threat actor or compromised host
85% confidence
active
138.124.242.51
Source interacted with a Sotiras honeypot decoy. Any contact with a decoy that advertises no legitimate service is unsolicited and treated as malicious.
Recommended action
Temporary Block based on approved public Sotiras intelligence.
First seen
Jun 11, 2026, 9:41 PM
Last seen
Jun 20, 2026, 2:11 PM
Activity window
9 days
Aggressiveness
How strongly the public evidence suggests active malicious behavior.
100/100
Background noise
How much routine scanning or low-value noise this source appears to generate.
70/100
Observed behavior
Public-safe behavior labels derived from approved aggregate evidence.
active-aggressors
Confidence reasons
Plain-language reasons behind the public Sotiras score.
- High confidence score from approved Sotiras evidence.
- Seen across 138 approved source records.
- Behavior includes active-aggressors.
- Suggested action is Temporary Block.
- High threat level after scoring.
Activity timeline
Recent public-safe observation volume by day.
- 2026-06-1292
- 2026-06-2046
Aggregate evidence
Counts are grouped without exposing customer logs, hostnames, usernames, payloads, or tenant-specific routes.
Sources
- Honeypot138
Behaviors
- HTTP probing123
- Honeypot Http Interaction12
- Honeypot Fake Login3
Ports
- 80/tcp138
Countries
No public country groups.
Services
- web-route-trap138