Threat LevelCRITICAL80/1002 rule types across 2 attack categories
12 incidents · 2 rule types · confirmed on global blocklist · persistent 7-day campaign · seen 5h ago · bulletproof hosting
| PTR | N/A |
| Org / ASN | Feo Prest SRL |
| Country | 🇳🇱 The Netherlands |
| City | Eygelshoven, Limburg |
| Timezone | Europe/Amsterdam |
Iranian Attack InfrastructureFEO PREST SRL (Iran)
This IP originates from an Iranian netblock (FEO PREST SRL range) that is among the most heavily reported attack infrastructure in global threat databases, with adjacent IPs accumulating over 326,000 independent abuse reports and 100% abuse confidence ratings. The scale and duration of abuse is consistent with state-adjacent or professionally-operated Iranian offensive infrastructure targeting servers globally.
Attack Analysis
Port 22 Honeypot Probe
This IP connected to a fake SSH honeypot — a port 22 listener that is not a real SSH server. This is an automated scanner fingerprinting targets before launching a brute-force campaign. Legitimate systems never probe port 22 without a specific reason; this activity is virtually 100% malicious.
IDS: Blocklist — Spamhaus DROP
This IP is on the Spamhaus DROP list — a dataset of netblocks hijacked or leased by professional spam and cybercrime operations with no legitimate users. Traffic from DROP-listed ranges is considered hostile by design. Blocking is unconditional.
Reports (12)
| Date | Severity | Description |
|---|---|---|
| 29 Sep 2026 - 20:29 | high | IDS: Blocklist — Spamhaus DROP listed IP — ET DROP Spamhaus DROP Listed Traffic Inbound group 64 |
| 29 Sep 2026 - 20:29 | high | IDS: Honeypot probe — port 22 listener that is not a real SSH server — Honeypot: probe to closed SSH port 22 |
| 29 Sep 2026 - 15:31 | high | IDS: Blocklist — Spamhaus DROP listed IP — ET DROP Spamhaus DROP Listed Traffic Inbound group 64 |
| 29 Sep 2026 - 15:31 | high | IDS: Honeypot probe — port 22 listener that is not a real SSH server — Honeypot: probe to closed SSH port 22 |
| 26 Sep 2026 - 22:47 | high | IDS: Blocklist — Spamhaus DROP listed IP — ET DROP Spamhaus DROP Listed Traffic Inbound group 64 |
| 26 Sep 2026 - 22:47 | high | IDS: Honeypot probe — port 22 listener that is not a real SSH server — Honeypot: probe to closed SSH port 22 |
| 23 Sep 2026 - 05:35 | high | IDS: Honeypot probe — port 22 listener that is not a real SSH server — Honeypot: probe to closed SSH port 22 |
| 23 Sep 2026 - 05:35 | high | IDS: Blocklist — Spamhaus DROP listed IP — ET DROP Spamhaus DROP Listed Traffic Inbound group 64 |
| 22 Sep 2026 - 23:44 | high | IDS: Blocklist — Spamhaus DROP listed IP — ET DROP Spamhaus DROP Listed Traffic Inbound group 64 |
| 22 Sep 2026 - 23:44 | high | IDS: Honeypot probe — port 22 listener that is not a real SSH server — Honeypot: probe to closed SSH port 22 |
| 22 Sep 2026 - 19:33 | high | IDS: Honeypot probe — port 22 listener that is not a real SSH server — Honeypot: probe to closed SSH port 22 |
| 22 Sep 2026 - 19:33 | high | IDS: Blocklist — Spamhaus DROP listed IP — ET DROP Spamhaus DROP Listed Traffic Inbound group 64 |
EagleEye Intelligence