Report for IP: 209.14.89.9

Threat LevelCRITICAL72/1001 rule type
13 incidents · active attack detected · persistent 17-day campaign · last seen 23d ago
PTR gru-209-14-89-9.ip4.99.network
Org / ASN X99 US LLC
Country 🇧🇷 Brazil
City São Paulo, São Paulo
Timezone America/Sao_Paulo

Attack Analysis

🇧🇷 Brazil · Vila Sarapui · 272786 · Cogent Communications
Suricata IDS Alert
Suricata intrusion detection flagged this IP for malicious network behaviour — including port scanning, exploit attempts, botnet activity, or known attack signatures. The specific signature is shown in the report list below.

Reports (13)

Date Severity Description
9 Jul 2026 - 10:36 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
9 Jul 2026 - 05:31 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
9 Jul 2026 - 02:16 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
8 Jul 2026 - 21:43 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
8 Jul 2026 - 01:54 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
7 Jul 2026 - 09:55 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
6 Jul 2026 - 22:41 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
6 Jul 2026 - 21:58 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
6 Jul 2026 - 17:35 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
6 Jul 2026 - 15:51 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
28 Jun 2026 - 08:04 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
27 Jun 2026 - 08:48 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
22 Jun 2026 - 01:15 high IDS: Suricata alert — Honeypot: probe to closed SSH port 22