Check an IP Address, Domain Name, Subnet, or ASN
117.72.108.18 has a threat confidence score of 90%. This IP address from China (AS141679, China Telecom Beijing Tianjin Hebei Big Data Industry Park Branch) has been observed in 107 honeypot sessions targeting SSH protocols. First observed on April 20, 2026, most recently active April 21, 2026.
Identifies the use of SCP in quiet mode (-q) with “to” mode (-t), indicating the remote system is receiving a file. This pattern is commonly associated with post-authentication payload delivery, lateral movement staging, or tool transfer to a compromised host.
Identifies SSH sessions where the actor executes uname -s -v -n -r -m to retrieve detailed kernel, hostname, architecture, and OS version information for environment profiling and post-access decision making.