Report for IP: 209.141.57.35

Threat LevelCRITICAL72/1001 rule type
9 incidents on record Β· persistent 17-day campaign Β· last seen 73d ago
PTR nv.oberholster.net
Org / ASN FranTech Solutions
Country πŸ‡ΊπŸ‡Έ United States
City Las Vegas, Nevada
Timezone America/Los_Angeles

Attack Analysis

Port 22 Honeypot Probe
This IP connected to a fake SSH honeypot β€” a port 22 listener that is not a real SSH server. This is an automated scanner fingerprinting targets before launching a brute-force campaign. Legitimate systems never probe port 22 without a specific reason; this activity is virtually 100% malicious.

Reports (9)

Date Severity Description
19 Jul 2026 - 09:33 medium IDS: Suricata alert β€” Honeypot: probe to closed SSH port 22
18 Jul 2026 - 19:05 medium IDS: Suricata alert β€” Honeypot: probe to closed SSH port 22
16 Jul 2026 - 20:02 medium IDS: Suricata alert β€” Honeypot: probe to closed SSH port 22
16 Jul 2026 - 07:53 medium IDS: Suricata alert β€” Honeypot: probe to closed SSH port 22
15 Jul 2026 - 11:01 medium IDS: Suricata alert β€” Honeypot: probe to closed SSH port 22
14 Jul 2026 - 03:20 medium IDS: Suricata alert β€” Honeypot: probe to closed SSH port 22
9 Jul 2026 - 12:55 medium IDS: Suricata alert β€” Honeypot: probe to closed SSH port 22
6 Jul 2026 - 07:31 medium IDS: Suricata alert β€” Honeypot: probe to closed SSH port 22
2 Jul 2026 - 10:24 medium IDS: Suricata alert β€” Honeypot: probe to closed SSH port 22