Check an IP Address, Domain Name, Subnet, or ASN
130.211.93.147 has a threat confidence score of 73%. This IP address from Belgium (AS396982, Google LLC) has been observed in 6 honeypot sessions targeting HTTPS, POSTGRES, SMB, HTTP protocols. First observed on March 23, 2026, most recently active March 23, 2026.
Composite behavior identifying authenticated SMB interaction where a client accesses the IPC$ share, performs root directory reads, binds to the SAMR RPC interface, and interacts with the SRVSVC service pipe. This sequence is consistent with remote host and account enumeration activity over SMB, typically used to gather domain, user, and share information prior to lateral movement or privilege escalation attempts.
Identifies HTTP requests targeting the web server root path ("/"), typically used for initial service discovery, host validation, or baseline content inspection prior to deeper enumeration.
Identifies HTTPS requests targeting the web server root path ("/"), typically used for initial service discovery, host validation, or baseline content inspection prior to deeper enumeration