Skip to content
COOEY

◄ SITREP

GLOBAL THREAT POSTURE

LIVE

Live global posture — geolocated threat events (outages, attacks, DDoS, ransomware, C2, scans) fused across sources, with a DEFCON level derived from the intel pipeline's own correlated escalations.

LIVE THREAT STREAM streaming · SSE
◈ Connected — awaiting pushed events from the intel stream…
Global DEFCON
1
SEVERE
25 SEVERE (DEFCON-1) escalations active
Global events processed
29,290,475
prevailing recent level · live counter
GLOBAL POSTURE VECTOR signal fusion →
MALWARE_URL · high · TW — Malware URL: 210.208.110.21 (malware_download)COMPROMISED_HOST · high · CN — Compromised: 101.96.192.88C2_SERVER · critical · CN — Cobaltstrike: 101.133.229.117BREACH · high · ? — Breach: GolfCanada (569k accounts)BREACH · high · ? — Breach: Fanlore (145k accounts)COMPROMISED_HOST · high · PK — Compromised: 101.50.83.146MALWARE_URL · high · PK — Malware URL: 72.255.30.244 (malware_download)C2_SERVER · critical · CN — Cobaltstrike: 101.126.10.34BREACH · critical · ? — Breach: ExactSciences (10870k accounts)BREACH · high · ? — Breach: BrinksHome (732k accounts)COMPROMISED_HOST · high · SG — Compromised: 101.100.216.61MALWARE_URL · high · SE — Malware URL: 185.205.226.191 (malware_download)C2_SERVER · critical · CN — Cobaltstrike: 1.15.76.39BREACH · high · ? — Breach: Alcon (218k accounts)OUTAGE · critical · PK · Nayatel (Pvt) Ltd — NAYATEL-PK -- Punjab — ping-slash24 criticalDDOS_ORIGIN · high · US — CF Radar: US top DDoS L7 origin (22.3% of global)DDOS_ORIGIN · high · BR — CF Radar: BR top DDoS L3 origin (14.2% of global)OUTAGE · critical · PK · Nayatel (Pvt) Ltd — NAYATEL-PK -- Punjab — ping-slash24 criticalOUTAGE · critical · PK · Nayatel (Pvt) Ltd — NAYATEL-PK -- Punjab — ping-slash24 criticalOUTAGE · critical · CN · BEIJING GEHUA CATV NETWORK CO.LTD — BGCTVNET -- China — ping-slash24 criticalOUTAGE · critical · CN · BEIJING GEHUA CATV NETWORK CO.LTD — AS17429 (BGCTVNET) — ping-slash24 criticalDDOS_ORIGIN · high · US — CF Radar: US top DDoS L7 origin (22.3% of global)DDOS_ORIGIN · high · BR — CF Radar: BR top DDoS L3 origin (14.2% of global)MALICIOUS_SCAN · high · SG — urlscan: nst-study-dp0a2pk0rl9x.edgeone.dev (phishing, malicious)MALICIOUS_SCAN · high · SG — urlscan: eager-teal-y5rcx44y-dpco632xczgj.edgeone.dev (phishing, malicious)MALICIOUS_SCAN · high · SG — urlscan: yappiest-silver-wdqst59k-dprv31sf9bt6.edgeone.dev (phishing, malicious)MALICIOUS_SCAN · high · SG — urlscan: prepared-tan-smeq5bd0-dpbgh99qublx.edgeone.dev (phishing, malicious)ATTACK · high · NL — Top attacker: 52.157.207.201 (195k reports)MALICIOUS_SCAN · high · SG — urlscan: different-lime-wjexf4qi-dpsj7j539qyx.edgeone.dev (phishing, malicious)ATTACK · high · ES — Top attacker: 194.224.249.214 (310k reports)MALICIOUS_SCAN · high · SG — urlscan: causal-azure-9hq8d3zt-dpuspqqwca3a.edgeone.dev (phishing, malicious)ATTACK · high · NL — Top attacker: 13.94.254.200 (320k reports)MALICIOUS_SCAN · high · SG — urlscan: magic-sapphire-td2fox1e-dpq1cmpr2vwd.edgeone.dev (phishing, malicious)C2_SERVER · critical · US — LIVE C2: 50.16.16.211:443 (QakBot)OUTAGE · critical · PK · Nayatel (Pvt) Ltd — NAYATEL-PK -- Punjab — ping-slash24 criticalOUTAGE · critical · CN · BEIJING GEHUA CATV NETWORK CO.LTD — BGCTVNET -- China — ping-slash24 criticalOUTAGE · critical · CN · BEIJING GEHUA CATV NETWORK CO.LTD — AS17429 (BGCTVNET) — ping-slash24 criticalOUTAGE · critical · CN · BEIJING GEHUA CATV NETWORK CO.LTD — BGCTVNET -- China — ping-slash24 criticalOUTAGE · critical · CN · BEIJING GEHUA CATV NETWORK CO.LTD — AS17429 (BGCTVNET) — ping-slash24 criticalDDOS_ORIGIN · high · US — CF Radar: US top DDoS L7 origin (22.3% of global)DDOS_ORIGIN · high · BR — CF Radar: BR top DDoS L3 origin (14.2% of global)OUTAGE · critical · CN · BEIJING GEHUA CATV NETWORK CO.LTD — AS17429 (BGCTVNET) — ping-slash24 criticalOUTAGE · critical · CN · BEIJING GEHUA CATV NETWORK CO.LTD — BGCTVNET -- China — ping-slash24 criticalOUTAGE · critical · US · Summit Broadband — ORLANDOTELCO -- United States — ping-slash24 criticalDDOS_ORIGIN · high · US — CF Radar: US top DDoS L7 origin (22.3% of global)DDOS_ORIGIN · high · BR — CF Radar: BR top DDoS L3 origin (13.8% of global)OUTAGE · critical · US · Summit Broadband — ORLANDOTELCO -- United States — ping-slash24 criticalOUTAGE · critical · ZA · Vodacom — VODACOM-ZA -- South Africa — ping-slash24 criticalOUTAGE · critical · ZA · Vodacom — VODACOM-ZA -- Gauteng — ping-slash24 criticalOUTAGE · critical · ZA · Vodacom — AS29975 (VODACOM-ZA) — ping-slash24 criticalDDOS_ORIGIN · high · US — CF Radar: US top DDoS L7 origin (22.3% of global)DDOS_ORIGIN · high · BR — CF Radar: BR top DDoS L3 origin (13.8% of global)MALICIOUS_SCAN · high · SG — urlscan: tall-blue-6qqslukx-dpcjrne4laxj.edgeone.dev (phishing, malicious)MALICIOUS_SCAN · high · SG — urlscan: