Threat LevelCRITICAL72/1002 rule types across 2 attack categories
3 incidents on record ยท 2 rule types ยท active attacker + blocklisted ยท last seen 14d ago
| PTR | 112-nred253.megalink.com.ar |
| Org / ASN | Megalink S.R.L |
| Country | ๐ฆ๐ท Argentina |
| City | Granadero Baigorria, Santa Fe |
| Timezone | America/Argentina/Cordoba |
Attack Analysis
IDS: Blocklist โ Spamhaus DROP
This IP is on the Spamhaus DROP list โ a dataset of netblocks hijacked or leased by professional spam and cybercrime operations with no legitimate users. Traffic from DROP-listed ranges is considered hostile by design. Blocking is unconditional.
Suricata IDS Alert
Suricata intrusion detection flagged this IP for malicious network behaviour โ including port scanning, exploit attempts, botnet activity, or known attack signatures. The specific signature is shown in the report list below.
Reports (3)
| Date | Severity | Description |
|---|---|---|
| 15 Sep 2026 - 23:25 | medium | IDS: Suricata alert โ ET WEB_SERVER WGET Command Specifying Output in HTTP Headers |
| 15 Sep 2026 - 23:21 | high | IDS: Blocklist โ Spamhaus DROP listed IP โ ET DROP Spamhaus DROP Listed Traffic Inbound group 42 |
| 15 Sep 2026 - 23:21 | high | IDS: Blocklist โ Spamhaus DROP listed IP |
EagleEye Intelligence