threat actor or compromised host
85% confidence
active
93.174.93.12
Source interacted with a Sotiras honeypot decoy. Any contact with a decoy that advertises no legitimate service is unsolicited and treated as malicious.
Recommended action
Temporary Block based on approved public Sotiras intelligence.
First seen
May 30, 2026, 10:16 AM
Last seen
Jun 20, 2026, 2:16 PM
Activity window
21 days
Aggressiveness
How strongly the public evidence suggests active malicious behavior.
100/100
Background noise
How much routine scanning or low-value noise this source appears to generate.
70/100
Observed behavior
Public-safe behavior labels derived from approved aggregate evidence.
active-aggressors
Confidence reasons
Plain-language reasons behind the public Sotiras score.
- High confidence score from approved Sotiras evidence.
- Seen across 123 approved source records.
- Behavior includes active-aggressors.
- Suggested action is Temporary Block.
- High threat level after scoring.
Activity timeline
Recent public-safe observation volume by day.
- 2026-06-075
- 2026-06-087
- 2026-06-096
- 2026-06-104
- 2026-06-118
- 2026-06-125
- 2026-06-137
- 2026-06-145
- 2026-06-156
- 2026-06-166
- 2026-06-176
- 2026-06-184
- 2026-06-196
- 2026-06-204
Aggregate evidence
Counts are grouped without exposing customer logs, hostnames, usernames, payloads, or tenant-specific routes.
Sources
- Honeypot123
Behaviors
- Honeypot Fake Login63
- HTTP probing60
Ports
- 80/tcp123
Countries
No public country groups.
Services
- fake-login63
- web-route-trap60