. First observed on March 18, 2026, most recently active April 13, 2026.
Observed exploitation chain targeting /GponForm/diag_Form diagnostic endpoint, abusing diag_action=ping for command injection to download Mozi.m malware via wget, accompanied by images/ query artifact. Indicative of automated GPON router exploitation for Mozi botnet deployment.
HTTP GET request to /boaform/admin/formLogin with username and psd parameters, indicating an authentication attempt against a Boa-based router or embedded device administrative login endpoint.