Check an IP Address, Domain Name, Subnet, or ASN
5.180.253.39 has a threat confidence score of 83%. This IP address from Germany (AS44486, SYNLINQ) has been observed in 714 honeypot sessions targeting HTTP, SSH protocols. First observed on February 6, 2026, most recently active March 6, 2026.
Repeated SSH password authentication attempts observed within the same activity window, indicating automated credential guessing against the SSH service. The behavior reflects authentication-based access attempts derived from observed password login events without assuming successful compromise.
Identifies HTTP requests targeting the web server root path ("/"), typically used for initial service discovery, host validation, or baseline content inspection prior to deeper enumeration.