// public entity intelligence
77.239.124.235
Evidence summary
Researcher feed observations and neutral DNS history are counted separately.
Tags
Sources
Observed 2347 times. Targeted ports: 22. Country: The Netherlands. Reputation: known attacker. Alert categories: Generic Protocol Command Decode, Misc activity. Signatures: ET INFO SSH session in progress on Expected Port, SURICATA STREAM Packet with invalid timestamp, SURICATA STREAM spurious retransmission. Usernames: a, aaa, admin, admin1, admin123 and 115 more.
| Indicator | Type | Tag | Source | Last seen |
|---|---|---|---|---|
| 77.239.124.235 | ip | honeypot, historical | 2026-08-20 14:26:06 | |
Honeypot infrastructure watch: Observed 2347 times. Targeted ports: 22. Country: The Netherlands. Reputation: known attacker. Alert categories: Generic Protocol Command Decode, Misc activity. Signatures: ET INFO SSH session in progress on Expected Port, SURICATA STREAM Packet with invalid timestamp, SURICATA STREAM spurious retransmission. Usernames: a, aaa, admin, admin1, admin123 and 115 more. | ||||
Related hosts and IPs
Public passive DNS relationships connected to this exact indicator.
No passive DNS rows match this value.
Network ownership
BGP origin and registry data from Team Cymru.
This indicator was added to the neutral entity index. A background worker is processing it now; refresh shortly to see the result.
Popularity
Daily link and hosting prominence from top1m.org; not a security verdict or traffic estimate.
Not present in the current Top 1M lists.
Take this investigation further
1 public feed match. Private searches stay out of Latest searches. Each private app search costs 1 CTIDAO.