Check an IP Address, Domain Name, Subnet, or ASN
165.245.168.40 has a threat confidence score of 92%. This IP address from United States (AS14061, DigitalOcean, LLC) has been observed in 9 honeypot sessions targeting SSH protocols. Detected attack patterns include dual source gpu validation with host context. First observed on March 28, 2026, most recently active March 28, 2026.
Combined execution of lspci (VGA and 3D controller extraction and device count) and nvidia-smi -q (product name extraction and non-empty count validation), together with kernel/architecture (uname -s -v -n -r -m) and uptime collection. This pattern reflects cross-validation of GPU presence using both PCI-level and NVIDIA driver-level queries, enriched with host system context.
Identifies SSH sessions where the actor performs structured hardware reconnaissance including CPU core enumeration, GPU detection via nvidia-smi, VGA/3D controller inspection via lspci, system uptime queries, and kernel/architecture fingerprinting to assess computational capabilities of the compromised host.