← Back to feed

Multi-Agent Scan

SCAN Active medium
Why this campaign was detected
7 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close succession indicates shared reconnaissance tooling or a coordinated scan list.
Primary ASN
Subnet
Country
Cloud Provider
Member Count
7 IPs
Below average
Total Events
13122
Below average by volume
Started / Ended
2026-06-24 19:24 — ongoing
Member Actors
IP Address Behavior Confidence Flags Events Agents Attack Types Hostname Last Seen
80.94.92.55 interactive_operator 77% DROP2x OSINT 13960 3 ssh:bruteforce 2026-08-28 06:11 evidence →
36.41.173.197 credential_harvester 74% 2x OSINT 509 3 ssh:bruteforce 2026-08-22 23:04 evidence →
172.191.94.172 credential_harvester 71% 1x OSINT 901 3 ssh:bruteforce 2026-08-23 00:43 evidence →
103.78.2.252 credential_probe 31% 2x OSINT 30 2 ssh:bruteforce 2026-08-22 17:44 evidence →
45.61.177.200 ftp_bruter 28% 43 2 ftp:bruteforce 2026-08-26 19:31 evidence →
73.246.154.213 scanner 22% 8 2 ssh:bruteforce 2026-08-22 23:45 evidence →
191.116.11.184 scanner 21% 4 2 ssh:bruteforce 2026-08-23 00:17 evidence →
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds
{# Cloudflare Web Analytics — cookieless, public pages only. The context processor withholds the token from authenticated requests. #}