Check an IP Address, Domain Name, Subnet, or ASN
3.93.40.64 has a threat confidence score of 89%. This IP address from United States (AS14618, Amazon.com, Inc.) has been observed in 16 honeypot sessions targeting SSH, RDP protocols. Detected attack patterns include ssh post auth comprehensive host profiling. First observed on February 21, 2026, most recently active March 29, 2026.
Identifies structured post-authentication SSH activity consistent with automated host qualification and capability assessment. The session performs broad system enumeration including kernel and version queries, CPU and process inspection, network configuration and listening service discovery, service inventory via systemctl, credential file probing (/etc/passwd, /etc/shadow), hostname retrieval (command and file read), root and filesystem inspection, connectivity validation via ping, temporary file creation and cleanup, and command resolution checks to evaluate system suitability for further exploitation or staging.