Threat LevelCRITICAL80/1001 rule type
1 incident on record · last seen 31d ago
| PTR | 157.128.150.27.broad.xm.fj.dynamic.163data.com.cn |
| Org / ASN | Chinanet FJ |
| Country | 🇨🇳 China |
| City | Xiamen, Fujian |
| Timezone | Asia/Shanghai |
Botnet InfrastructureChinaNet (AS4134, China Telecom)
ChinaNet (AS4134) is one of the highest-volume attack-originating ASNs globally, consistently ranking in SANS/DShield top-10 attacker lists. Activity ranges from compromised consumer endpoints to dedicated scan infrastructure. SSH brute-force from this network targets common username dictionaries at scale — automated, persistent credential-harvesting botnet behavior.
Attack Analysis
Bad Bot Flood
This IP generated over 20 HTTP 4xx errors in 60 seconds using a User-Agent identified as a bad bot (scraper, headless browser, or attack proxy). The high error rate indicates automated probing for vulnerabilities while trying to appear as generic traffic. Legitimate services respect robots.txt and do not flood servers with errors.
Reports (1)
| Date | Severity | Description |
|---|---|---|
| 1 Jul 2026 - 08:52 | high | Web: Bad bot 4xx flood — 20+ errors in 60s |
EagleEye Intelligence