Check an IP Address, Domain Name, Subnet, or ASN
207.46.224.80 has a very high threat confidence level of 100%, originating from Singapore, Singapore, on the Microsoft Corporation network (8075). It has been observed across 532 sessions targeting SSH, with detected attack patterns including ssh comprehensive host reconnaissance sequence, First observed on February 18, 2026, most recently active March 11, 2026.
Identifies an SSH session performing broad system, network, identity, filesystem, and service enumeration in a single execution sequence. The behavior combines environment fingerprinting (kernel, CPU, uptime), user and credential surface inspection (/etc/passwd, /etc/shadow, history), network topology discovery (interfaces, routes, listening ports), process and service inventory, writable directory validation, and connectivity testing. This pattern reflects automated post-compromise host profiling used by botnets, cryptominers, and lateral-movement frameworks to determine system suitability and operational value.