Report for IP: 120.48.115.34

Threat LevelCRITICAL72/1002 rule types
10 incidents · 2 rule types · active attack detected · persistent 41-day campaign · last seen 16d ago
PTR N/A
Org / ASN Beijing Baidu Netcom Science and Technology Co., Ltd.
Country 🇨🇳 China
City Beijing, Beijing
Timezone Asia/Shanghai

Attack Analysis

🇨🇳 China · Beijing · 38365 · Beijing Baidu Netcom Science And Technology Co., Ltd.
Port 22 Honeypot Probe
This IP connected to a fake SSH honeypot — a port 22 listener that is not a real SSH server. This is an automated scanner fingerprinting targets before launching a brute-force campaign. Legitimate systems never probe port 22 without a specific reason; this activity is virtually 100% malicious.
Suricata IDS Alert
Suricata intrusion detection flagged this IP for malicious network behaviour — including port scanning, exploit attempts, botnet activity, or known attack signatures. The specific signature is shown in the report list below.

Reports (10)

Date Severity Description
16 Jul 2026 - 07:13 high IDS: Suricata alert — Honeypot: probe to closed SSH port 22
14 Jul 2026 - 00:40 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
13 Jul 2026 - 08:31 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
13 Jul 2026 - 01:03 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
12 Jul 2026 - 01:10 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
5 Jul 2026 - 00:35 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
1 Jul 2026 - 00:56 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
28 Jun 2026 - 00:47 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
21 Jun 2026 - 00:08 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
4 Jun 2026 - 22:33 high IDS: Port 22 honeypot probe