poised-azure-zvw1ljg8-dpscowlyceap.edgeone.dev (phishing, malicious)MALICIOUS_SCAN · high · SG — urlscan: due-olive-pwmpb7gm-dpetyt7w4p32.edgeone.dev (phishing, malicious)MALICIOUS_SCAN · high · SG — urlscan: clear-copper-lipvkfpb-dpiq16uv6acf.edgeone.dev (phishing, malicious)MALICIOUS_SCAN · high · SG — urlscan: petite-indigo-6akhqvzz-dpo25ao2pa4o.edgeone.dev (phishing, malicious)MALICIOUS_SCAN · high · SG — urlscan: silky-sapphire-dzpl2m2z-dp000y4g4ebx.edgeone.dev (phishing, malicious)ATTACK · high · NL — Top attacker: 52.157.207.201 (195k reports)MALICIOUS_SCAN · high · SG — urlscan: experimental-bronze-5dkpucg9-dpcac5yzn1qk.edgeone.dev (phishing, malicious)ATTACK · high · ES — Top attacker: 194.224.249.214 (310k reports)MALICIOUS_SCAN · high · SG — urlscan: partial-maroon-gujyly5w-dplqykjp48vc.edgeone.dev (phishing, malicious)ATTACK · high · NL — Top attacker: 13.94.254.200 (320k reports)C2_SERVER · critical · US — LIVE C2: 50.16.16.211:443 (QakBot)OUTAGE · critical · ZA · Vodacom — VODACOM-ZA -- South Africa — ping-slash24 criticalOUTAGE · critical · ZA · Vodacom — VODACOM-ZA -- Gauteng — ping-slash24 criticalOUTAGE · critical · ZA · Vodacom — AS29975 (VODACOM-ZA) — ping-slash24 criticalOUTAGE · critical · ZA · Vodacom — VODACOM-ZA -- Gauteng — ping-slash24 criticalOUTAGE · critical · ZA · Vodacom — VODACOM-ZA -- South Africa — ping-slash24 criticalOUTAGE · critical · ZA · Vodacom — AS29975 (VODACOM-ZA) — ping-slash24 criticalDDOS_ORIGIN · high · US — CF Radar: US top DDoS L7 origin (22.3% of global)DDOS_ORIGIN · high · BR — CF Radar: BR top DDoS L3 origin (13.8% of global)OUTAGE · critical · ZA · Vodacom — VODACOM-ZA -- Gauteng — ping-slash24 criticalOUTAGE · critical · ZA · Vodacom — VODACOM-ZA -- South Africa — ping-slash24 criticalOUTAGE · critical · ZA · Vodacom — AS29975 (VODACOM-ZA) — ping-slash24 criticalMALWARE_URL · high · TR — Malware URL: 95.9.35.137 (malware_download)COMPROMISED_HOST · high · HK — Compromised: 103.194.106.230MALWARE_URL · high · CN — Malware URL: 222.138.116.230 (malware_download)COMPROMISED_HOST · high · IN — Compromised: 103.19.196.230C2_SERVER · critical · CN — Cobaltstrike: 101.43.103.154MALWARE_URL · high · TR — Malware URL: 95.9.35.137 (malware_download)COMPROMISED_HOST · high · IN — Compromised: 103.159.85.90C2_SERVER · critical · CN — Cobaltstrike: 101.42.255.92MALWARE_URL · high · CN — Malware URL: 113.230.83.154 (malware_download)COMPROMISED_HOST · high · SI — Compromised: 102.220.160.38C2_SERVER · critical · CN — Cobaltstrike: 101.33.225.32BREACH · critical · ? — Breach: OzHairAndBeauty (1988k accounts)MALWARE_URL · high · CN — Malware URL: 123.13.1.98 (malware_download)COMPROMISED_HOST · high · SI — Compromised: 102.220.160.172C2_SERVER · critical · CN — Cobaltstrike: 101.200.193.211BREACH · high · ? — Breach: InterConSecurity (276k accounts)BREACH · high · ? — Breach: HoustonCityCollege (832k accounts)MALWARE_URL · high · CN — Malware URL: 123.13.1.98 (malware_download)COMPROMISED_HOST · high · CN — Compromised: 101.96.192.88C2_SERVER · critical · CN — Cobaltstrike: 101.133.229.117BREACH · high · ? — Breach: GolfCanada (569k accounts)BREACH · high · ? — Breach: Fanlore (145k accounts)MALWARE_URL · high · CN — Malware URL: 42.227.205.122 (malware_download)COMPROMISED_HOST · high · PK — Compromised: 101.50.83.146C2_SERVER · critical · CN — Cobaltstrike: 101.126.10.34BREACH · critical · ? — Breach: ExactSciences (10870k accounts)BREACH · high · ? — Breach: BrinksHome (732k accounts)MALWARE_URL · high · CN — Malware URL: 27.152.11.30 (malware_download)COMPROMISED_HOST · high · SG — Compromised: 101.100.216.61C2_SERVER · critical · CN — Cobaltstrike: 1.15.76.39BREACH · high · ? — Breach: Alcon (218k accounts)OUTAGE · critical · ZA · Vodacom — AS29975 (VODACOM-ZA) — ping-slash24 criticalDDOS_ORIGIN · high · US — CF Radar: US top DDoS L7 origin (22.3% of global)DDOS_ORIGIN · high · BR — CF Radar: BR top DDoS L3 origin (13.8% of global)OUTAGE · critical · ZA · Vodacom — AS29975 (VODACOM-ZA) — ping-slash24 criticalDDOS_ORIGIN · high · US — CF Radar: US top DDoS L7 origin (22.3% of global)DDOS_ORIGIN · high · BR — CF Radar: BR top DDoS L3 origin (13.8% of global)MALICIOUS_SCAN · high · SG — urlscan: delicate-yellow-ph6hmpw0-dpqxyfzs6o0k.edgeone.dev (phishing, malicious)MALICIOUS_SCAN · high · SG — urlscan: famconnect-dp5z32w7jlkk.edgeone.dev (phishing, malicious)MALICIOUS_SCAN · high · SG — urlscan: manwali-dpxhno4dmgvb.edgeone.dev (phishing, malicious)MALICIOUS_SCAN · high · SG — urlscan: amateur-copper-hjzpmdwi-dpafnqg6ab61.edgeone.dev (phishing, malicious)ATTACK · high · NL — Top attacker: 52.157.207.201 (195k reports)MALICIOUS_SCAN · high · SG — urlscan: driftzen-dpaae590o5j3.edgeone.dev (phishing, malicious)ATTACK · high · ES — Top attacker: 194.224.249.214 (310k reports)MALICIOUS_SCAN · high · SG — urlscan: stuck-pink-vnrgewok-dpek5gd6bpfv.edgeone.dev (phishing, malicious)ATTACK · high · NL — Top attacker: 13.94.254.200 (320k reports)MALICIOUS_SCAN · high · SG — urlscan: pengembalian-paylater-tiktok-dpm1z76zzjgi.edgeone.dev (phishing, malicious)C2_SERVER · critical · US — LIVE C2: 50.16.16.211:443 (QakBot)OUTAGE · critical · FI · Telia Cygate Oy — NBLNETWORKS-AS -- Finland — ping-slash24 criticalDDOS_ORIGIN · high · US — CF Radar: US top DDoS L7 origin (22.3% of global)DDOS_ORIGIN · high · BR — CF Radar: BR top DDoS L3 origin (13.8% of global)OUTAGE · critical · FI · Telia Cygate Oy — NBLNETWORKS-AS -- Finland — ping-slash24 criticalOUTAGE · critical · FI · Telia Cygate Oy — NBLNETWORKS-AS -- Finland — ping-slash24 criticalDDOS_ORIGIN · high · US — CF Radar: US top DDoS L7 origin (22.3% of global)DDOS_ORIGIN · high · BR — CF Radar: BR top DDoS L3 origin (13.8% of global)OUTAGE · critical · FI · Telia Cygate Oy — NBLNETWORKS-AS -- Finland — ping-slash24 criticalREPUTATION · critical · AD — IPsum: 193.47.62.69 (score 8/10+)REPUTATION · critical · VN — IPsum: 103.78.2.252 (score 8/10+)HONEYPOT · high · TH — CINS Honeypot: 1.20.163.53REPUTATION · critical · TH — IPsum: 101.51.157.107 (score 8/10+)PHISHING · high · US — Phishing: www.trustwalletmycard.vercel.appHONEYPOT · high · CN — CINS Honeypot: 1.197.94.77REPUTATION · critical · DE — IPsum: 85.239.149.72 (score 8/10+)PHISHING · high · US — Phishing: www.loginnews.vercel.appHONEYPOT · high · CN — CINS Honeypot: 1.197.139.151REPUTATION · critical · NL — IPsum: 80.82.77.33 (score 8/10+)PHISHING · high · US — Phishing: www.instagram-login-authentication.duckdns.orgREPUTATION · critical · NL — IPsum: 77.239.124.108 (score 8/10+)HONEYPOT · high · CN — CINS Honeypot: 1.193.63.32PHISHING · high · CL — Phishing: 283d48.icefactory.clHONEYPOT · high · CN — CINS Honeypot: 1.193.63.197REPUTATION · critical · NL — IPsum: 77.239.124.102 (score 8/10+)PHISHING · high · CL — Phishing: a8aeb8.icefactory.clHONEYPOT · high · CN — CINS Honeypot: 1.193.63.11REPUTATION · critical · DE — IPsum: 77.90.185.20 (score 8/10+)PHISHING · high · CL — Phishing: 43643c.icefactory.clREPUTATION · critical · IR — IPsum: 62.60.130.253 (score 9/10+)HONEYPOT · high · CN — CINS Honeypot: 1.180.247.82PHISHING · high · CL — Phishing: 4ec655.icefactory.clREPUTATION · critical · IR — IPsum: 62.60.130.242 (score 9/10+)HONEYPOT · high · CN — CINS Honeypot: 1.15.227.58OUTAGE · critical · FI · Telia Cygate Oy — NBLNETWORKS-AS -- Finland — ping-slash24 criticalDDOS_ORIGIN · high · US — CF Radar: US top DDoS L7 origin (22.3% of global)DDOS_ORIGIN · high · BR — CF Radar: BR top DDoS L3 origin (13.8% of global)MALICIOUS_SCAN · high · SG — urlscan: identical-bronze-fopswb87-dpfys77zjd0s.edgeone.dev (phishing, malicious)MALICIOUS_SCAN · high · SG — urlscan: quickest-sapphire-mfkrtrvs-dppq1ih0uz87.edgeone.dev (phishing, malicious)MALICIOUS_SCAN · high · SG — urlscan: accused-gold-tot15xqk-dpm8gj9936ru.edgeone.dev (phishing, malicious)MALICIOUS_SCAN · high · SG — urlscan: whole-aqua-npnomnmr-dpv8su4o507v.edgeone.dev (phishing, malicious)ATTACK · high · NL — Top attacker: 52.157.207.201 (195k reports)MALICIOUS_SCAN · high · SG — urlscan: vertical-blue-4wm8i7bm-dp3zga9qq6gl.edgeone.dev (phishing, malicious)ATTACK · high · ES — Top attacker: 194.224.249.214 (310k reports)MALICIOUS_SCAN · high · SG — urlscan: stiks-dpfbi58cugnu.edgeone.dev (phishing, malicious)ATTACK · high · NL — Top attacker: 13.94.254.200 (320k reports)MALICIOUS_SCAN · high · SG — urlscan: inc-amber-xprzaalr-dpsalnpv2u19.edgeone.dev (phishing, malicious)C2_SERVER · critical · US — LIVE C2: 50.16.16.211:443 (QakBot)OUTAGE · critical · FI · Telia Cygate Oy — NBLNETWORKS-AS -- Finland — ping-slash24 criticalDDOS_ORIGIN · high · US — CF Radar: US top DDoS L7 origin (22.3% of global)DDOS_ORIGIN · high · BR — CF Radar: BR top DDoS L3 origin (13.8% of global)COMPROMISED_HOST · high · HK — Compromised: 103.194.106.230MALWARE_URL · high · CN — Malware URL: 182.126.124.102 (malware_download)MALWARE_URL · high · CN — Malware URL: 222.138.116.230 (malware_download)COMPROMISED_HOST · high · IN — Compromised: 103.19.196.230C2_SERVER · critical · CN — Cobaltstrike: 101.43.103.154MALWARE_URL · high · CN — Malware URL: 182.126.124.102 (malware_download)COMPROMISED_HOST · high · IN — Compromised: 103.159.85.90C2_SERVER · critical · CN — Cobaltstrike: 101.42.255.92MALWARE_URL · high · CN — Malware URL: 219.154.188.157 (malware_download)COMPROMISED_HOST · high · SI — Compromised: 102.220.160.38C2_SERVER · critical · CN — Cobaltstrike: 101.33.225.32BREACH · critical · ? — Breach: OzHairAndBeauty (1988k accounts)MALWARE_URL · high · TR — Malware URL: 95.9.35.137 (malware_download)COMPROMISED_HOST · high · SI — Compromised: 102.220.160.172BREACH · high · ? — Breach: InterConSecurity (276k accounts)C2_SERVER · critical · CN — Cobaltstrike: 101.200.193.211BREACH · high · ? — Breach: HoustonCityCollege (832k accounts)MALWARE_URL · high · CN — Malware URL: 222.138.116.230 (malware_download)COMPROMISED_HOST · high · CN — Compromised: 101.96.192.88BREACH · high · ? — Breach: GolfCanada (569k accounts)C2_SERVER · critical · CN — Cobaltstrike: 101.133.229.117BREACH · high · ? — Breach: Fanlore (145k accounts)MALWARE_URL · high · TR — Malware URL: 95.9.35.137 (malware_download)COMPROMISED_HOST · high · PK — Compromised: 101.50.83.146C2_SERVER · critical · CN — Cobaltstrike: 101.126.10.34BREACH · critical · ? — Breach: ExactSciences (10870k accounts)BREACH · high · ? — Breach: BrinksHome (732k accounts)MALWARE_URL · high · CN — Malware URL: 113.230.83.154 (malware_download)COMPROMISED_HOST · high · SG — Compromised: 101.100.216.61C2_SERVER · critical · CN — Cobaltstrike: 1.15.76.39BREACH · high · ? — Breach: Alcon (218k accounts)OUTAGE · critical · SE · Internet Vikings International AB — INTERNETBOLAGET -- Sweden — ping-slash24 criticalDDOS_ORIGIN · high · US — CF Radar: US top DDoS L7 origin (22.3% of global)DDOS_ORIGIN · high · BR — CF Radar: BR top DDoS L3 origin (13.8% of global)OUTAGE · critical · SE · Internet Vikings International AB — INTERNETBOLAGET -- Sweden — ping-slash24 criticalOUTAGE · critical · SE · Internet Vikings International AB — INTERNETBOLAGET -- Sweden — ping-slash24 criticalDDOS_ORIGIN · high · US — CF Radar: US top DDoS L7 origin (22.3% of global)DDOS_ORIGIN · high · BR — CF Radar: BR top DDoS L3 origin (13.8% of global)MALICIOUS_SCAN · high · SG — urlscan: delicious-purple-1iz5aczb-dpqojqvey16q.edgeone.dev (phishing, malicious)MALICIOUS_SCAN · high · SG — urlscan: real-aqua-cfcefsgf-dpo5ypvdds1p.edgeone.dev (phishing, malicious)MALICIOUS_SCAN · high · SG — urlscan: regulatory-amaranth-1kpgcus3-dps8k9fcr4fd.edgeone.dev (phishing, malicious)MALICIOUS_SCAN · high · SG — urlscan: dependent-scarlet-i2py42fg-dposrbkgaysz.edgeone.dev (phishing, malicious)ATTACK · high · NL — Top attacker: 52.157.207.201 (195k reports)MALICIOUS_SCAN · high · SG — urlscan: involved-magenta-05p534to-dpm2mzn0rj0m.edgeone.dev (phishing, malicious)ATTACK · high · ES — Top attacker: 194.224.249.214 (310k reports)MALICIOUS_SCAN · high · SG — urlscan: quick-violet-dubqxp2s-dpjyxququtwh.edgeone.dev (phishing, malicious)ATTACK · high · NL — Top attacker: 13.94.254.200 (320k reports)MALICIOUS_SCAN · high · SG — urlscan: nanandsh-dp9nzsa0lgnv.edgeone.dev (phishing, malicious)C2_SERVER · critical · US — LIVE C2: 50.16.16.211:443 (QakBot)OUTAGE · critical · SE · Internet Vikings International AB — INTERNETBOLAGET -- Sweden — ping-slash24 criticalOUTAGE · critical · IR · NOAVARAN SHABAKEH SABZ MEHREGAN (Ltd.) — Hostiran-Network -- Iran (Islamic Republic Of) — ping-slash24 criticalOUTAGE · critical · IR · NOAVARAN SHABAKEH SABZ MEHREGAN (Ltd.) — Hostiran-Network -- Fars — ping-slash24 criticalOUTAGE · critical · IR · NOAVARAN SHABAKEH SABZ MEHREGAN (Ltd.) — AS59441 (Hostiran-Network) — ping-slash24 criticalDDOS_ORIGIN · high · US — CF Radar: US top DDoS L7 origin (22.3% of global)DDOS_ORIGIN · high · BR — CF Radar: BR top DDoS L3 origin (13.8% of global)OUTAGE · critical · SE · Internet Vikings International AB — INTERNETBOLAGET -- Sweden — ping-slash24 criticalOUTAGE · critical · IR · NOAVARAN SHABAKEH SABZ MEHREGAN (Ltd.) — Hostiran-Network -- Fars — ping-slash24 criticalOUTAGE · critical · IR · NOAVARAN SHABAKEH SABZ MEHREGAN (Ltd.) — Hostiran-Network -- Iran (Islamic Republic Of) — ping-slash24 criticalOUTAGE · critical · IR · NOAVARAN SHABAKEH SABZ MEHREGAN (Ltd.) — AS59441 (Hostiran-Network) — ping-slash24 criticalOUTAGE · critical · CN · SiChuan XunYou Network Technologe Limit, co — AS146834 (XunYou) — bgp criticalDDOS_ORIGIN · high · US — CF Radar: US top DDoS L7 origin (22.2% of global)DDOS_ORIGIN · high · BR — CF Radar: BR top DDoS L3 origin (13.5% of global)OUTAGE · critical · CN · SiChuan XunYou Network Technologe Limit, co — AS146834 (XunYou) — bgp criticalOUTAGE · critical · CN · GDS CHANGAN SERVICES Ltd. — AS45079 (GDSNET) — bgp criticalOUTAGE · critical · CN · Beijing Internet Harbor Technology Co., Ltd — AS56282 (VClouD) — bgp criticalOUTAGE · critical · CN · Beijing Kingsoft Cloud Internet Technology Co., Ltd — AS59019 (BJKSCNET) — bgp criticalOUTAGE · critical · CN · 21vianet(China) Inc. — AS17428 (CHINA-ABITCOOL) — bgp criticalOUTAGE · critical · CN · Guangzhou navigation information technology co., LTD — AS59045 (SUNHONGS) — bgp criticalOUTAGE · critical · CN · China Telecom (Group) — AS4816 (CHINANET-IDC-GD) — bgp criticalOUTAGE · critical · CN · Huawei — AS55990 (HWCSNET) — bgp criticalOUTAGE · critical · GB · Box Broadband Limited — box-broadband -- United Kingdom — ping-slash24 criticalDDOS_ORIGIN · high · US — CF Radar: US top DDoS L7 origin (22.3% of global)DDOS_ORIGIN · high · BR — CF Radar: BR top DDoS