Check an IP Address, Domain Name, Subnet, or ASN
45.156.87.99 has a threat confidence score of 97%. This IP address from The Netherlands (AS51396, Pfcloud UG (haftungsbeschrankt)) has been observed in 830 honeypot sessions targeting SSH, TELNET, HTTP, DOCKER protocols. First observed on February 16, 2026, most recently active April 15, 2026.
Identifies the use of SCP in quiet mode (-q) with “to” mode (-t), indicating the remote system is receiving a file. This pattern is commonly associated with post-authentication payload delivery, lateral movement staging, or tool transfer to a compromised host.
Identifies HTTP requests targeting the web server root path ("/"), typically used for initial service discovery, host validation, or baseline content inspection prior to deeper enumeration.