Known botnet and C&C servers, these have responded with a valid botnet C2 response.
This is an active or recently TOR exit node, which is not inherently a threat, but may have been involved in attacks.
Systems that are infected with or involved in spreading malware and ransomware.
Threats are hosts that have attempted to exploit, brute force, or execute a denial of service attack. These are often compromised hosts.
|ISP||KeFF Networks Ltd|
|Organization||KeFF Networks Ltd|
|Hosted By||KeFF Networks Ltd|
|Threat Type||botnets malware threats|
|Blocked Since||2021-12-19 15:29:15|
|Last Threat||2022-05-18 18:29:25|
|Intel: HTTP Server|
|Intel: Powered By|
|Intel: SSH Server||SSH-2.0-OpenSSH_8.4p1 Debian-5|
|SENSE list (high risk)||Yes|
|One day public list||Yes|
|Seven day public list||Yes|
Threat History [last 14 days]
|2022-05-18 00:17:41||Internal||Threat score opinion changed to 79.|
|2022-05-14 01:00:19||Threats||Threats confirmation received.|
|2022-05-13 00:15:49||Internal||Threat score opinion changed to 79.|
|2022-05-11 00:15:35||Internal||Threat score opinion changed to 100.|
|2022-05-10 00:17:51||Internal||Threat score opinion changed to 92.|
|2022-05-10 00:15:48||Internal||Threat score opinion changed to 79.|
|2022-05-07 01:10:30||Threats||NovaSense attack detection triggered.|
|2022-05-07 00:37:00||Internal||Threat score opinion changed to 100.|
|2022-05-07 00:35:48||Probe||Discovered listed SSH daemon: SSH-2.0-OpenSSH_8.4p1 Debian-5|
|2022-05-07 00:34:59||Abusers||Abusers confirmation received.|
|2022-05-04 00:19:08||Internal||Threat score opinion changed to 79.|
|2022-05-02 00:19:52||Internal||Threat score opinion changed to 92.|
|2022-04-30 21:59:45||Threats||Threats confirmation received.|
|2022-04-30 21:29:24||Probe||Discovered listed SSH daemon: SSH-2.0-OpenSSH_8.4p1 Debian-5|
|2022-04-30 21:29:23||Botnets||Botnets confirmation received.|
|2022-04-30 21:02:38||Internal||Threat score opinion changed to 100.|
|2022-04-30 21:02:37||Probe||Discovered listed SSH daemon: SSH-2.0-OpenSSH_8.4p1 Debian-5|
|2022-04-30 21:02:33||Tor||Tor confirmation received.|
|2022-04-30 20:42:47||Probe||Discovered listed SSH daemon: SSH-2.0-OpenSSH_8.4p1 Debian-5|
|2022-04-30 20:42:47||Internal||Threat score opinion changed to 100.|
You may enter an IP address to check if it is blocked on NovaSense. If you have an IP address which is incorrectly blocked you may then request an exception.
Snapt users: you may whitelist IP addresses on your ADC to immediately ignore matches in NovaSense.