← Back to feed

Multi-Agent Scan

SCAN Active medium
Why this campaign was detected
7 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close succession indicates shared reconnaissance tooling or a coordinated scan list.
Primary ASN
Subnet
Country
Cloud Provider
Member Count
7 IPs
Below average
Total Events
733
Below average by volume
Started / Ended
2026-02-27 22:24 — ongoing
Member Actors
IP Address Confidence Flags Events Agents Attack Types Hostname Last Seen
187.212.40.215 67% 1x OSINT 347 2 ssh:bruteforce 2026-04-02 09:42
128.1.47.28 66% 1x OSINT 210 2 ssh:bruteforce 2026-04-02 09:58
197.248.207.139 66% 1x OSINT 144 2 ssh:bruteforce 2026-04-02 09:39
34.76.35.74 40% 3 2 ftp:bruteforcemysql:bruteforce 2026-04-02 08:41
116.176.62.179 37% 11 1 ssh:bruteforce 2026-04-02 07:43
195.178.110.155 34% DROP 15 2 http:scan 2026-04-02 07:09
45.79.5.11 29% 1x OSINT 3 1 ssh:bruteforce 2026-04-02 07:35
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds