Check an IP Address, Domain Name, Subnet, or ASN
157.245.197.167 has a threat confidence score of 82%. This IP address from Singapore (AS14061, DigitalOcean, LLC) has been observed in 51 honeypot sessions targeting RDP, SSH protocols. Detected attack patterns include ssh hardened host profiling and shell rc immutability bypass. First observed on March 1, 2026, most recently active April 8, 2026.
Identifies SSH post-auth activity combining resilient multi-source CPU enumeration (explicit /usr/bin/nproc fallback) with removal of the immutable flag from ~/.shellrc via chattr, indicating host profiling followed by shell configuration tampering for persistence preparation.
Identifies RDP clients attempting authentication using Network Level Authentication (NLA) with the NTLM challenge-response protocol. This occurs during the CredSSP negotiation phase before a remote desktop session is established and indicates an active credential authentication attempt against the RDP service