Sotiras AI
Public threat intelligence
Threat intelligence
Public lookup

Search an IP address seen in your logs.

Sotiras publishes privacy-safe intelligence for selected active IPs observed through honeypots, collectors, server logs, and public-facing services.

IP reputation lookup

Enter a public IPv4 or IPv6 address from a firewall, fail2ban, WordPress event, honeypot, or server log.

Public IPs
13,242
6,121 high or critical IPs in scope
Events
0
Last 14 days of public-safe observations
Attack types
0
Grouped from normalized event types
Countries
0
May 10, 2026 - Jul 14, 2026

Event heat map

Public-safe observation density by UTC day and hour. Darker cells mean more events.

Peak cell 1
12AM
3AM
6AM
9AM
12PM
3PM
6PM
9PM
Jul 250
Jul 260
Jul 270
Jul 280
Jul 290
Jul 300
Jul 310

Top IPs

IPs with the most public-safe observations in the current window.

No aggregate rows are available yet.

Attack types

Normalized behavior categories seen across published intelligence.

No aggregate rows are available yet.

Countries

Observed source geography after enrichment, grouped for public display.

No aggregate rows are available yet.

Targeted services

Ports and services most often touched by observed traffic.

No aggregate rows are available yet.

Source mix

Collector and telemetry families contributing aggregate evidence.

No aggregate rows are available yet.

Categories

Public blocklist and behavior labels associated with listed IPs.

Active Aggressors8,257
Ssh Bruteforce4,172

Privacy-safe by design

Public pages show aggregate behavior, source mix, timing, and recommended action. They do not publish customer logs, hostnames, usernames, payloads, or tenant-specific evidence.

Connect your signals

Sotiras can correlate public IP intelligence with your WordPress, Linux server, firewall, nginx, Apache, VoIP, and application logs after you connect a collector.

Recently published indicators

Active IPs with approved public intelligence or anonymized Sotiras aggregate evidence.

18.116.101.220
Last seen Jun 20, 2026
threat actor or compromised host
85% confidence
active-aggressors

Source interacted with a Sotiras honeypot decoy. Any contact with a decoy that advertises no legitimate service is unsolicited and treated as malicious.

204.76.203.206
Last seen Jun 20, 2026
threat actor or compromised host
85% confidence
active-aggressors

Source interacted with a Sotiras honeypot decoy. Any contact with a decoy that advertises no legitimate service is unsolicited and treated as malicious.

93.174.93.12
Last seen Jun 20, 2026
threat actor or compromised host
85% confidence
active-aggressors

Source interacted with a Sotiras honeypot decoy. Any contact with a decoy that advertises no legitimate service is unsolicited and treated as malicious.

138.124.242.51
Last seen Jun 20, 2026
threat actor or compromised host
85% confidence
active-aggressors

Source interacted with a Sotiras honeypot decoy. Any contact with a decoy that advertises no legitimate service is unsolicited and treated as malicious.

67.209.176.50
Last seen Jun 20, 2026
threat actor or compromised host
85% confidence
active-aggressors

Source interacted with a Sotiras honeypot decoy. Any contact with a decoy that advertises no legitimate service is unsolicited and treated as malicious.

66.132.195.58
Last seen Jun 20, 2026
threat actor or compromised host
85% confidence
active-aggressors

Source interacted with a Sotiras honeypot decoy. Any contact with a decoy that advertises no legitimate service is unsolicited and treated as malicious.

205.210.31.215
Last seen Jun 20, 2026
threat actor or compromised host
85% confidence
active-aggressors

Source interacted with a Sotiras honeypot decoy. Any contact with a decoy that advertises no legitimate service is unsolicited and treated as malicious.

43.157.46.118
Last seen Jun 20, 2026
threat actor or compromised host
85% confidence
active-aggressors

Source interacted with a Sotiras honeypot decoy. Any contact with a decoy that advertises no legitimate service is unsolicited and treated as malicious.