Check an IP Address, Domain Name, Subnet, or ASN
138.68.69.145 has a threat confidence score of 97%. This IP address from Germany (AS14061, DigitalOcean, LLC) has been observed in 293 honeypot sessions targeting SSH, HTTPS, SMB, SIP, SMTP and 1 other protocols. First observed on March 4, 2026, most recently active March 29, 2026.
Identifies the use of SCP in quiet mode (-q) with “to” mode (-t), indicating the remote system is receiving a file. This pattern is commonly associated with post-authentication payload delivery, lateral movement staging, or tool transfer to a compromised host.
Identifies HTTPS requests targeting the web server root path ("/"), typically used for initial service discovery, host validation, or baseline content inspection prior to deeper enumeration