Report for IP: 66.116.237.163

Threat LevelCRITICAL74/1002 rule types across 2 attack categories
21 incidents · 2 rule types · active attack detected · persistent 11-day campaign · seen 20h ago
PTR server.nfccard.live
Org / ASN P.D.R Solutions FZC
Country 🇦🇪 United Arab Emirates
City Abu Dhabi, Abu Dhabi
Timezone Asia/Dubai

Attack Analysis

🇺🇸 United States · Phoenix · 31898 · P.D.R Solutions Fzc
Suricata IDS Alert
Suricata intrusion detection flagged this IP for malicious network behaviour — including port scanning, exploit attempts, botnet activity, or known attack signatures. The specific signature is shown in the report list below.
IDS: SSH Port Scan
Suricata detected automated SSH port scanning from this IP. SSH scanners map targets before launching credential brute-force attacks. This is the reconnaissance phase of a larger attack campaign.

Reports (21)

Date Severity Description
18 Jun 2026 - 17:36 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
18 Jun 2026 - 17:36 high IDS: SSH port scan — ET SCAN Potential SSH Scan
17 Jun 2026 - 06:29 high IDS: SSH port scan — ET SCAN Potential SSH Scan
17 Jun 2026 - 06:29 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
15 Jun 2026 - 19:38 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
15 Jun 2026 - 19:38 high IDS: SSH port scan — ET SCAN Potential SSH Scan
14 Jun 2026 - 11:52 high IDS: SSH port scan — ET SCAN Potential SSH Scan
14 Jun 2026 - 11:52 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
13 Jun 2026 - 06:32 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
13 Jun 2026 - 06:32 high IDS: SSH port scan — ET SCAN Potential SSH Scan
12 Jun 2026 - 05:08 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
12 Jun 2026 - 05:08 high IDS: SSH port scan — ET SCAN Potential SSH Scan
11 Jun 2026 - 04:41 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
11 Jun 2026 - 04:41 high IDS: SSH port scan — ET SCAN Potential SSH Scan
10 Jun 2026 - 06:37 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
10 Jun 2026 - 06:37 high IDS: SSH port scan — ET SCAN Potential SSH Scan
9 Jun 2026 - 11:23 high IDS: SSH port scan — ET SCAN Potential SSH Scan
9 Jun 2026 - 11:23 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
8 Jun 2026 - 18:36 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
8 Jun 2026 - 18:36 high IDS: SSH port scan — ET SCAN Potential SSH Scan