← Back to feed

85.217.149.59

TAGGED SUSPICIOUS how we decide →
Threat Confidence
53%
Location
🇨🇦 CA / Beauharnois
ASN
AS209334 · Modat B.V.
Cloud Provider
Total Events
5
Below average by volume
Agent Count
2
First / Last Seen
2026-06-12 13:59 — 2026-06-19 07:07
Attack Types
http:scan ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Credential Access
External Corroboration
CINS Army
Reported 2026-06-19 10:06
cins:bad_reputation
DShield Top Attackers
Reported 2026-06-19 10:01
dshield:top_attacker
Campaigns
Multi-Agent Scan SCAN Active medium
136 IPs 252705 events
2026-05-15 — ongoing · 136 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
214 IPs 291025 events
2026-05-08 — ongoing · 214 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
67 IPs 121751 events
2026-05-08 — ongoing · 67 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
31 IPs 8984 events
2026-04-04 — ongoing · 31 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
102 IPs 240553 events
2026-03-17 — ongoing · 102 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
100 IPs 239255 events
2026-03-17 — ongoing · 100 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
201 IPs 298198 events
2026-03-01 — ongoing · 201 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Subnet 85.217.149.0/24 SUBNET Active high 🇨🇦 CA
11 IPs 111 events
http:scanssh:bruteforce
2026-02-16 — ongoing · 11 IPs from the same /24 subnet (85.217.149.0/24) were observed attacking our sensors within the same time window. …
Session Forensics
web_probe ×1
Sessions
1
Avg Depth Score
0.25
Commands Executed
0
Files Downloaded
0
Evidence Timeline
Web Probe 51c999d1f4e43c02 newark_01 · 2026-06-12 13:59
25%
Loading events...
Non-Session Events
Timestamp Port Proto Event Source Location
2026-06-12 13:59:43 :80 http HTTP GET request opencanary ewr