Threat LevelCRITICAL80/1003 rule types across 3 attack categories
3 incidents on record · 3 rule types · active attacker + blocklisted · persistent 25-day campaign · last seen 32d ago
| PTR | lbank-bot-Netherlands-01 |
| Org / ASN | AS16276 OVH SAS |
| Country | 🇫🇷 France |
| City | Paris, Île-de-France |
| Timezone | Europe/Paris |
Attack Analysis
Bad Bot Flood
This IP generated over 20 HTTP 4xx errors in 60 seconds using a User-Agent identified as a bad bot (scraper, headless browser, or attack proxy). The high error rate indicates automated probing for vulnerabilities while trying to appear as generic traffic. Legitimate services respect robots.txt and do not flood servers with errors.
IDS: Threat Intel — CINS Active Threat
This IP appears in the CINS (Collective Intelligence Network Security) Active Threat Intelligence feed — a real-time blocklist of IPs with poor reputation scores derived from observed malicious activity. CINS-listed IPs are actively engaged in attacks at the time of detection.
Suricata IDS Alert
Suricata intrusion detection flagged this IP for malicious network behaviour — including port scanning, exploit attempts, botnet activity, or known attack signatures. The specific signature is shown in the report list below.
Reports (3)
| Date | Severity | Description |
|---|---|---|
| 28 Aug 2026 - 21:52 | high | Web: Bad bot 4xx flood — 20+ errors in 60s |
| 20 Aug 2026 - 04:49 | high | IDS: Suricata alert |
| 3 Aug 2026 - 14:37 | high | IDS: Threat Intel — CINS poor reputation IP |
EagleEye Intelligence