Last updated Fri, 25 Sep 2026 21:04:59 (Australia/Brisbane)
Below is a list of the top 500 IP addresses with suspicious activity observed by SCARD. Click on an IP address below for more information about its activity.
Note: Due to the overwhelming number of common scan types, this list omits typical scan types in favour of less-seen threat types.
Back to top
Below is a list of the top 200 threat types observed across the network.
| Description | Incidence |
|---|---|
| SERVER-OTHER tcpdump ISAKMP parser buffer overflow attempt | 433282 |
| SURICATA TCP header length too small | 362919 |
| ET USER_AGENTS WinRM User Agent Detected - Possible Lateral Movement | 249859 |
| ET INFO WinRM wsman Access - Possible Lateral Movement | 249447 |
| ET INFO Session Traversal Utilities for NAT (STUN Binding Response) | 185573 |
| ET EXPLOIT Realtek SDK - Command Execution/Backdoor Access Inbound (CVE-2021-35394) | 46188 |
| ET SCAN LeakIX Inbound User-Agent | 38079 |
| ET WEB_SERVER WEB-PHP phpinfo access | 29901 |
| ET WEB_SPECIFIC_APPS React Server Components React2Shell Unsafe Flight Protocol Property Access (CVE-2025-55182) | 28555 |
| ET HUNTING Javascript Prototype Pollution Attempt via __proto__ in HTTP Body | 24526 |
| ET SCAN WordPress Scanner Performing Multiple Requests to Windows Live Writer XML | 24246 |
| ET WEB_SPECIFIC_APPS Vite Arbitrary File Read Via raw parameter (CVE-2025-30208) | 22909 |
| ET VOIP Modified Sipvicious Asterisk PBX User-Agent | 19140 |
| ET INFO SSH-2.0-Go version string Observed in Network Traffic | 17381 |
| ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 | 15646 |
| ET HUNTING SUSPICIOUS Dotted Quad Host MZ Response | 15545 |
| ET INFO External Oracle T3 Requests Inbound | 13678 |
| ET WEB_SERVER WebShell Generic - wget http - POST | 13391 |
| ET INFO Netlink GPON Login Attempt (GET) | 12638 |
| ET VOIP INVITE Message Flood UDP | 12551 |
| ET VOIP Possible Inbound VOIP Scan/Misuse With User-Agent Zoiper | 12014 |
| ET WEB_SPECIFIC_APPS WordPress Plugin Gravity SMTP Unauthenticated REST API (CVE-2026-4020) | 11400 |
| ET WEB_SERVER /etc/passwd Detected in URI | 11048 |
| ET INFO Python aiohttp User-Agent Observed Inbound | 10191 |
| ET HUNTING Suspicious Chmod Usage in URI (Inbound) | 9705 |
| ET SCAN Behavioral Unusually fast Terminal Server Traffic Potential Scan or Infection (Inbound) | 8533 |
| ET INFO Request for Visual Studio Code sftp.json - Possible Information Leak | 8519 |
| SURICATA HTTP Host header invalid | 8501 |
| ET SCAN Rapid POP3S Connections - Possible Brute Force Attack | 8409 |
| ET HUNTING Javascript Sandbox Escape via Global Object (process) | 8219 |
| SURICATA HTTP URI terminated by non-compliant character | 7928 |
| SERVER-WEBAPP React Server Components remote code execution attempt | 7849 |
| SURICATA FRAG IPv4 Fragmentation overlap | 7769 |
| ET HUNTING Request for Webshell in .well-known directory | 7465 |
| ET WEB_SERVER Next.js Middleware Authorization Bypass (CVE-2025-29927) | 7350 |
| ET INFO Apache Solr System Information Request | 6679 |
| ET EXPLOIT MVPower DVR Shell UCE | 6540 |
| ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) | 6465 |
| ET EXPLOIT GraphQL Introspection Query Attempt | 6457 |
| SURICATA ICMPv4 unknown code | 5816 |
| ET SCAN JAWS Webserver Unauthenticated Shell Command Execution | 5658 |
| ET SCAN Mirai Variant User-Agent (Inbound) | 5630 |
| ET WEB_SERVER Likely Malicious Request for /proc/self/environ | 5562 |
| ET INFO Spring Boot Actuator Health Check Request | 5455 |
| SURICATA IKE invalid proposal | 5033 |
