threat actor or compromised host
85% confidence
active
67.209.176.50
Source interacted with a Sotiras honeypot decoy. Any contact with a decoy that advertises no legitimate service is unsolicited and treated as malicious.
Recommended action
Temporary Block based on approved public Sotiras intelligence.
First seen
Jun 20, 2026, 1:57 PM
Last seen
Jun 20, 2026, 1:57 PM
Activity window
1 hour
Aggressiveness
How strongly the public evidence suggests active malicious behavior.
92/100
Background noise
How much routine scanning or low-value noise this source appears to generate.
37/100
Observed behavior
Public-safe behavior labels derived from approved aggregate evidence.
active-aggressors
Confidence reasons
Plain-language reasons behind the public Sotiras score.
- High confidence score from approved Sotiras evidence.
- Behavior includes active-aggressors.
- Suggested action is Temporary Block.
- High threat level after scoring.
Activity timeline
Recent public-safe observation volume by day.
- 2026-06-201
Aggregate evidence
Counts are grouped without exposing customer logs, hostnames, usernames, payloads, or tenant-specific routes.
Sources
- Honeypot1
Behaviors
- HTTP probing1
Ports
- 80/tcp1
Countries
No public country groups.
Services
- web-route-trap1