threat actor or compromised host
85% confidence
active
66.132.195.58
Source interacted with a Sotiras honeypot decoy. Any contact with a decoy that advertises no legitimate service is unsolicited and treated as malicious.
Recommended action
Temporary Block based on approved public Sotiras intelligence.
First seen
Jun 20, 2026, 1:56 PM
Last seen
Jun 20, 2026, 1:56 PM
Activity window
1 hour
Aggressiveness
How strongly the public evidence suggests active malicious behavior.
92/100
Background noise
How much routine scanning or low-value noise this source appears to generate.
37/100
Observed behavior
Public-safe behavior labels derived from approved aggregate evidence.
active-aggressors
Confidence reasons
Plain-language reasons behind the public Sotiras score.
- High confidence score from approved Sotiras evidence.
- Behavior includes active-aggressors.
- Suggested action is Temporary Block.
- High threat level after scoring.
Activity timeline
Recent public-safe observation volume by day.
- 2026-06-201
Aggregate evidence
Counts are grouped without exposing customer logs, hostnames, usernames, payloads, or tenant-specific routes.
Sources
- Honeypot1
Behaviors
- Honeypot Tcp Connect1
Ports
- 25/tcp1
Countries
No public country groups.
Services
- tcp-banner1