Check an IP Address, Domain Name, Subnet, or ASN
14.103.149.244 has a threat confidence score of 88%. This IP address from China (AS4811, China Telecom Group) has been observed in 338 honeypot sessions and reported 1 times targeting SSH protocols. First observed on January 21, 2026, most recently active April 2, 2026.
Identifies the use of SCP in quiet mode (-q) with “to” mode (-t), indicating the remote system is receiving a file. This pattern is commonly associated with post-authentication payload delivery, lateral movement staging, or tool transfer to a compromised host.
Identifies SSH sessions where the actor executes uname -s -v -n -r -m to retrieve detailed kernel, hostname, architecture, and OS version information for environment profiling and post-access decision making.
| Reporter | Date | Category | Protocol | Comment |
|---|---|---|---|---|
| User | Mar 24, 2026, 06:22 | Brute Force | SSH | Fail2Ban Report - Bruteforce attempt |