Check an IP Address, Domain Name, Subnet, or ASN
83.147.216.33 has a threat confidence score of 77%. This IP address from Finland (AS203273, NetCrafters OU) has been observed in 11 honeypot sessions targeting SSH protocols. First observed on March 26, 2026, most recently active March 26, 2026.
Identifies the use of SCP in quiet mode (-q) with “to” mode (-t), indicating the remote system is receiving a file. This pattern is commonly associated with post-authentication payload delivery, lateral movement staging, or tool transfer to a compromised host.
Identifies SSH sessions where the actor executes uname -s -v -n -r -m to retrieve detailed kernel, hostname, architecture, and OS version information for environment profiling and post-access decision making.