threat actor or compromised host
85% confidence
active
204.76.203.206
Source interacted with a Sotiras honeypot decoy. Any contact with a decoy that advertises no legitimate service is unsolicited and treated as malicious.
Recommended action
Temporary Block based on approved public Sotiras intelligence.
First seen
Jun 7, 2026, 1:58 PM
Last seen
Jun 20, 2026, 2:16 PM
Activity window
13 days
Aggressiveness
How strongly the public evidence suggests active malicious behavior.
100/100
Background noise
How much routine scanning or low-value noise this source appears to generate.
70/100
Observed behavior
Public-safe behavior labels derived from approved aggregate evidence.
active-aggressors
Confidence reasons
Plain-language reasons behind the public Sotiras score.
- High confidence score from approved Sotiras evidence.
- Seen across 644 approved source records.
- Behavior includes active-aggressors.
- Suggested action is Temporary Block.
- High threat level after scoring.
Activity timeline
Recent public-safe observation volume by day.
- 2026-06-1544
- 2026-06-1646
- 2026-06-1744
- 2026-06-1839
- 2026-06-1942
- 2026-06-2035
Aggregate evidence
Counts are grouped without exposing customer logs, hostnames, usernames, payloads, or tenant-specific routes.
Sources
- Honeypot644
Behaviors
- Honeypot Fake Login323
- HTTP probing321
Ports
- 80/tcp644
Countries
No public country groups.
Services
- web-route-trap125
- fake-login125