Check an IP Address, Domain Name, Subnet, or ASN
91.196.152.88 has a threat confidence score of 53%. This IP address from France (AS213412, ONYPHE SAS) has been observed in 31 honeypot sessions targeting FTP, SSH, HTTP, HTTPS, IMAP and 7 other protocols. First observed on January 23, 2026, most recently active March 24, 2026.
FTP session where an empty control-channel command is observed in conjunction with non-printable binary data on the control channel. This pattern reflects malformed or non-FTP-compliant input, commonly seen during TLS handshake attempts on plaintext endpoints, protocol confusion, or automated scanner misfires.
Identifies HTTP requests targeting the web server root path ("/"), typically used for initial service discovery, host validation, or baseline content inspection prior to deeper enumeration.