| ET WEB_SERVER Possible SQL Injection UNION SELECT in HTTP Request Body | 4878 |
| ET EXPLOIT HackingTrio UA (Hello, World) | 4838 |
| ET INFO ChatGPT-User Traffic Detected Inbound M1 | 4762 |
| ET INFO ChatGPT-User Traffic Detected Inbound M2 | 4756 |
| SERVER-WEBAPP TP-Link Archer Router command injection attempt | 4751 |
| ET WEB_SERVER Possible SQL Injection SELECT CONCAT in HTTP Request Body | 4743 |
| ET SCAN SFTP/FTP Password Exposure via sftp-config.json | 4735 |
| ET EXPLOIT Netgear DGN Remote Command Execution | 4735 |
| ET WEB_SERVER WGET Command Specifying Output in HTTP Headers | 4671 |
| ET EXPLOIT D-Link Devices Home Network Administration Protocol Command Execution | 4663 |
| ET WEB_SERVER PHP tags in HTTP POST | 4523 |
| ET EXPLOIT D-Link DSL-2750B - OS Command Injection | 4350 |
| ET EXPLOIT D-Link DSL-2750B Command Injection Attempt (CVE-2016-20017) | 4348 |
| SURICATA HTTP METHOD terminated by non-compliant character | 4311 |
| ET INFO External IP Lookup Domain in DNS Lookup (ipecho .net) | 4296 |
| SERVER-WEBAPP Netgear DGN1000 series routers authentication bypass attempt | 4176 |
| ET WEB_SERVER Wordpress Login Bruteforcing Detected | 4031 |
| SERVER-WEBAPP D-Link DSL-2750B routers login.cgi command injection attempt | 3951 |
| ET WEB_SERVER PHP Possible https Local File Inclusion Attempt | 3803 |
| SURICATA HTTP request field missing colon | 3779 |
| ET SCAN Nmap Scripting Engine User-Agent Detected (Nmap Scripting Engine) | 3571 |
| ET INFO Google DNS Over HTTPS Certificate Inbound | 3552 |
| SURICATA Applayer Unexpected protocol | 3539 |
| SURICATA Applayer No TLS after STARTTLS | 3539 |
| ET SCAN Laravel Debug Mode Information Disclosure Probe Inbound | 3498 |
| ET EXPLOIT Possible Authenticated Command Injection Inbound - Comtrend VR-3033 (CVE-2020-10173) | 3378 |
| ET DNS Query to a *.top domain - Likely Hostile | 3330 |
| SURICATA TCP invalid option length | 3310 |
| SURICATA SMTP data command rejected | 3136 |
| ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability | 3036 |
| SERVER-WEBAPP PHPUnit PHP remote code execution attempt | 3024 |
| ET WEB_SPECIFIC_APPS WordPress Core wp2shell Remote Code Execution (CVE-2026-63030 & CVE-2026-60137) M2 | 2677 |
| ET INFO Observed DNS Query to .nexus TLD | 2512 |
| SURICATA HTTP invalid request field folding | 2479 |
| SURICATA SMB malformed request dialects | 2474 |
| ET SCAN Potential SSH Scan OUTBOUND | 2355 |
| ET SCAN NMAP OS Detection Probe | 2323 |
| SURICATA ICMPv4 invalid checksum | 2104 |
| SURICATA QUIC error on data | 2089 |
| ET DOS Potential CLDAP Amplification Reflection | 2087 |
| ET INFO Observed DNS Query to .life TLD | 1971 |
| ET EXPLOIT VMware Spring Cloud Directory Traversal (CVE-2020-5410) | 1846 |
| ET WEB_SERVER .bash_history Detected in URI | 1844 |
| ET SCAN Suspicious User-Agent Containing Security Scan/ner Likely Scan | 1738 |
| ET INFO Server Hello with Downgrade Request to TLS 1.1 or Lower | 1711 |
| ET SCAN NETWORK Incoming Masscan detected | 1685 |
| ET USER_AGENTS Suspcious LeakIX User-Agent (l9explore) | 1668 |
| ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev) | 1610 |
| ET SCAN Behavioral Unusual Port 1433 traffic Potential Scan or Infection | 1555 |
| ET WEB_SPECIFIC_APPS WordPress Core wp2shell Remote Code Execution (CVE-2026-63030 & CVE-2026-60137) M1 | 1528 |
| SURICATA IKE unknown proposal | 1504 |
| SERVER-WEBAPP Next.js Middleware authentication bypass attempt | 1422 |
| SURICATA TLS handshake invalid length | 1417 |
