Check an IP Address, Domain Name, Subnet, or ASN
118.26.104.19 has a threat confidence score of 90%. This IP address from United Kingdom (AS135377, UCLOUD INFORMATION TECHNOLOGY HK LIMITED) has been observed in 318 honeypot sessions targeting FTP, SIP, SMTP, HTTP, TELNET and 6 other protocols. First observed on February 3, 2026, most recently active April 19, 2026.
FTP session where an empty control-channel command is observed in conjunction with non-printable binary data on the control channel. This pattern reflects malformed or non-FTP-compliant input, commonly seen during TLS handshake attempts on plaintext endpoints, protocol confusion, or automated scanner misfires.
Identifies HTTP requests targeting the web server root path ("/"), typically used for initial service discovery, host validation, or baseline content inspection prior to deeper enumeration.
HTTP request using GET method.
HTTP GET request to /robots.txt.
FTP session where the client issues AUTH TLS to upgrade the connection to Transport Layer Security. This reflects protocol-level encryption negotiation prior to further interaction.
HTTPS request to /robots.txt.