// public entity intelligence
116.99.171.249
Evidence summary
Researcher feed observations and neutral DNS history are counted separately.
Tags
Sources
Observed 380 times. Targeted ports: 22. Country: Vietnam. Alert categories: Generic Protocol Command Decode, Misc activity. Signatures: ET INFO SSH session in progress on Expected Port, SURICATA STREAM CLOSEWAIT FIN out of window, SURICATA STREAM spurious retransmission. Usernames: admin, btf, ftp, guest, kelly and 11 more.
| Indicator | Type | Tag | Source | Last seen |
|---|---|---|---|---|
| 116.99.171.249 | ip | honeypot, historical | 2026-08-12 11:17:16 | |
Honeypot infrastructure watch: Observed 380 times. Targeted ports: 22. Country: Vietnam. Alert categories: Generic Protocol Command Decode, Misc activity. Signatures: ET INFO SSH session in progress on Expected Port, SURICATA STREAM CLOSEWAIT FIN out of window, SURICATA STREAM spurious retransmission. Usernames: admin, btf, ftp, guest, kelly and 11 more. | ||||
Related hosts and IPs
Public passive DNS relationships connected to this exact indicator.
Network ownership
BGP origin and registry data from Team Cymru.
VIETTEL-AS-VN - Viettel Corporation, VN
Registry country is RIR assignment data, not IP geolocation.
Checked 9/28/2026, 12:42:41 AM
Popularity
Daily link and hosting prominence from top1m.org; not a security verdict or traffic estimate.
Not present in the current Top 1M lists.
Take this investigation further
1 public pDNS relationships are available. Private research adds exact timing, focused pivots, and matching paid-feed intelligence. Each private app search costs 1 CTIDAO.