Check an IP Address, Domain Name, Subnet, or ASN
211.149.218.225 has a threat confidence score of 98%. This IP address from China (AS38283, CHINANET SiChuan Telecom Internet Data Center) has been observed in 64 honeypot sessions targeting FTP protocols. Detected attack patterns include ftp valid account photo scr deployment. First observed on February 18, 2026, most recently active February 18, 2026.
Detects an automated FTP session performing credential probing, directory discovery, ASCII mode configuration, passive transfer negotiation, and staged upload of a photo_scr payload. This pattern is consistent with scripted web shell or content-stager deployment via compromised FTP credentials.
FTP session where the client uploads files named Photo.scr and Photo.lnk using STOR after entering passive mode.