Check an IP Address, Domain Name, Subnet, or ASN
165.227.81.6 has a threat confidence score of 64%. This IP address from United States (AS14061, DigitalOcean, LLC) has been observed in 57 honeypot sessions targeting MSSQL, HTTPS, SIP, RDP, HTTP and 2 other protocols. First observed on March 1, 2026, most recently active April 2, 2026.
Identifies RDP clients attempting authentication using Network Level Authentication (NLA) with the NTLM challenge-response protocol. This occurs during the CredSSP negotiation phase before a remote desktop session is established and indicates an active credential authentication attempt against the RDP service
Identifies direct HTTPS requests to the /bad-request path, indicating manual or automated probing of error-handling routes rather than normal application flow.