Threat LevelCRITICAL72/1004 rule types across 3 attack categories
15 incidents · 4 rule types · active attack detected · active over 2 days · last seen 22d ago
| PTR | host-36.50.151-66.myrepublic.co.id |
| Org / ASN | PT. INKOPI SOLUSI CIPTA CEMERLANG |
| Country | 🇮🇩 Indonesia |
| City | Depok, West Java |
| Timezone | Asia/Jakarta |
Attack Analysis
SSH: Login Attempt — Non-Existent User
This IP attempted to authenticate via SSH using a username that does not exist on the system. This is characteristic of automated credential-stuffing attacks cycling through common username wordlists (admin, root, ubuntu, pi, etc.).
SSH: Invalid User Flood
This IP attempted SSH logins using 5 or more invalid usernames within 2 minutes — a credential-stuffing attack cycling through common account names (admin, root, ubuntu, deploy, pi). This indicates an automated tool probing for default or common accounts.
Suricata IDS Alert
Suricata intrusion detection flagged this IP for malicious network behaviour — including port scanning, exploit attempts, botnet activity, or known attack signatures. The specific signature is shown in the report list below.
IDS: SSH Port Scan
Suricata detected automated SSH port scanning from this IP. SSH scanners map targets before launching credential brute-force attacks. This is the reconnaissance phase of a larger attack campaign.
Reports (15)
| Date | Severity | Description |
|---|---|---|
| 9 Jul 2026 - 21:06 | medium | IDS: Suricata alert — Honeypot: probe to closed SSH port 22 |
| 9 Jul 2026 - 21:06 | high | IDS: SSH port scan — ET SCAN Potential SSH Scan |
| 8 Jul 2026 - 07:22 | medium | SSH: Login attempt using non-existent user |
| 8 Jul 2026 - 07:21 | medium | SSH: Login attempt using non-existent user |
| 8 Jul 2026 - 07:18 | medium | SSH: Login attempt using non-existent user |
| 8 Jul 2026 - 07:13 | high | SSH: Invalid user flood — 5+ attempts in 120s |
| 8 Jul 2026 - 07:13 | medium | SSH: Login attempt using non-existent user |
| 8 Jul 2026 - 07:11 | medium | SSH: Login attempt using non-existent user |
| 8 Jul 2026 - 07:07 | medium | SSH: Login attempt using non-existent user |
| 8 Jul 2026 - 07:01 | medium | SSH: Login attempt using non-existent user |
| 8 Jul 2026 - 07:00 | medium | SSH: Login attempt using non-existent user |
| 8 Jul 2026 - 06:52 | medium | SSH: Login attempt using non-existent user |
| 8 Jul 2026 - 06:52 | high | SSH: Invalid user flood — 5+ attempts in 120s |
| 8 Jul 2026 - 06:50 | medium | SSH: Login attempt using non-existent user |
| 8 Jul 2026 - 06:37 | high | SSH: Login attempt using non-existent user |
EagleEye Intelligence