Check an IP Address, Domain Name, Subnet, or ASN
195.96.138.88 has a threat confidence score of 80%. This IP address from United Kingdom (AS210924, ssd networks limited) has been observed in 5 honeypot sessions targeting FTP protocols. First observed on April 26, 2026, most recently active April 26, 2026.
FTP session where a client probes for valid usernames, attempts authentication, switches to ASCII mode, and enters passive mode without performing explicit file listing or transfer operations. This reflects a completed login and session setup sequence, often observed during credential validation or preparatory access prior to further activity.
FTP session where a client probes for valid users, attempts authentication, switches to ASCII mode, enters passive mode, and issues an NLST command to retrieve a directory name listing. This sequence reflects authenticated directory enumeration focused on discovering available files or structure without detailed metadata retrieval.