This IP address has been reported a total of
43
times from
34 distinct
sources.
177.4.12.11 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Germany
with 12
reports;
United States of America
with 6
reports;
Argentina
with 3
reports.
The most common categories in these recent reports were:
Web App Attack
22
times;
Port Scan
11
times;
Brute-Force
10
times;
Hacking
9
times;
Exploited Host
6
times;
Other
4
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[Honeypot Report] Vulnerability exploitation attempt via FTP and Telnet
An automated exploitation t ...
show more[Honeypot Report] Vulnerability exploitation attempt via FTP and Telnet
An automated exploitation tool attempted to exploit CVE-2015-3306, then attempted to log in to our emulated FTP and Telnet services, and finally obtained shell access and executed commands.
Observed: 2026-09-16 05:16 to 2026-10-09 11:22 UTC | 6 sessions | 18 events | FTP/Telnet (port 21, 23)
Attack chain:
1. Exploit attempt: CVE-2015-3306
2. 1 credential attempt: root/id;hostname;uname -a
3. Shell access obtained; 2 distinct commands executed: SITE CPFR /etc/passwd ; SITE CPTO /tmp/.nz6ac8ce81
Signatures: ProFTPD mod_copy File Write
Full evidence: https://github.com/1Birdo/lyrebird-intel/blob/main/incidents/2026/10/177.4.12.11.md
Reported by birdo.uk (Lyrebird honeypot lyrebird-01). Emulated service - no host was compromised.
show less
[news.tmg.gr] httpd-suspicious-path: sites=www.news.tmg.gr; logs=/var/log/httpd/domains/news.tmg.gr. ...
show more[news.tmg.gr] httpd-suspicious-path: sites=www.news.tmg.gr; logs=/var/log/httpd/domains/news.tmg.gr.log; samples=/wp-content/plugins/acymailing/readme.txt
show less
Wazuh rule 31198: Web Attack is Multiple web server 400 error code detected trigger Active Re ...
show moreWazuh rule 31198: Web Attack is Multiple web server 400 error code detected trigger Active Response.
show less
COMODO WAF: Remote File Access Attempt. Match of "contains cpanel" against "REQUEST_URI" required. ( ...
show moreCOMODO WAF: Remote File Access Attempt. Match of "contains cpanel" against "REQUEST_URI" required. (211190-145)
show less
Honeypot detection: port scan / service probe. 2 events observed. Reported automatically from a hone ...
show moreHoneypot detection: port scan / service probe. 2 events observed. Reported automatically from a honeypot sensor.
show less