threat actor or compromised host
85% confidence
active
2 related incidents
18.116.101.220
Source interacted with a Sotiras honeypot decoy. Any contact with a decoy that advertises no legitimate service is unsolicited and treated as malicious.
Recommended action
Temporary Block based on approved public Sotiras intelligence.
First seen
Jun 16, 2026, 9:40 PM
Last seen
Jun 20, 2026, 2:29 PM
Activity window
4 days
Aggressiveness
How strongly the public evidence suggests active malicious behavior.
100/100
Background noise
How much routine scanning or low-value noise this source appears to generate.
59/100
Observed behavior
Public-safe behavior labels derived from approved aggregate evidence.
active-aggressors
Confidence reasons
Plain-language reasons behind the public Sotiras score.
- Sotiras has identified 2 related incidents tied to this IP in internal evidence.
- High confidence score from approved Sotiras evidence.
- Seen across 45 approved source records.
- Behavior includes active-aggressors.
- Suggested action is Temporary Block.
- High threat level after scoring.
Activity timeline
Recent public-safe observation volume by day.
- 2026-06-174
- 2026-06-1828
- 2026-06-2013
Aggregate evidence
Counts are grouped without exposing customer logs, hostnames, usernames, payloads, or tenant-specific routes.
Sources
- Honeypot45
Behaviors
- Honeypot Tcp Connect29
- Honeypot Fake Login8
- HTTP probing8
Ports
- 25/tcp29
- 80/tcp16
Countries
No public country groups.
Services
- tcp-banner29
- fake-login8
- web-route-trap8