| ET SCAN LibSSH Based Frequent SSH Connections Likely BruteForce Attack | 1415 |
| SURICATA SMTP duplicate fields | 1402 |
| SURICATA DHCP truncated options | 1382 |
| ET INFO Observed DNS Query to .fit TLD | 1338 |
| ET WEB_SERVER Possible SQL Injection (exec) in HTTP Request Body | 1317 |
| ET INFO Infrastructure as a Service Domain in DNS Lookup (railway .app) | 1255 |
| ET WEB_SERVER Double Encoded Characters in URI (../) | 1251 |
| ET INFO DNS Query to Cloudflare Tunneling Domain (argotunnel .com) | 1216 |
| ET WEB_SPECIFIC_APPS Wordpress LiteSpeed Cache Plugin debug.log Access Attempt (CVE-2024-44000) | 1192 |
| ET INFO Observed DNS Query to .cfd TLD | 1191 |
| ET INFO External IP Lookup Domain in DNS Lookup (icanhazip .com) | 1181 |
| ET SCAN NMAP SIP Version Detection Script Activity | 1167 |
| ET INFO Session Traversal Utilities for NAT (STUN Binding Request On Non-Standard Low Port) | 1136 |
| ET TA_ABUSED_SERVICES Commonly Actor Abused Online Service Domain (storjshare .io) | 1113 |
| ET WEB_SERVER auto_prepend_file PHP config option in uri | 1105 |
| ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol UDP (CVE-2021-44228) | 1085 |
| ET WEB_SERVER allow_url_include PHP config option in uri | 1075 |
| ET INFO POSSIBLE Web Crawl using Curl | 1055 |
| ET WEB_SERVER Generic PHP Remote File Include | 1031 |
| ET WEB_SERVER PHP.//Input in HTTP POST | 1031 |
| ET SCAN RDP Connection Attempt from Nmap | 987 |
| ET WEB_SPECIFIC_APPS Apache ActiveMQ 6.x Default Unauthenticated API Access (CVE-2024-32114) M1 | 974 |
| ET WEB_SPECIFIC_APPS PHP-CGI OS Command Injection (soft hyphen) (CVE-2024-4577) | 957 |
| SERVER-WEBAPP PHP PHP-CGI command execution attempt | 940 |
| ET WEB_SPECIFIC_APPS Microhard Systems 3G/4G Cellular Ethernet and Serial Gateway - Default Credentials | 939 |
| ET INFO Observed ZeroSSL SSL/TLS Certificate | 925 |
| ET VOIP REGISTER Message Flood UDP | 888 |
| SURICATA STREAM ESTABLISHED packet out of window | 864 |
| ET INFO External IP Lookup api.ipify.org | 811 |
| ET EXPLOIT Apache log4j RCE Attempt - lower/upper UDP Bypass M2 (CVE-2021-44228) | 805 |
| ET EXPLOIT Apache log4j RCE Attempt (udp ldap) (CVE-2021-44228) | 805 |
| SERVER-WEBAPP Vite Vitejs arbitrary file read attempt | 804 |
| ET INFO Inbound Frequent Emails - Possible Spambot Inbound | 792 |
| ET HUNTING Suspicious PHP Code in HTTP POST (Inbound) | 783 |
| ET INFO External IP Lookup Domain in DNS Lookup (ipinfo .io) | 777 |
| ET WEB_SERVER ThinkPHP RCE Exploitation Attempt | 741 |
| SURICATA DNS Invalid opcode | 707 |
| ET INFO External IP Lookup Domain (freegeiop .net in DNS lookup) | 672 |
| ET INFO External IP Lookup Domain (ident .me) in DNS Lookup | 662 |
| ET EXPLOIT LB-Link Command Injection Attempt (CVE-2023-26801) | 643 |
| ET WEB_SPECIFIC_APPS Possible Oracle WebLogic RCE Fuzzing Inbound M2 | 637 |
| ET INFO Tailscale Control Pane in DNS Query | 637 |
| ET DNS Query to a *.pw domain - Likely Hostile | 631 |
| ET Threatview.io High Confidence Cobalt Strike C2 IP group 3 | 627 |
| SERVER-WEBAPP Langflow code validator remote code execution attempt | 618 |
| ET SCAN Yandex Webcrawler User-Agent (YandexBot) | 615 |
| SERVER-WEBAPP WordPress wp-config.php access via directory traversal attempt | 612 |
| ET WEB_SPECIFIC_APPS WordPress Core wp2shell Remote Code Execution (CVE-2026-63030) M2 | 612 |
| ET WEB_SERVER Fake Googlebot UA 2 Inbound | 596 |
| ET INFO Discord Chat Service Domain in DNS Lookup (gateway .discord .gg) | 581 |
| ET INFO External IP Lookup - ipecho.net | 566 |
| ET HUNTING Observed Query to .beauty TLD | 564 |
