Check an IP Address, Domain Name, Subnet, or ASN
45.205.1.3 has a threat confidence score of 94%. This IP address from Seychelles (AS328608, Africa-on-Cloud-AS) has been observed in 167 honeypot sessions targeting TELNET, HTTPS protocols. First observed on March 9, 2026, most recently active March 20, 2026.
Telnet-based shell activity where the actor enumerates process execution context via cat /proc/self/cmdline (or equivalent) and performs directory navigation using cd. This pattern reflects post-access discovery behavior, where the session is inspecting runtime parameters and exploring filesystem layout to understand the execution environment before staging or executing additional actions. The combination indicates environmental reconnaissance rather than immediate payload deployment.
Identifies HTTPS requests targeting the web server root path ("/"), typically used for initial service discovery, host validation, or baseline content inspection prior to deeper enumeration