Check an IP Address, Domain Name, Subnet, or ASN
58.181.99.122 has a threat confidence score of 67%. This IP address from Pakistan (AS45595, Pakistan Telecom Company Limited) has been observed in 253 honeypot sessions targeting SMB, FTP protocols. Detected attack patterns include ftp authenticated upload to pub vendor. First observed on January 20, 2026, most recently active March 23, 2026.
FTP session where a client probes for valid usernames, attempts authentication, enters passive mode, negotiates transfer modes (ASCII/Binary), enumerates the /pub/vendor directory, and attempts to upload info.zip. This sequence reflects authenticated directory reconnaissance followed by file placement into a publicly accessible path, consistent with staged content deployment.