Report for IP: 106.12.148.154

Threat LevelCRITICAL72/1002 rule types
28 incidents ยท 2 rule types ยท persistent 65-day campaign ยท last seen 15d ago
PTR N/A
Org / ASN Beijing Baidu Netcom Science and Technology Co., Ltd.
Country ๐Ÿ‡จ๐Ÿ‡ณ China
City Beijing, Beijing
Timezone Asia/Shanghai

Attack Analysis

Port 22 Honeypot Probe
This IP connected to a fake SSH honeypot โ€” a port 22 listener that is not a real SSH server. This is an automated scanner fingerprinting targets before launching a brute-force campaign. Legitimate systems never probe port 22 without a specific reason; this activity is virtually 100% malicious.

Reports (28)

Date Severity Description
1 Sep 2026 - 03:30 medium IDS: Suricata alert โ€” Honeypot: probe to closed SSH port 22
1 Sep 2026 - 03:28 medium IDS: Suricata alert โ€” Honeypot: probe to closed SSH port 22
1 Sep 2026 - 03:26 medium IDS: Suricata alert โ€” Honeypot: probe to closed SSH port 22
1 Sep 2026 - 03:22 medium IDS: Suricata alert โ€” Honeypot: probe to closed SSH port 22
1 Sep 2026 - 03:22 medium IDS: Suricata alert โ€” Honeypot: probe to closed SSH port 22
29 Aug 2026 - 00:34 medium IDS: Suricata alert โ€” Honeypot: probe to closed SSH port 22
28 Aug 2026 - 23:39 medium IDS: Suricata alert โ€” Honeypot: probe to closed SSH port 22
12 Jul 2026 - 07:45 medium IDS: Suricata alert โ€” Honeypot: probe to closed SSH port 22