Report for IP: 1.209.110.147

Threat LevelCRITICAL74/1001 rule type
7 incidents on record · active attack detected · persistent 12-day campaign · seen 11h ago
PTR N/A
Org / ASN Boranet
Country 🇰🇷 South Korea
City Goyang-si, Gyeonggi-do
Timezone Asia/Seoul

Attack Analysis

🇰🇷 South Korea · Anyang-si · 3786 · Lg Dacom Corporation
Suricata IDS Alert
Suricata intrusion detection flagged this IP for malicious network behaviour — including port scanning, exploit attempts, botnet activity, or known attack signatures. The specific signature is shown in the report list below.

Reports (7)

Date Severity Description
31 Jul 2026 - 12:55 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
31 Jul 2026 - 12:47 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
31 Jul 2026 - 11:00 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
24 Jul 2026 - 11:04 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
24 Jul 2026 - 11:03 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
19 Jul 2026 - 10:38 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
19 Jul 2026 - 10:37 high IDS: Suricata alert — Honeypot: probe to closed SSH port 22