← Back to feed
65.49.1.149
Location
🇺🇸 US
ASN
AS6939 · Hurricane Electric LLC
Cloud Provider
—
Total Events
8
Below average by volume
Agent Count
2
First / Last Seen
2026-04-27 14:39 — 2026-04-30 13:52
Attack Types
MITRE ATT&CK Techniques
External Corroboration
DShield Top Attackers
dshield:top_attacker
Campaigns
Multi-Agent Scan
SCAN
Active
medium
80 IPs
363877 events
2026-04-27 — ongoing · 80 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan
SCAN
Active
medium
76 IPs
367258 events
2026-04-23 — ongoing · 76 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan
SCAN
Active
medium
4 IPs
267 events
2026-04-17 — ongoing · 4 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan
SCAN
Active
medium
31 IPs
25526 events
2026-03-20 — ongoing · 31 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan
SCAN
Active
medium
78 IPs
42532 events
2026-03-20 — ongoing · 78 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan
SCAN
Active
medium
71 IPs
358625 events
2026-03-10 — ongoing · 71 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan
SCAN
Active
medium
94 IPs
373670 events
2026-03-07 — ongoing · 94 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan
SCAN
Active
medium
57 IPs
258689 events
2026-03-07 — ongoing · 57 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan
SCAN
Active
medium
6 IPs
1664 events
2026-03-07 — ongoing · 6 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Subnet 65.49.1.0/24
SUBNET
Active
high
🇺🇸 US
16 IPs
118 events
http:scanssh:bruteforce
2026-02-19 — ongoing · 16 IPs from the same /24 subnet (65.49.1.0/24) were observed attacking our sensors within the same time window. …
Session Forensics
Sessions
2
Avg Depth Score
0.15
Commands Executed
0
Files Downloaded
0
Fingerprints
HASSH
SSH Client
Evidence Timeline