Check an IP Address, Domain Name, Subnet, or ASN
88.123.132.148 has a threat confidence score of 82%. This IP address from France (AS12322, Free SAS) has been observed in 9 honeypot sessions targeting SMB protocols. Detected attack patterns include smb domain share and rpc enumeration with write test. First observed on March 25, 2026, most recently active March 25, 2026.
Composite behavior identifying authenticated SMB access across administrative (ADMIN$, C$), backup, data, IPC$, and NETLOGON shares, combined with root directory reads, SAMR and SRVSVC RPC binding, and creation or overwrite of a delete.me file. This sequence is consistent with structured domain-level host and share reconnaissance followed by write-permission validation, commonly observed in automated post-authentication discovery and lateral movement tooling.