Check an IP Address, Domain Name, Subnet, or ASN
13.89.124.208 has a threat confidence score of 91%. This IP address from United States (AS8075, Microsoft Corporation) has been observed in 101 honeypot sessions and reported 1 times targeting HTTPS, SSH, TELNET, HTTP, IMAP and 10 other protocols. Detected attack patterns include https autodiscover powershell probe. First observed on January 23, 2026, most recently active April 12, 2026.
HTTPS request to /autodiscover/autodiscover.json with a query string containing @zdi/Powershell.
SIP activity where the Call-ID follows a token@IP format, a pattern commonly generated by automated scanners and SIP tooling rather than standard client implementations, indicating non-human or enumeration-driven behavior.
HTTPS request to /developmentserver/metadatauploader.
Identifies HTTP requests targeting the web server root path ("/"), typically used for initial service discovery, host validation, or baseline content inspection prior to deeper enumeration.
| Reporter | Date | Category | Protocol | Comment |
|---|---|---|---|---|
| User | Mar 20, 2026, 02:08 | Brute Force | TELNET | SikkerGuard: 2 blocked packets |