Check an IP Address, Domain Name, Subnet, or ASN
152.32.199.73 has a threat confidence score of 79%. This IP address from Brazil (AS135377, UCLOUD INFORMATION TECHNOLOGY HK LIMITED) has been observed in 539 honeypot sessions targeting HTTPS, IMAP, FTP, SMTP, HTTP and 4 other protocols. First observed on January 20, 2026, most recently active March 18, 2026.
FTP session where an empty control-channel command is observed in conjunction with non-printable binary data on the control channel. This pattern reflects malformed or non-FTP-compliant input, commonly seen during TLS handshake attempts on plaintext endpoints, protocol confusion, or automated scanner misfires.
Identifies HTTPS requests targeting the web server root path ("/"), typically used for initial service discovery, host validation, or baseline content inspection prior to deeper enumeration
Identifies HTTP GET requests directly targeting the /bad-request path, indicating automated or manual probing of application error-handling routes rather than legitimate navigation flow.