← Back to feed

199.195.248.228

TAGGED SUSPICIOUS how we decide →
Threat Confidence
48%
Location
🇺🇸 US / Staten Island
ASN
AS53667 · FranTech Solutions
Cloud Provider
Total Events
28
Average by volume
Agent Count
2
First / Last Seen
2026-05-05 02:05 — 2026-05-10 11:41
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Credential Access
External Corroboration
Blocklist.de
Reported 2026-05-10 13:02
blocklist_de:reported
Campaigns
Multi-Agent Scan SCAN Active medium
276 IPs 141221 events
2026-05-10 — ongoing · 276 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
46 IPs 9761 events
2026-05-10 — ongoing · 46 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
285 IPs 141225 events
2026-05-03 — ongoing · 285 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
282 IPs 131472 events
2026-05-03 — ongoing · 282 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
286 IPs 141222 events
2026-05-03 — ongoing · 286 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
HASSH 14b2ddda386a… — SSH-2.0-libssh2_1.11.0 (566 IPs, 48 countries) HASSH Active high 🇺🇸 US
566 IPs 14114 events
ssh:bruteforce
2026-04-22 — ongoing · 566 IPs are running an identical SSH client (HASSH fingerprint 14b2ddda386a…). Top network: OVH SAS (AS16276). Geographic and …
Multi-Agent Scan SCAN Active medium
247 IPs 140554 events
2026-04-20 — ongoing · 247 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
241 IPs 32836 events
2026-03-31 — ongoing · 241 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
270 IPs 36769 events
2026-03-21 — ongoing · 270 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
12 IPs 261 events
2026-02-26 — ongoing · 12 IPs independently targeted the same honeypot sensors within a 24-hour window. Hosted on DO. Scanning the same …
Multi-Agent Scan SCAN Active medium
294 IPs 142551 events
2026-02-22 — ongoing · 294 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
AS53667 FranTech Solutions ASN Active medium 🇺🇸 US
13 IPs 2424 events
ssh:bruteforce
2026-02-16 — ongoing · 13 IPs from the same network (FranTech Solutions, AS53667) were active during overlapping time periods. Temporal correlation across …
Session Forensics
credential_harvester ×2
Sessions
2
Avg Depth Score
0.4
Commands Executed
0
Files Downloaded
0
Fingerprints
SSH-2.0-libssh2_1.11.0
Evidence Timeline
Credential Harvester 2305a3b01fa0 w4m_seattle_01 · 2026-05-10 11:41
5 40%
Loading events...
Credential Harvester c9f93a38f4c5 w4m_singapore_01 · 2026-05-05 02:05
5 40%
Loading events...