Check an IP Address, Domain Name, Subnet, or ASN
68.235.38.3 has a threat confidence score of 77%. This IP address from United States (AS11878, tzulo, inc.) has been observed in 7 honeypot sessions targeting FTP protocols. First observed on March 26, 2026, most recently active March 27, 2026.
FTP session where a client probes for valid users, attempts authentication, switches to ASCII mode, enters passive mode, and issues an NLST command to retrieve a directory name listing. This sequence reflects authenticated directory enumeration focused on discovering available files or structure without detailed metadata retrieval.
FTP session where a client probes for valid usernames, attempts authentication, switches to ASCII mode, and enters passive mode without performing explicit file listing or transfer operations. This reflects a completed login and session setup sequence, often observed during credential validation or preparatory access prior to further activity.