Check an IP Address, Domain Name, Subnet, or ASN
209.38.18.110 has a threat confidence score of 79%. This IP address from Australia (AS14061, DigitalOcean, LLC) has been observed in 7 honeypot sessions targeting SSH protocols. First observed on February 17, 2026, most recently active February 17, 2026.
Comprehensive post-access host reconnaissance over SSH focused on system fingerprinting and GPU capability validation. The activity enumerates OS and kernel details, CPU model and core count, uptime, interactive users, routing information, and performs conditional GPU detection via lspci or nvidia-smi. It also validates binary availability (e.g., kill) and performs external IP organization lookups. This pattern is consistent with operators assessing compute capacity (including GPU suitability), system stability, and execution environment before payload deployment such as cryptomining, AI workload abuse, or resource-intensive tooling.