Check an IP Address, Domain Name, Subnet, or ASN
198.44.159.43 has a threat confidence score of 88%. This IP address from United States (AS11878, tzulo, inc.) has been observed in 25 honeypot sessions targeting FTP protocols. First observed on March 17, 2026, most recently active March 18, 2026.
FTP session where a client probes for valid usernames, attempts authentication, switches to ASCII mode, and enters passive mode without performing explicit file listing or transfer operations. This reflects a completed login and session setup sequence, often observed during credential validation or preparatory access prior to further activity.
FTP session where a client probes for valid users, attempts authentication, switches to ASCII mode, enters passive mode, and issues an NLST command to retrieve a directory name listing. This sequence reflects authenticated directory enumeration focused on discovering available files or structure without detailed metadata retrieval.