| SURICATA TLS invalid record version | 546 |
| ET INFO DNS Query for Suspicious .icu Domain | 537 |
| ET SCAN Exabot Webcrawler User Agent | 531 |
| ET HUNTING Suspicious PHP Code in HTTP POST (Outbound) | 526 |
| ET EXPLOIT Zyxel ZyWALL/USG OS Command Injection (CVE-2023-28771) | 518 |
| ET DNS DNS Lookup for localhost.DOMAIN.TLD | 516 |
| ET INFO SOCKSv4 HTTP Proxy Inbound Request (Linux Source) | 500 |
| ET EXPLOIT Apache log4j RCE Attempt - lower/upper TCP Bypass M2 (CVE-2021-44228) | 499 |
| ET EXPLOIT Apache log4j RCE Attempt (tcp ldap) (CVE-2021-44228) | 499 |
| ET EXPLOIT Apache log4j RCE Attempt (http ldap) (CVE-2021-44228) | 495 |
| ET INFO Http Client Body contains pwd= in cleartext | 487 |
| SURICATA HTTP request header invalid | 477 |
| ET SCAN Web Scanner - Fuzz Faster U Fool (Inbound) | 472 |
| ET INFO External IP Lookup Domain in DNS Lookup (ip-api .com) | 470 |
| ET SCAN DuckDuckGo Webcrawler User-Agent (DuckDuckBot) | 444 |
| SURICATA HTTP request buffer too long | 442 |
| SERVER-OTHER Apache Log4j logging remote code execution attempt | 418 |
| ET EXPLOIT Cisco ASA and Firepower Path Traversal Vulnerability M2 (CVE-2020-3452) | 397 |
| ET EXPLOIT Cisco ASA/Firepower Unauthenticated File Read (CVE-2020-3452) M3 | 397 |
| ET EXPLOIT Cisco ASA/Firepower Unauthenticated File Read (CVE-2020-3452) M2 | 397 |
| ET DYN_DNS DYNAMIC_DNS Query to a *.dynu .com Domain | 394 |
| ET WEB_SPECIFIC_APPS TBK DVR-4104/4216 Command Injection Attempt (CVE-2024-3721) | 388 |
| SURICATA DNS Z flag set | 377 |
| ET INFO POSSIBLE Crawl using Fetch | 377 |
| ET SCAN NMAP SIP Version Detect OPTIONS Scan | 373 |
| ET WEB_SPECIFIC_APPS WordPress Core wp2shell Remote Code Execution (CVE-2026-63030) M1 | 358 |
| ET INFO DNS Query to Alibaba Cloud CDN Domain (aliyuncs .com) | 355 |
| SURICATA SMTP invalid pipelined sequence | 353 |
| ET INFO MailJet URL Shortening Service Domain in DNS Lookup (mjt .lu) | 348 |
| ET SCAN Suspicious User-Agent Containing Web Scan/er Likely Web Scanner | 339 |
| SURICATA UDP packet too small | 326 |
| ET INFO External IP Lookup Domain in DNS Lookup (whatismyipaddress .com) | 310 |
| ET WEB_SERVER Possible DD-WRT Metacharacter Injection Command Execution Attempt | 309 |
| ET EXPLOIT Fortigate VPN - Request to /remote/info - Possible CVE-2023-27997 Exploit Attempt | 307 |
| ET INFO URL Shortening Service Domain in DNS Lookup (shorturl .at) | 300 |
| ET WEB_SERVER Possible SQL Injection (exec) in HTTP URI | 287 |
| SURICATA HTTP Host header ambiguous | 281 |
| SURICATA TLS invalid heartbeat encountered, possible exploit attempt (heartbleed) | 273 |
| SURICATA TCP option invalid length | 272 |
| ET WEB_SERVER Possible D-Link Router HNAP Protocol Security Bypass Attempt | 257 |
| SERVER-WEBAPP Zyxel unauthenticated IKEv2 command injection attempt | 254 |
| SERVER-WEBAPP Zyxel unauthenticated IKEv2 overflow attempt | 254 |
| ET DYN_DNS DYNAMIC_DNS Query to a Suspicious no-ip Domain | 253 |
| ET WEB_SPECIFIC_APPS Joomla Improper Access Control to Webservice Endpoints (CVE-2023-23752) | 253 |
| ET EXPLOIT D-Link HNAP SOAPAction Command Injection (CVE-2015-2051, CVE-2019-10891, CVE-2022,37056, CVE-2024-33112, CVE-2025-114 | 251 |
| ET EXPLOIT Linksys E-Series Device RCE Attempt | 250 |
| ET HUNTING HTTP URI Path Normalization Bypasses & Escapes M1 | 248 |
| MALWARE-BACKDOOR Aspx.Webshell.Agent inbound request for known webshell path attempt | 247 |
| ET INFO DNS Query for Suspicious .ml Domain | 237 |
| ET INFO F5 BIG-IP - Command Execution via util/bash | 236 |
Back to top