Check an IP Address, Domain Name, Subnet, or ASN
212.97.2.182 has a threat confidence score of 88%. This IP address from Kyrgyzstan (AS12997, OJSC Kyrgyztelecom) has been observed in 17 honeypot sessions targeting FTP protocols. Detected attack patterns include ftp authenticated upload to reports directory, ftp authenticated upload to scripts directory. First observed on March 17, 2026, most recently active March 17, 2026.
FTP session where a client probes for valid users, attempts authentication, negotiates transfer modes (ASCII/Binary), enumerates the /reports directory, and attempts to upload info.zip in passive mode. This sequence reflects an authenticated file placement attempt following directory discovery, consistent with staged content deployment onto a writable path.
FTP session where a client probes for valid users, attempts authentication, switches transfer modes (ASCII/Binary), enumerates the /scripts directory, and attempts to upload info.zip via STOR in passive mode. This sequence reflects an authenticated file placement attempt following directory discovery, consistent with efforts to deploy content onto a remotely accessible scripts path.