Threat LevelMEDIUM47/1002 rule types
3 incidents on record · 2 rule types · active attack detected · last seen 36d ago
| PTR | N/A |
| Org / ASN | AS49870 Alsycon B.V. |
| Country | 🇳🇱 The Netherlands |
| City | Amsterdam, North Holland |
| Timezone | Europe/Amsterdam |
Attack Analysis
Slow SSH Preauth Scan
This IP repeatedly connected to SSH, collected the server banner and host key, then disconnected before authenticating — multiple times over 30 minutes. This slow scan pattern maps SSH versions and keys while staying below rate-limit thresholds. It is used exclusively by botnet scanners preparing for brute-force attacks.
SSH: Login Attempt — Non-Existent User
This IP attempted to authenticate via SSH using a username that does not exist on the system. This is characteristic of automated credential-stuffing attacks cycling through common username wordlists (admin, root, ubuntu, pi, etc.).
Reports (3)
| Date | Severity | Description |
|---|---|---|
| 24 Aug 2026 - 22:46 | high | SSH: Login attempt using non-existent user |
| 23 Aug 2026 - 22:45 | medium | SSH: Login attempt using non-existent user |
| 23 Aug 2026 - 22:45 | high | SSH: Slow preauth scan — 5+ disconnects in 30 min |
EagleEye Intelligence