Sotiras AI
Public threat intelligence
threat actor or compromised host
85% confidence
active

93.174.93.12

Source interacted with a Sotiras honeypot decoy. Any contact with a decoy that advertises no legitimate service is unsolicited and treated as malicious.

Recommended action

Temporary Block based on approved public Sotiras intelligence.

First seen

May 30, 2026, 10:16 AM

Last seen

Jun 20, 2026, 2:16 PM

Activity window

21 days

Aggressiveness

How strongly the public evidence suggests active malicious behavior.

100/100

Background noise

How much routine scanning or low-value noise this source appears to generate.

70/100

Observed behavior

Public-safe behavior labels derived from approved aggregate evidence.

active-aggressors

Confidence reasons

Plain-language reasons behind the public Sotiras score.

  • High confidence score from approved Sotiras evidence.
  • Seen across 123 approved source records.
  • Behavior includes active-aggressors.
  • Suggested action is Temporary Block.
  • High threat level after scoring.

Activity timeline

Recent public-safe observation volume by day.

  • 2026-06-075
  • 2026-06-087
  • 2026-06-096
  • 2026-06-104
  • 2026-06-118
  • 2026-06-125
  • 2026-06-137
  • 2026-06-145
  • 2026-06-156
  • 2026-06-166
  • 2026-06-176
  • 2026-06-184
  • 2026-06-196
  • 2026-06-204

Aggregate evidence

Counts are grouped without exposing customer logs, hostnames, usernames, payloads, or tenant-specific routes.

Sources

  • Honeypot123

Behaviors

  • Honeypot Fake Login63
  • HTTP probing60

Ports

  • 80/tcp123

Countries

No public country groups.

Services

  • fake-login63
  • web-route-trap60