← Back to feed

Multi-Agent Scan

SCAN Active medium
Why this campaign was detected
5 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close succession indicates shared reconnaissance tooling or a coordinated scan list.
Primary ASN
Subnet
Country
Cloud Provider
Member Count
5 IPs
Below average
Total Events
4050
Below average by volume
Started / Ended
2026-02-22 20:25 — ongoing
Member Actors
IP Address Confidence Flags Events Agents Attack Types Hostname Last Seen
91.92.243.49 59% DROP1x OSINT 25 2 ssh:bruteforce 2026-04-03 19:41
66.181.171.136 59% 1x OSINT 3019 2 ssh:bruteforce 2026-04-03 17:26
36.212.227.224 58% 37 2 ssh:bruteforce 2026-04-03 17:05
80.94.92.168 57% DROP2x OSINT 984 2 ssh:bruteforce 2026-04-03 22:59
204.76.203.215 43% DROP2x OSINT 6 2 ssh:bruteforce 2026-04-03 18:10
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds