Cyber Threat Intelligence

Discover malicious IPs and domains with Akamai Guardicore Segmentation

IP Address: 156.96.155.227Previously Malicious

IP Address: 156.96.155.227Previously Malicious

This IP address attempted an attack on a machine in our threat sensors network

Threat Information

Role

Attacker, Connect-Back, Scanner

Services Targeted

MYSQL SMB

Tags

Create Mysql Function MYSQL 38 Sql Commands Malicious Mysql Command

Associated Attack Servers

122-airtelbroadband.in 163data.com.cn 49-tataidc.co.in actcorp.in airtelbroadband.in airtel.in hrcloud.ir jlccptt.net.cn nexlinx.net.pk tedata.net ztomy.com

1.248.75.8 14.157.138.127 14.235.121.80 37.156.28.158 41.38.86.147 42.119.73.192 45.174.32.21 46.99.134.170 46.151.57.35 49.248.169.221 58.56.164.82 58.220.46.131 59.47.231.110 61.138.28.41 61.247.230.145 71.187.180.65 80.85.84.75 85.93.20.170 91.135.200.114 95.132.70.178 103.23.144.53 103.41.110.14 103.104.49.88 103.205.114.35 103.226.239.53 103.227.99.55 105.172.172.83 106.44.155.154 106.201.138.13 111.42.132.72

Basic Information

IP Address

156.96.155.227

Domain

-

ISP

XNS Technology Group

Country

United States

WHOIS

Created Date

-

Updated Date

-

Organization

-

First seen in Akamai Guardicore Segmentation

2021-01-24

Last seen in Akamai Guardicore Segmentation

2023-01-27

What is Akamai Guardicore Segmentation
Akamai Guardicore Segmentation is a data center and cloud security solution that protects the organization's core assets, using flexible, quickly deployed and easy to understand micro-segmentation controls. Akamai Guardicore Segmentation generates in-context security incidents, with details on attacker tools and techniques, that help IR teams prioritize incident investigation and reduce dwell time. Learn More

Attack Flow

An attempt to create MySQL user-defined function (UDF) xpdl3 implemented in /usr/local/mysql/lib/plugin/udf.dll

Create Mysql Function

An attempt to create MySQL user-defined function (UDF) cmdshell implemented in /usr/local/mysql/lib/plugin/xsa.dll

Create Mysql Function

An attempt to create MySQL user-defined function (UDF) downloader implemented in /usr/local/mysql/lib/plugin/xsa.dll

Create Mysql Function

An attempt to create MySQL user-defined function (UDF) cmdshell implemented in /usr/local/mysql/lib/plugin/lib_mysqludf_sys.dll

Create Mysql Function

An attempt to create MySQL user-defined function (UDF) downloader implemented in /usr/local/mysql/lib/plugin/lib_mysqludf_sys.dll

Create Mysql Function

An attempt to create MySQL user-defined function (UDF) cmdshell implemented in /usr/local/mysql/lib/plugin/udf32.dll

Create Mysql Function

An attempt to create MySQL user-defined function (UDF) cmdshell implemented in /usr/local/mysql/lib/plugin/udf33.dll

Create Mysql Function

An attempt to create MySQL user-defined function (UDF) downloader implemented in /usr/local/mysql/lib/plugin/udf32.dll

Create Mysql Function

An attempt to create MySQL user-defined function (UDF) downloader implemented in /usr/local/mysql/lib/plugin/udf33.dll

Create Mysql Function

An attempt to create MySQL user-defined function (UDF) cmdshell implemented in /usr/local/mysql/lib/plugin/xsa.dll

Create Mysql Function

An attempt to create MySQL user-defined function (UDF) downloader implemented in /usr/local/mysql/lib/plugin/xsa.dll

Create Mysql Function

An attempt to create MySQL user-defined function (UDF) cmdshell implemented in /usr/local/mysql/lib/plugin/xijin.dll

Create Mysql Function

An attempt to create MySQL user-defined function (UDF) downloader implemented in /usr/local/mysql/lib/plugin/xijin.dll

Create Mysql Function

An attempt to create MySQL user-defined function (UDF) cmdshell implemented in /usr/local/mysql/lib/plugin/xijin1.dll

Create Mysql Function

An attempt to create MySQL user-defined function (UDF) downloader implemented in /usr/local/mysql/lib/plugin/xijin1.dll

Create Mysql Function

An attempt to create MySQL user-defined function (UDF) shell implemented in /usr/local/mysql/lib/plugin/udf.dll

Create Mysql Function

An attempt to create MySQL user-defined function (UDF) cmdshelv implemented in /usr/local/mysql/lib/plugin/udf.dll

Create Mysql Function

An attempt to create MySQL user-defined function (UDF) cmdshell implemented in /usr/local/mysql/lib/plugin/lib_mysqludf_sys.dll

Create Mysql Function

An attempt to create MySQL user-defined function (UDF) downloader implemented in /usr/local/mysql/lib/plugin/lib_mysqludf_sys.dll

Create Mysql Function

Malicious MySQL commands were executed: DROP FUNCTION

Malicious Mysql Command

Connection was closed due to user inactivity