Looking up IP
Check an IP Address, Domain Name, Subnet, or ASN
176.65.132.24 has a threat confidence score of 99%. This IP address from Germany (AS51396, Pfcloud UG (haftungsbeschrankt)) has been observed in 249 honeypot sessions and reported 1 times targeting SSH protocols. First observed on April 27, 2026, most recently active April 30, 2026.
Identifies the use of SCP in quiet mode (-q) with “to” mode (-t), indicating the remote system is receiving a file. This pattern is commonly associated with post-authentication payload delivery, lateral movement staging, or tool transfer to a compromised host.
| Reporter | Date | Category | Protocol | Comment |
|---|---|---|---|---|
| Anonymous | Apr 29, 2026, 24:30 | Brute Force | SSH | SikkerGuard: 2 blocked packets |