Report for IP: 90.162.116.66

Threat LevelCRITICAL76/1002 rule types across 2 attack categories
21 incidents · 2 rule types · active attack detected · persistent 9-day campaign · seen 15h ago
PTR 66.pool90-162-116.dynamic.orange.es
Org / ASN AS12479 Orange Espagne SA
Country 🇪🇸 Spain
City Valencia, Valencia
Timezone Europe/Madrid

Attack Analysis

🇪🇸 Spain · Valencia · 12479 · Addresses Ip for Adsl Customers
Suricata IDS Alert
Suricata intrusion detection flagged this IP for malicious network behaviour — including port scanning, exploit attempts, botnet activity, or known attack signatures. The specific signature is shown in the report list below.
IDS: SSH Port Scan
Suricata detected automated SSH port scanning from this IP. SSH scanners map targets before launching credential brute-force attacks. This is the reconnaissance phase of a larger attack campaign.

Reports (21)

Date Severity Description
16 Jun 2026 - 18:56 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
16 Jun 2026 - 18:56 high IDS: SSH port scan — ET SCAN Potential SSH Scan
16 Jun 2026 - 00:40 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
16 Jun 2026 - 00:40 high IDS: SSH port scan — ET SCAN Potential SSH Scan
15 Jun 2026 - 09:03 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
15 Jun 2026 - 09:03 high IDS: SSH port scan — ET SCAN Potential SSH Scan
14 Jun 2026 - 09:27 high IDS: SSH port scan — ET SCAN Potential SSH Scan
14 Jun 2026 - 09:27 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
13 Jun 2026 - 04:29 high IDS: SSH port scan — ET SCAN Potential SSH Scan
13 Jun 2026 - 04:29 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
12 Jun 2026 - 04:04 high IDS: SSH port scan — ET SCAN Potential SSH Scan
12 Jun 2026 - 04:03 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
11 Jun 2026 - 03:39 high IDS: SSH port scan — ET SCAN Potential SSH Scan
11 Jun 2026 - 03:39 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
10 Jun 2026 - 05:08 high IDS: SSH port scan — ET SCAN Potential SSH Scan
10 Jun 2026 - 05:08 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
9 Jun 2026 - 10:01 high IDS: SSH port scan — ET SCAN Potential SSH Scan
9 Jun 2026 - 10:01 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
8 Jun 2026 - 19:05 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
8 Jun 2026 - 19:05 high IDS: SSH port scan — ET SCAN Potential SSH Scan