Looking up IP
Check an IP Address, Domain Name, Subnet, or ASN
20.121.194.192 has a threat confidence score of 94%. This IP address from United States (AS8075, Microsoft Corporation) has been observed in 70 honeypot sessions targeting SSH, TELNET, HTTP, HTTPS protocols. First observed on March 26, 2026, most recently active April 17, 2026.
Identifies the use of SCP in quiet mode (-q) with “to” mode (-t), indicating the remote system is receiving a file. This pattern is commonly associated with post-authentication payload delivery, lateral movement staging, or tool transfer to a compromised host.