← Back to feed

185.139.214.221

TAGGED SUSPICIOUS how we decide →
Threat Confidence
33%
Location
🇺🇸 US / Las Vegas
ASN
AS200019 · Alexhost Srl
Cloud Provider
Total Events
9
Average by volume
Agent Count
1
First / Last Seen
2026-09-03 17:58 — 2026-09-04 20:04
Attack Types
ftp:bruteforce http:scan
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Credential Access
External Corroboration
CINS Army
Reported 2026-09-15 17:01
cins:bad_reputation
DShield Top Attackers
Reported 2026-09-15 06:01
dshield:top_attacker
Campaigns
Not associated with any campaigns
Session Forensics
ftp_probe ×7 web_probe ×2
Sessions
9
Avg Depth Score
0.21
Commands Executed
0
Files Downloaded
0
Evidence Timeline
Web Probe 1f5340e67dff4c19 newark_01 · 2026-09-04 20:04
25%
Loading events...
Web Probe 9dba1ad9da1a20fa newark_01 · 2026-09-04 19:16
25%
Loading events...
FTP Probe 2b05128cb465fc98 newark_01 · 2026-09-03 17:58
1 20%
Loading events...
FTP Probe 7967354df6334dfc newark_01 · 2026-09-03 17:58
1 20%
Loading events...
FTP Probe adec2ec6436318a7 newark_01 · 2026-09-03 17:58
1 20%
Loading events...
FTP Probe e1e66b50861c4a66 newark_01 · 2026-09-03 17:58
1 20%
Loading events...
FTP Probe 2dec719812f2aef0 newark_01 · 2026-09-03 17:58
1 20%
Loading events...
FTP Probe 17582fa23c914577 newark_01 · 2026-09-03 17:58
1 20%
Loading events...
FTP Probe 092dc38acbbb047e newark_01 · 2026-09-03 17:58
1 20%
Loading events...
Non-Session Events
Timestamp Port Proto Event Source Location
2026-09-04 20:04:26 :80 http HTTP GET request opencanary ewr
2026-09-04 19:16:36 :80 http HTTP GET request opencanary ewr
2026-09-03 17:58:33 :21 ftp FTP connection opencanary ewr
2026-09-03 17:58:32 :21 ftp FTP connection opencanary ewr
2026-09-03 17:58:32 :21 ftp FTP connection opencanary ewr
2026-09-03 17:58:31 :21 ftp FTP connection opencanary ewr
2026-09-03 17:58:31 :21 ftp FTP connection opencanary ewr
2026-09-03 17:58:31 :21 ftp FTP connection opencanary ewr
2026-09-03 17:58:30 :21 ftp FTP connection opencanary ewr
{# Cloudflare Web Analytics — cookieless, public pages only. The context processor withholds the token from authenticated requests. #}