Threat LevelMEDIUM32/1001 rule type
7 incidents on record · persistent 7-day campaign · last seen 15d ago · known internet scanner
| PTR | us-east-3.xenon.li.prod.binaryedge.ninja |
| Org / ASN | Linode |
| Country | 🇺🇸 United States |
| City | Cedar Knolls, New Jersey |
| Timezone | America/New_York |
Internet ScannerBinaryedge
BinaryEdge — commercial threat intelligence company performing continuous internet-wide port scans. Data used to build attack surface maps. All unsolicited scanning probes are treated as hostile traffic on this network regardless of stated purpose.
Attack Analysis
Directory Brute-Force (Active Scan)
This IP triggered 10 or more HTTP 4xx errors within 60 seconds — the signature of a vulnerability scanner cycling through wordlists of common admin paths, config files, and endpoints. Tools like Nikto, Dirbuster, and Gobuster produce exactly this pattern.
Reports (7)
| Date | Severity | Description |
|---|---|---|
| 15 Sep 2026 - 00:18 | high | Web: Active scan — 10+ 4xx errors in 60s |
| 14 Sep 2026 - 00:31 | high | Web: Active scan — 10+ 4xx errors in 60s |
| 12 Sep 2026 - 00:53 | high | Web: Active scan — 10+ 4xx errors in 60s |
| 10 Sep 2026 - 00:35 | high | Web: Active scan — 10+ 4xx errors in 60s |
| 9 Sep 2026 - 00:26 | high | Web: Active scan — 10+ 4xx errors in 60s |
| 8 Sep 2026 - 00:53 | high | Web: Active scan — 10+ 4xx errors in 60s |
| 7 Sep 2026 - 16:39 | high | Web: Active scan — 10+ 4xx errors in 60s |
EagleEye Intelligence