L3 origin (13.5% of global)MALICIOUS_SCAN · high · SG — urlscan: tame-turquoise-d1wbs9jr-dpozsnn2ndse.edgeone.dev (phishing, malicious)MALICIOUS_SCAN · high · SG — urlscan: ok-amber-b7xggxjz-dpc2kbdsiwpq.edgeone.dev (phishing, malicious)MALICIOUS_SCAN · high · SG — urlscan: estimated-harlequin-gbxysoim-dp2cxemvm4m8.edgeone.dev (phishing, malicious)MALICIOUS_SCAN · high · SG — urlscan: global-bronze-gcnhbrub-dprjahr6ucqf.edgeone.dev (phishing, malicious)MALICIOUS_SCAN · high · SG — urlscan: liable-blush-5v6vs2m7-dphlg7msg9mf.edgeone.dev (phishing, malicious)ATTACK · high · NL — Top attacker: 52.157.207.201 (195k reports)MALICIOUS_SCAN · high · SG — urlscan: amadeussocialchatiind-dp9upt3nn5cz.edgeone.dev (phishing, malicious)ATTACK · high · ES — Top attacker: 194.224.249.214 (310k reports)MALICIOUS_SCAN · high · SG — urlscan: stingy-crimson-wqfrcxvz-dphbqq0v9g61.edgeone.dev (phishing, malicious)ATTACK · high · NL — Top attacker: 13.94.254.200 (320k reports)MALICIOUS_SCAN · high · SG — urlscan: uncertain-azure-0c0crkdk-dprw9vsujkpg.edgeone.dev (phishing, malicious)C2_SERVER · critical · US — LIVE C2: 50.16.16.211:443 (QakBot)OUTAGE · critical · SE · Internet Vikings International AB — INTERNETBOLAGET -- Sweden — ping-slash24 criticalOUTAGE · critical · FI · Telia Cygate Oy — NBLNETWORKS-AS -- Finland — ping-slash24 criticalOUTAGE · critical · PL · EURONET NORBERT SANIEWSKI SPOLKA JAWNA — EURONET-AS -- Poland — ping-slash24 criticalOUTAGE · critical · FI · Telia Cygate Oy — NBLNETWORKS-AS -- Finland — ping-slash24 criticalOUTAGE · critical · SE · Internet Vikings International AB — INTERNETBOLAGET -- Sweden — ping-slash24 criticalDDOS_ORIGIN · high · US — CF Radar: US top DDoS L7 origin (22.2% of global)DDOS_ORIGIN · high · BR — CF Radar: BR top DDoS L3 origin (13.5% of global)COMPROMISED_HOST · high · HK — Compromised: 103.194.106.230MALWARE_URL · high · CN — Malware URL: 115.58.88.6 (malware_download)COMPROMISED_HOST · high · IN — Compromised: 103.19.196.230C2_SERVER · critical · CN — Cobaltstrike: 101.43.103.154MALWARE_URL · high · CN — Malware URL: 175.169.60.91 (malware_download)COMPROMISED_HOST · high · IN — Compromised: 103.159.85.90C2_SERVER · critical · CN — Cobaltstrike: 101.42.255.92MALWARE_URL · high · CN — Malware URL: 175.169.60.91 (malware_download)COMPROMISED_HOST · high · SI — Compromised: 102.220.160.38C2_SERVER · critical · CN — Cobaltstrike: 101.33.225.32MALWARE_URL · high · CN — Malware URL: 115.50.3.162 (malware_download)BREACH · critical · ? — Breach: OzHairAndBeauty (1988k accounts)COMPROMISED_HOST · high · SI — Compromised: 102.220.160.172C2_SERVER · critical · CN — Cobaltstrike: 101.200.193.211BREACH · high · ? — Breach: InterConSecurity (276k accounts)MALWARE_URL · high · PH — Malware URL: 112.198.186.190 (malware_download)BREACH · high · ? — Breach: HoustonCityCollege (832k accounts)BREACH · high · ? — Breach: GolfCanada (569k accounts)COMPROMISED_HOST · high · CN — Compromised: 101.96.192.88C2_SERVER · critical · CN — Cobaltstrike: 101.133.229.117MALWARE_URL · high · CN — Malware URL: 182.117.71.91 (malware_download)BREACH · high · ? — Breach: Fanlore (145k accounts)COMPROMISED_HOST · high · PK — Compromised: 101.50.83.146C2_SERVER · critical · CN — Cobaltstrike: 101.126.10.34MALWARE_URL · high · CN — Malware URL: 221.202.22.141 (malware_download)BREACH · critical · ? — Breach: ExactSciences (10870k accounts)BREACH · high · ? — Breach: BrinksHome (732k accounts)COMPROMISED_HOST · high · SG — Compromised: 101.100.216.61MALWARE_URL · high · CN — Malware URL: 116.55.26.114 (malware_download)C2_SERVER · critical · CN — Cobaltstrike: 1.15.76.39BREACH · high · ? — Breach: Alcon (218k accounts)DDOS_ORIGIN · high · US — CF Radar: US top DDoS L7 origin (22.2% of global)DDOS_ORIGIN · high · BR — CF Radar: BR top DDoS L3 origin (13.6% of global)OUTAGE · critical · PL · EURONET NORBERT SANIEWSKI SPOLKA JAWNA — EURONET-AS -- Poland — ping-slash24 criticalOUTAGE · critical · GB · Box Broadband Limited — box-broadband -- United Kingdom — ping-slash24 criticalOUTAGE · critical · BR · SERCOMTEL S/A TELECOMUNICACOES — AS22689 -- Brazil — ping-slash24 criticalDDOS_ORIGIN · high · US — CF Radar: US top DDoS L7 origin (22.2% of global)DDOS_ORIGIN · high · BR — CF Radar: BR top DDoS L3 origin (13.6% of global)MALICIOUS_SCAN · high · SG — urlscan: ethnic-peach-uzaebyob-dpx4aarxflje.edgeone.dev (phishing, malicious)MALICIOUS_SCAN · high · SG — urlscan: multiple-white-e8jkwbcx-dpfive881zig.edgeone.dev (phishing, malicious)MALICIOUS_SCAN · high · SG — urlscan: sonamkeliye-dpsk1e9g959i.edgeone.dev (phishing, malicious)MALICIOUS_SCAN · high · SG — urlscan: unnecessary-indigo-wdt0rdks-dp73wxopss6q.edgeone.dev (phishing, malicious)MALICIOUS_SCAN · high · SG — urlscan: nm2ticketmaster-ph-mytickets-4338-dpev2b5aif7x.edgeone.dev...ATTACK · high · NL — Top attacker: 52.157.207.201 (195k reports)MALICIOUS_SCAN · high · SG — urlscan: fortunate-blue-owgdqejf-dpvrp5bde380.edgeone.dev (phishing, malicious)ATTACK · high · ES — Top attacker: 194.224.249.214 (310k reports)MALICIOUS_SCAN · high · SG — urlscan: aesthetic-lime-zecoeppa-dpcw5n56pvy5.edgeone.dev (phishing, malicious)ATTACK · high · NL — Top attacker: 13.94.254.200 (320k reports)MALICIOUS_SCAN · high · SG — urlscan: terasssscafeandishe10-dp0n1wzvg8ua.edgeone.dev (phishing, malicious)C2_SERVER · critical · US — LIVE C2: 50.16.16.211:443 (QakBot)OUTAGE · critical · BR · SERCOMTEL S/A TELECOMUNICACOES — AS22689 -- Brazil — ping-slash24 criticalOUTAGE · critical · BR · SERCOMTEL S/A TELECOMUNICACOES — AS22689 -- Brazil — ping-slash24 criticalDDOS_ORIGIN · high · US — CF Radar: US top DDoS L7 origin (22.2% of global)DDOS_ORIGIN · high · BR — CF Radar: BR top DDoS L3 origin (13.6% of global)OUTAGE · critical · BR · SERCOMTEL S/A TELECOMUNICACOES — AS22689 -- Brazil — ping-slash24 criticalOUTAGE · critical · BR · SERCOMTEL S/A TELECOMUNICACOES — AS22689 -- Brazil — ping-slash24 criticalDDOS_ORIGIN · high · US — CF Radar: US top DDoS L7 origin (22.1% of global)DDOS_ORIGIN · high · BR — CF Radar: BR top DDoS L3 origin (13.6% of global)OUTAGE · critical · BR · SERCOMTEL S/A TELECOMUNICACOES — AS22689 -- Brazil — ping-slash24 criticalOUTAGE · critical · PK · Nayatel (Pvt) Ltd — NAYATEL-PK -- Punjab — ping-slash24 criticalDDOS_ORIGIN · high · US — CF Radar: US top DDoS L7 origin (22.1% of global)DDOS_ORIGIN · high · BR — CF Radar: BR top DDoS L3 origin (13.6% of global)MALICIOUS_SCAN · high · SG — urlscan: secret-tan-2hdszsva-dp4tz9svyuqv.edgeone.dev (phishing, malicious)MALICIOUS_SCAN · high · SG — urlscan: immense-crimson-0ckldtkg-dpbr4wjlrimn.edgeone.dev (phishing, malicious)MALICIOUS_SCAN · high · SG — urlscan: credocontact-dpbhdv5yxvwc.edgeone.dev (phishing, malicious)MALICIOUS_SCAN · high · SG — urlscan: erdemm-dp2taegg4ivc.edgeone.dev (phishing, malicious)MALICIOUS_SCAN · high · SG — urlscan: autonomous-magenta-9b44ikna-dpm8vqlmb7kp.edgeone.dev (phishing, malicious)ATTACK · high · NL — Top attacker: 52.157.207.201 (195k reports)MALICIOUS_SCAN · high · SG — urlscan: my-project-free-dpw39ubq3ax2.edgeone.dev (phishing, malicious)ATTACK · high · ES — Top attacker: 194.224.249.214 (310k reports)MALICIOUS_SCAN · high · SG — urlscan: adjacent-red-oy2soj2c-dp2mn4gzsptk.edgeone.dev (phishing, malicious)ATTACK · high · NL — Top attacker: 13.94.254.200 (320k reports)MALICIOUS_SCAN · high · SG — urlscan: brurwebsite-dpj8dcerjih6.edgeone.dev (phishing, malicious)C2_SERVER · critical · US — LIVE C2: 50.16.16.211:443 (QakBot)OUTAGE · critical · PK · Nayatel (Pvt) Ltd — NAYATEL-PK -- Punjab — ping-slash24 criticalOUTAGE · critical · PK · Nayatel (Pvt) Ltd — NAYATEL-PK -- Punjab — ping-slash24 criticalDDOS_ORIGIN · high · US — CF Radar: US top DDoS L7 origin (22.1% of global)DDOS_ORIGIN · high · BR — CF Radar: BR top DDoS L3 origin (13.6% of global)OUTAGE · critical · PK · Nayatel (Pvt) Ltd — NAYATEL-PK -- Punjab — ping-slash24 criticalOUTAGE · critical · NG · KKON Technologies Ltd — AS36920 (KKON) — bgp criticalMALWARE_URL · high · CN — Malware URL: 115.55.49.244 (malware_download)COMPROMISED_HOST · high · HK — Compromised: 103.194.106.230MALWARE_URL · high · CN — Malware URL: 123.14.59.100 (malware_download)COMPROMISED_HOST · high · IN — Compromised: 103.19.196.230C2_SERVER · critical · CN — Cobaltstrike: 101.43.103.154MALWARE_URL · high · CN — Malware URL: 182.125.18.121 (malware_download)COMPROMISED_HOST · high · IN — Compromised: 103.159.85.90C2_SERVER · critical · CN — Cobaltstrike: 101.42.255.92MALWARE_URL · high · CN — Malware URL: 182.120.96.20 (malware_download)COMPROMISED_HOST · high · SI — Compromised: 102.220.160.38C2_SERVER · critical · CN — Cobaltstrike: 101.33.225.32BREACH · critical · ? — Breach: OzHairAndBeauty (1988k accounts)MALWARE_URL · high · CN — Malware URL: 115.58.88.6 (malware_download)COMPROMISED_HOST · high · SI — Compromised: 102.220.160.172C2_SERVER · critical · CN — Cobaltstrike: 101.200.193.211BREACH · high · ? — Breach: InterConSecurity (276k accounts)BREACH · high · ? — Breach: HoustonCityCollege (832k accounts)MALWARE_URL · high · CN — Malware URL: 175.169.60.91 (malware_download)COMPROMISED_HOST · high · CN — Compromised: 101.96.192.88C2_SERVER · critical · CN — Cobaltstrike: 101.133.229.117BREACH · high · ? — Breach: GolfCanada (569k accounts)BREACH · high · ? — Breach: Fanlore (145k accounts)MALWARE_URL · high · CN — Malware URL: 175.169.60.91 (malware_download)COMPROMISED_HOST · high · PK — Compromised: 101.50.83.146C2_SERVER · critical · CN — Cobaltstrike: 101.126.10.34BREACH · critical · ? — Breach: ExactSciences (10870k accounts)BREACH · high · ? — Breach: BrinksHome (732k accounts)MALWARE_URL · high · CN — Malware URL: 115.50.3.162 (malware_download)COMPROMISED_HOST · high · SG — Compromised: 101.100.216.61C2_SERVER · critical · CN — Cobaltstrike: 1.15.76.39BREACH · high · ? — Breach: Alcon (218k accounts)OUTAGE · critical · NG · KKON Technologies Ltd — AS36920 (KKON) — bgp criticalDDOS_ORIGIN · high · US — CF Radar: US top DDoS L7 origin (22.1% of global)DDOS_ORIGIN · high · BR — CF Radar: BR top DDoS L3 origin (13.6% of global)OUTAGE · critical · PK · Nayatel (Pvt) Ltd — NAYATEL-PK -- Punjab — ping-slash24 criticalOUTAGE · critical · NG · KKON Technologies Ltd — AS36920 (KKON) — bgp criticalOUTAGE · critical · NG · KKON Technologies Ltd — AS36920 (KKON) — bgp criticalOUTAGE · critical · BR · SERCOMTEL S/A TELECOMUNICACOES — AS22689 -- Brazil — ping-slash24 criticalOUTAGE · critical · RU · Kompeatelecom Ltd. — AS59815 (TRK-METRO-AS) — ping-slash24 criticalOUTAGE · critical · RU · Kompeatelecom Ltd. — TRINITY-AS -- Russian Federation — ping-slash24 criticalOUTAGE · critical · US · Summit Broadband — ORLANDOTELCO -- United States — ping-slash24 criticalDDOS_ORIGIN · high · US — CF Radar: US top DDoS L7 origin (22.1% of global)DDOS_ORIGIN · high · BR — CF Radar: BR top DDoS L3 origin (13.6% of global)MALICIOUS_SCAN · high · SG — urlscan: gross-maroon-at722bdy-dpzvor2v35le.edgeone.dev (phishing, malicious)MALICIOUS_SCAN · high · SG — urlscan: better-lime-ooesxh5x-dpm0ckcv370b.edgeone.dev (phishing, malicious)MALICIOUS_SCAN · high · SG — urlscan: impressed-emerald-k75hoxr6-dp9iwwktn05c.edgeone.dev (phishing, malicious)MALICIOUS_SCAN · high · SG — urlscan: tusharyadav-dp5nrimtbswf.edgeone.dev (phishing, malicious)MALICIOUS_SCAN · high · SG — urlscan: snus-arne-wiki-dp03bl65qxts.edgeone.dev (phishing, malicious)ATTACK · high · NL — Top attacker: 52.157.207.201 (195k reports)MALICIOUS_SCAN · high · SG — urlscan: meupetbairro-dpbglc09v8h7.edgeone.dev (phishing, malicious)ATTACK · high · ES — Top attacker: 194.224.249.214 (310k reports)MALICIOUS_SCAN · high · SG — urlscan: dependent-silver-l2pf1ck4-dprsmiryv4bd.edgeone.dev (phishing, malicious)ATTACK · high · NL — Top attacker: 13.94.254.200 (320k reports)MALICIOUS_SCAN · high · SG — urlscan: pynehpaedomt-dpnn88gor7zn.edgeone.dev (phishing, malicious)C2_SERVER · critical · US — LIVE C2: 50.16.16.211:443 (QakBot)OUTAGE · critical · NG · KKON Technologies Ltd — AS36920 (KKON) — bgp criticalOUTAGE · critical · BR · SERCOMTEL S/A TELECOMUNICACOES — AS22689 -- Brazil — ping-slash24 criticalOUTAGE · critical · US · Summit Broadband — ORLANDOTELCO -- United States — ping-slash24 criticalOUTAGE · critical · RU · Kompeatelecom Ltd. — TRINITY-AS -- Russian Federation — ping-slash24 criticalOUTAGE · critical · RU · Kompeatelecom Ltd. — AS59815 (TRK-METRO-AS) — ping-slash24 criticalOUTAGE · critical · US · Summit Broadband — ORLANDOTELCO -- United States — ping-slash24 criticalOUTAGE · critical · RU · Kompeatelecom Ltd. — AS59815 (TRK-METRO-AS) — ping-slash24 criticalOUTAGE · critical · FI · Telia Cygate Oy — NBLNETWORKS-AS -- Finland — ping-slash24 criticalOUTAGE · critical · PK · Nayatel (Pvt) Ltd — NAYATEL-PK -- Punjab — ping-slash24 criticalOUTAGE · critical · NG · Zinox Telecommunications Limited — AS37506 (Zinox) — bgp criticalDDOS_ORIGIN · high · US — CF Radar: US top DDoS L7 origin (22.1% of global)DDOS_ORIGIN · high · BR — CF Radar: BR top DDoS L3 origin (13.6% of global)OUTAGE · critical · BR · SERCOMTEL S/A TELECOMUNICACOES — AS22689 -- Brazil — ping-slash24 criticalOUTAGE · critical · RU · Kompeatelecom Ltd. — AS59815 (TRK-METRO-AS) — ping-slash24 criticalOUTAGE · critical · FI · Telia Cygate Oy — NBLNETWORKS-AS -- Finland — ping-slash24 criticalOUTAGE · critical · NG · Zinox Telecommunications Limited — AS37506 (Zinox) — bgp criticalOUTAGE · critical · PK · Nayatel (Pvt) Ltd — NAYATEL-PK -- Punjab — ping-slash24 criticalOUTAGE · critical · SE · Internet Vikings International AB — INTERNETBOLAGET -- Sweden — ping-slash24 criticalDDOS_ORIGIN · high · US — CF Radar: US top DDoS L7 origin (22.1% of global)DDOS_ORIGIN · high · BR — CF Radar: BR top DDoS L3 origin (13.6% of global)OUTAGE · critical · SE · Internet Vikings International AB — INTERNETBOLAGET -- Sweden — ping-slash24 criticalOUTAGE · critical · KR · KX NexG Co., LTD — NEXG-AS-KR -- South Korea — ping-slash24 criticalDDOS_ORIGIN · high · US — CF Radar: US top DDoS L7 origin (22.1% of global)DDOS_ORIGIN · high · BR — CF Radar: BR top DDoS L3 origin (13.6% of global)MALICIOUS_SCAN · high · SG — urlscan: various-harlequin-cddgben6-dpfhug1ju462.edgeone.dev (phishing, malicious)MALICIOUS_SCAN · high · SG — urlscan: yucky-tomato-m0tw7qg5-dpv7sa2tvgrv.edgeone.dev (phishing, malicious)MALICIOUS_SCAN · high · SG — urlscan: laepitaph-dpv7ptelrpd3.edgeone.dev (phishing, malicious)MALICIOUS_SCAN · high · SG — urlscan: bijoy-fg-dp6us7xr9nmm.edgeone.dev (phishing, malicious)ATTACK · high · NL — Top attacker: 52.157.207.201 (195k