Sotiras AI
Public threat intelligence
threat actor or compromised host
85% confidence
active
2 related incidents

18.116.101.220

Source interacted with a Sotiras honeypot decoy. Any contact with a decoy that advertises no legitimate service is unsolicited and treated as malicious.

Recommended action

Temporary Block based on approved public Sotiras intelligence.

First seen

Jun 16, 2026, 9:40 PM

Last seen

Jun 20, 2026, 2:29 PM

Activity window

4 days

Aggressiveness

How strongly the public evidence suggests active malicious behavior.

100/100

Background noise

How much routine scanning or low-value noise this source appears to generate.

59/100

Observed behavior

Public-safe behavior labels derived from approved aggregate evidence.

active-aggressors

Confidence reasons

Plain-language reasons behind the public Sotiras score.

  • Sotiras has identified 2 related incidents tied to this IP in internal evidence.
  • High confidence score from approved Sotiras evidence.
  • Seen across 45 approved source records.
  • Behavior includes active-aggressors.
  • Suggested action is Temporary Block.
  • High threat level after scoring.

Activity timeline

Recent public-safe observation volume by day.

  • 2026-06-174
  • 2026-06-1828
  • 2026-06-2013

Aggregate evidence

Counts are grouped without exposing customer logs, hostnames, usernames, payloads, or tenant-specific routes.

Sources

  • Honeypot45

Behaviors

  • Honeypot Tcp Connect29
  • Honeypot Fake Login8
  • HTTP probing8

Ports

  • 25/tcp29
  • 80/tcp16

Countries

No public country groups.

Services

  • tcp-banner29
  • fake-login8
  • web-route-trap8