Check an IP Address, Domain Name, Subnet, or ASN
143.110.215.13 has a threat confidence score of 59%. This IP address from Canada (AS14061, DigitalOcean, LLC) has been observed in 6 honeypot sessions targeting RDP, HTTPS protocols. First observed on April 22, 2026, most recently active May 5, 2026.
Identifies RDP clients attempting authentication using Network Level Authentication (NLA) with the NTLM challenge-response protocol. This occurs during the CredSSP negotiation phase before a remote desktop session is established and indicates an active credential authentication attempt against the RDP service
Identifies an HTTPS request targeting the .git/config file within a web-accessible repository directory. Access attempts to /.git/config indicate automated repository exposure scanning intended to retrieve remote origin URLs, repository structure, and potentially credential-bearing configuration data. This is a common reconnaissance technique used to identify misconfigured web servers exposing version control metadata.