Report for IP: 105.28.108.165

Threat LevelCRITICAL72/1003 rule types across 2 attack categories
22 incidents · 3 rule types · active attack detected · persistent 15-day campaign · last seen 18d ago
PTR N/A
Org / ASN AS37100 SEACOM Limited
Country 🇿🇦 South Africa
City Pretoria, Gauteng
Timezone Africa/Johannesburg

Attack Analysis

🇿🇦 South Africa · Pretoria · 37100 · Assignment Made to Seacom Infrastructure.
SSH: Login Attempt — Non-Existent User
This IP attempted to authenticate via SSH using a username that does not exist on the system. This is characteristic of automated credential-stuffing attacks cycling through common username wordlists (admin, root, ubuntu, pi, etc.).
SSH: Invalid User Flood
This IP attempted SSH logins using 5 or more invalid usernames within 2 minutes — a credential-stuffing attack cycling through common account names (admin, root, ubuntu, deploy, pi). This indicates an automated tool probing for default or common accounts.
Suricata IDS Alert
Suricata intrusion detection flagged this IP for malicious network behaviour — including port scanning, exploit attempts, botnet activity, or known attack signatures. The specific signature is shown in the report list below.

Reports (22)

Date Severity Description
8 Jul 2026 - 15:44 medium SSH: Login attempt using non-existent user
28 Jun 2026 - 14:23 high SSH: Login attempt using non-existent user