reports)MALICIOUS_SCAN · high · SG — urlscan: rear-emerald-ffnj5ohk-dp27cqq0mt5j.edgeone.dev (phishing, malicious)ATTACK · high · ES — Top attacker: 194.224.249.214 (310k reports)MALICIOUS_SCAN · high · SG — urlscan: s-ttd-dpwd95fo193e.edgeone.dev (phishing, malicious)ATTACK · high · NL — Top attacker: 13.94.254.200 (320k reports)MALICIOUS_SCAN · high · SG — urlscan: curious-gold-fvlyrv5m-dparxxwkfo6r.edgeone.dev (phishing, malicious)C2_SERVER · critical · US — LIVE C2: 50.16.16.211:443 (QakBot)OUTAGE · critical · CN · China Telecom (Group) — AS4835 (CHINANET-IDC-SN) — bgp criticalOUTAGE · critical · HK · Netsec Limited — AS45753 (NETSEC-HK) — bgp criticalOUTAGE · critical · BD · MetroNet Bangladesh Limited — AS38026 (MNBL-TRANSIT-AS-AP) — bgp criticalOUTAGE · critical · BD · MetroNet Bangladesh Limited — AS38026 (MNBL-TRANSIT-AS-AP) — bgp criticalOUTAGE · critical · HK · Netsec Limited — AS45753 (NETSEC-HK) — bgp criticalOUTAGE · critical · CN · China Telecom (Group) — AS4835 (CHINANET-IDC-SN) — bgp criticalOUTAGE · critical · BR · SERCOMTEL S/A TELECOMUNICACOES — AS22689 -- Brazil — ping-slash24 criticalDDOS_ORIGIN · high · US — CF Radar: US top DDoS L7 origin (22.1% of global)DDOS_ORIGIN · high · BR — CF Radar: BR top DDoS L3 origin (13.6% of global)OUTAGE · critical · HK · Netsec Limited — AS45753 (NETSEC-HK) — bgp criticalOUTAGE · critical · CN · China Telecom (Group) — AS4835 (CHINANET-IDC-SN) — bgp criticalOUTAGE · critical · BR · SERCOMTEL S/A TELECOMUNICACOES — AS22689 -- Brazil — ping-slash24 criticalCOMPROMISED_HOST · high · HK — Compromised: 103.194.106.230MALWARE_URL · high · NL — Malware URL: 91.92.242.236 (malware_download)COMPROMISED_HOST · high · IN — Compromised: 103.19.196.230C2_SERVER · critical · CN — Cobaltstrike: 101.43.103.154MALWARE_URL · high · CN — Malware URL: 123.14.177.167 (malware_download)COMPROMISED_HOST · high · IN — Compromised: 103.159.85.90C2_SERVER · critical · CN — Cobaltstrike: 101.42.255.92MALWARE_URL · high · CN — Malware URL: 123.14.59.100 (malware_download)COMPROMISED_HOST · high · SI — Compromised: 102.220.160.38C2_SERVER · critical · CN — Cobaltstrike: 101.33.225.32MALWARE_URL · high · CN — Malware URL: 115.55.49.244 (malware_download)BREACH · critical · ? — Breach: OzHairAndBeauty (1988k accounts)COMPROMISED_HOST · high · SI — Compromised: 102.220.160.172C2_SERVER · critical · CN — Cobaltstrike: 101.200.193.211BREACH · high · ? — Breach: InterConSecurity (276k accounts)MALWARE_URL · high · CN — Malware URL: 123.14.59.100 (malware_download)BREACH · high · ? — Breach: HoustonCityCollege (832k accounts)COMPROMISED_HOST · high · CN — Compromised: 101.96.192.88C2_SERVER · critical · CN — Cobaltstrike: 101.133.229.117BREACH · high · ? — Breach: GolfCanada (569k accounts)MALWARE_URL · high · CN — Malware URL: 182.125.18.121 (malware_download)BREACH · high · ? — Breach: Fanlore (145k accounts)COMPROMISED_HOST · high · PK — Compromised: 101.50.83.146C2_SERVER · critical · CN — Cobaltstrike: 101.126.10.34MALWARE_URL · high · CN — Malware URL: 182.120.96.20 (malware_download)BREACH · critical · ? — Breach: ExactSciences (10870k accounts)BREACH · high · ? — Breach: BrinksHome (732k accounts)COMPROMISED_HOST · high · SG — Compromised: 101.100.216.61MALWARE_URL · high · CN — Malware URL: 115.58.88.6 (malware_download)C2_SERVER · critical · CN — Cobaltstrike: 1.15.76.39BREACH · high · ? — Breach: Alcon (218k accounts)OUTAGE · critical · BR · SERCOMTEL S/A TELECOMUNICACOES — AS22689 -- Brazil — ping-slash24 criticalDDOS_ORIGIN · high · US — CF Radar: US top DDoS L7 origin (22.1% of global)DDOS_ORIGIN · high · BR — CF Radar: BR top DDoS L3 origin (13.7% of global)OUTAGE · critical · BR · SERCOMTEL S/A TELECOMUNICACOES — AS22689 -- Brazil — ping-slash24 criticalOUTAGE · critical · RU · Kompeatelecom Ltd. — TRINITY-AS -- Russian Federation — ping-slash24 criticalOUTAGE · critical · RU · Kompeatelecom Ltd. — AS59815 (TRK-METRO-AS) — ping-slash24 criticalDDOS_ORIGIN · high · US — CF Radar: US top DDoS L7 origin (22.1% of global)DDOS_ORIGIN · high · BR — CF Radar: BR top DDoS L3 origin (13.6% of global)
critical high med/low 486 geolocated of 1000 events
EVENT TYPES
event368
outage113
malicious scan75
ddos origin64
ransomware post50
c2 server48
breach45
malware url43
compromised host43
vulnerability30
exploited vuln30
attack30
iran probe change21
probe change13
reputation10
honeypot8
phishing7
ocsp responder anomaly1
hijacked prefix1
TOP ORIGIN COUNTRIES
CN107
SG81
US80
BR45
NL24
PK18
ZA14
IR11
CORRELATED ESCALATIONS
500 active
FUSED CORRELATIONS · DEFCON-RANKED all fusion →
DEFCON 1
Nation-State Network Activity · US
CRITICAL
DEFCON 1
Nation-State Network Activity · CN
CRITICAL
DEFCON 2
DDoS Origin + Active Threat Feed Signal · US
CRITICAL
DEFCON 2
DDoS Origin + Active Threat Feed Signal · CN
CRITICAL
DEFCON 3
Bulletproof Hosting Detected
HIGH