Check an IP Address, Domain Name, Subnet, or ASN
203.192.241.43 has a threat confidence score of 95%. This IP address from India (AS17665, ONEOTT INTERTAINMENT LIMITED) has been observed in 10 honeypot sessions targeting SMB protocols. Detected attack patterns include smb remcom remote command execution, smb remcom stdout pipe access, remcom remote execution. First observed on March 18, 2026, most recently active March 21, 2026.
Identifies PsExec/RemCom-style remote command execution over SMB, involving IPC$ share access, service control manager pipe interaction (svcctl), and communication via the RemCom named pipe. This behavior reflects authenticated lateral movement and remote process execution through Windows administrative shares.
SMB session accessing a RemCom_stdout* named pipe following IPC$ share access, indicating interaction with a RemCom-style remote command execution channel.
Sequential SMB session opening IPC$, accessing the svcctl pipe, issuing an RPC call, then opening the RemCom_communicaton pipe. Indicates remote service-based command execution.