Looking for any information on 103.215.75.19 which has potentially been linked with confirmed threat actor activity (let’s just say “we” messaged with the seller and leave it at that.) This IP is also scanning the you know what out of Azure Kubernetes. Seems to be looking for a way in. Attempted two remote connections. Logs show activity back into May.
VT says it’s ugly, and it appears to come from a bulletproof hosting AS.
In don’t have a link to a threat actor, but we (ESET) have seen malicious activity from this IP since at least mid-June, with a large spike on 2026-06-29
They eventually moved on after scanning the you-know-what out of our Internet facing services. There was a Joomla using server on a 3rd party host, but it had no internal environment access. All’s well that ends well I suppose. Thanks all!