Threat LevelCRITICAL76/1003 rule types across 2 attack categories
32 incidents · 3 rule types · active attack detected · persistent 53-day campaign · seen 13h ago
| PTR | srv50830.dus8.dedi.server-hosting.expert |
| Org / ASN | myLoc managed IT AG |
| Country | 🇩🇪 Germany |
| City | Düsseldorf, North Rhine-Westphalia |
| Timezone | Europe/Berlin |
Attack Analysis
IDS: SIPVicious VoIP Scanner
SIPVicious is an automated tool that scans for SIP/VoIP infrastructure to harvest extension numbers and brute-force credentials. A successful scan enables toll fraud, eavesdropping, and unauthorized calls billed to the victim.
Suricata IDS Alert
Suricata intrusion detection flagged this IP for malicious network behaviour — including port scanning, exploit attempts, botnet activity, or known attack signatures. The specific signature is shown in the report list below.
IDS: Database Port Scan
Suricata detected this IP scanning database ports (MySQL, PostgreSQL, Redis, MongoDB). This is reconnaissance to find exposed database services for direct exploitation or credential brute-force. Database ports should never be reachable from the internet.
Reports (32)
| Date | Severity | Description |
|---|---|---|
| 31 Jul 2026 - 12:24 | medium | IDS: SIPVicious VoIP scanner — ET SCAN Sipvicious User-Agent Detected (friendly-scanner) |
| 31 Jul 2026 - 12:24 | medium | IDS: SIPVicious VoIP scanner — ET SCAN Sipvicious Scan |
| 31 Jul 2026 - 12:16 | medium | IDS: SIPVicious VoIP scanner — ET SCAN Sipvicious Scan |
| 31 Jul 2026 - 12:16 | medium | IDS: SIPVicious VoIP scanner — ET SCAN Sipvicious User-Agent Detected (friendly-scanner) |
| 31 Jul 2026 - 12:13 | medium | IDS: SIPVicious VoIP scanner — ET SCAN Sipvicious User-Agent Detected (friendly-scanner) |
| 31 Jul 2026 - 12:13 | medium | IDS: SIPVicious VoIP scanner — ET SCAN Sipvicious Scan |
| 31 Jul 2026 - 12:12 | medium | IDS: SIPVicious VoIP scanner — ET SCAN Sipvicious User-Agent Detected (friendly-scanner) |
| 31 Jul 2026 - 12:12 | medium | IDS: SIPVicious VoIP scanner — ET SCAN Sipvicious Scan |
| 31 Jul 2026 - 12:11 | medium | IDS: SIPVicious VoIP scanner — ET SCAN Sipvicious User-Agent Detected (friendly-scanner) |
| 31 Jul 2026 - 12:11 | medium | IDS: SIPVicious VoIP scanner — ET SCAN Sipvicious Scan |
| 31 Jul 2026 - 11:49 | medium | IDS: SIPVicious VoIP scanner — ET SCAN Sipvicious Scan |
| 31 Jul 2026 - 11:49 | medium | IDS: SIPVicious VoIP scanner — ET SCAN Sipvicious User-Agent Detected (friendly-scanner) |
| 29 Jul 2026 - 19:05 | medium | IDS: Suricata alert — Honeypot: probe to closed SSH port 22 |
| 29 Jul 2026 - 18:51 | high | IDS: Database port scan — ET SCAN Suspicious inbound to mySQL port 3306 |
| 17 Jul 2026 - 16:13 | medium | IDS: SIPVicious VoIP scanner — ET SCAN Sipvicious User-Agent Detected (friendly-scanner) |
| 17 Jul 2026 - 16:13 | medium | IDS: SIPVicious VoIP scanner — ET SCAN Sipvicious Scan |
| 5 Jul 2026 - 14:14 | medium | IDS: Suricata alert — Honeypot: probe to closed SSH port 22 |
| 5 Jul 2026 - 13:58 | high | IDS: Database port scan — ET SCAN Suspicious inbound to mySQL port 3306 |
| 4 Jul 2026 - 14:34 | medium | IDS: SIPVicious VoIP scanner — ET SCAN Sipvicious Scan |
| 4 Jul 2026 - 14:34 | medium | IDS: SIPVicious VoIP scanner — ET SCAN Sipvicious User-Agent Detected (friendly-scanner) |
EagleEye Intelligence