Looking up IP
Check an IP Address, Domain Name, Subnet, or ASN
109.165.166.25 has a threat confidence score of 82%. This IP address from Bosnia and Herzegovina (AS25144, Telekomunikacije Republike Srpske akcionarsko drustvo Banja Luka) has been observed in 8 honeypot sessions targeting SMB protocols. Detected attack patterns include remcom remote execution. First observed on March 17, 2026, most recently active March 17, 2026.
Sequential SMB session opening IPC$, accessing the svcctl pipe, issuing an RPC call, then opening the RemCom_communicaton pipe. Indicates remote service-based command execution.