← Back to feed

Modat (CTI scanning)

SCANNER Active high
Primary ASN
Subnet
Country
🇨🇦 CA
Cloud Provider
Member Count
3 IPs
Below average
Total Events
73
Below average by volume
Started / Ended
2026-02-27 04:47 — ongoing
Attack Types
http:scan ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Credential Access
Discovery
Member Actors
IP Address Behavior Confidence Flags Events Agents Attack Types Hostname Last Seen
85.217.149.3 web_probe 10% 1x OSINT 30 3 http:scanssh:bruteforce o004.scanner.modat.io 2026-09-13 05:19 evidence →
85.217.149.2 web_probe 10% 1x OSINT 22 3 http:scanssh:bruteforce o003.scanner.modat.io 2026-09-12 19:27 evidence →
85.217.149.40 scanner 10% 1x OSINT 21 3 http:scanssh:bruteforce o040.scanner.modat.io 2026-09-10 19:09 evidence →
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds
{# Cloudflare Web Analytics — cookieless, public pages only. The context processor withholds the token from authenticated requests. #}