Check an IP Address, Domain Name, Subnet, or ASN
103.253.27.211 has a threat confidence score of 98%. This IP address from Singapore (AS133210, EN Technologies Pte Ltd) has been observed in 87 honeypot sessions targeting SSH, HTTPS, HTTP, FTP protocols. Detected attack patterns include ssh shell history tampering via environment reload. First observed on March 23, 2026, most recently active April 14, 2026.
Identifies an SSH session where the actor manipulates shell environment variables (such as HISTFILE, HISTSIZE, HISTCONTROL, or related variables) and reloads or reinitializes shell history in order to suppress, overwrite, or control command logging. The combination of explicitly setting environment variables and triggering a history reload indicates deliberate command history tampering rather than normal shell usage.
Identifies HTTP requests targeting the web server root path ("/"), typically used for initial service discovery, host validation, or baseline content inspection prior to deeper enumeration.