Check an IP Address, Domain Name, Subnet, or ASN
119.73.121.12 has a threat confidence score of 87%. This IP address from Pakistan (AS135407, Trans World Enterprise Services Private Limited) has been observed in 11 honeypot sessions targeting FTP protocols. Detected attack patterns include ftp authenticated upload to pub vendor, ftp authenticated upload to scripts directory. First observed on March 9, 2026, most recently active March 9, 2026.
FTP session where a client probes for valid usernames, attempts authentication, enters passive mode, negotiates transfer modes (ASCII/Binary), enumerates the /pub/vendor directory, and attempts to upload info.zip. This sequence reflects authenticated directory reconnaissance followed by file placement into a publicly accessible path, consistent with staged content deployment.
FTP session where a client probes for valid users, attempts authentication, switches transfer modes (ASCII/Binary), enumerates the /scripts directory, and attempts to upload info.zip via STOR in passive mode. This sequence reflects an authenticated file placement attempt following directory discovery, consistent with efforts to deploy content onto a remotely accessible scripts path.