Active Threat β€’ HIGH

167.99.230.219

First Detection1/4/2026
Last Activity1/23/2026
ISPDIGITALOCEAN-ASN
🎯
122
Total Attacks
πŸ”Œ
4
Ports
πŸ“‘
2
Attack Types
🦠
1
Malware

Geolocation

Country
πŸ‡ΊπŸ‡Έ United States
City
North Bergen
ASN
AS14061
ISP
DIGITALOCEAN-ASN

Attack Types

honeytrap
cowrie

Attacked Ports

600044818922223

Associated Malware

Attempted Credentials

πŸ”Content-Type: application/octet-stream/Content-Length: 7
1x
πŸ”Call-ID: 50000/CSeq: 42 OPTIONS
1x
πŸ”Content-Id: body@ff3af301-3196-497a-a918-72147c871a13/(empty)
1x
πŸ”Max-Forwards: 70/Content-Length: 0
1x
πŸ” <to>http://192.168.10.100/msmq/private$/queuejumper</to>/ <id>uuid:1@00000000-0000-0000-0000-000000000000
1x
πŸ”Content-Type: text/xml; charset=UTF-8/Content-Length: 606
1x
πŸ”Contact: <sip:nm@nm>/Accept: application/sdp
1x
πŸ”Content-Type: multipart/related; boundary="MSMQ - SOAP boundary, 53287"; type=text/xml/Host: 192.168.10.100
1x
πŸ”GET /nice%20ports%2C/Tri%6Eity.txt%2ebak HTTP/1.0/(empty)
1x
πŸ”From: <sip:nm@nm>;tag=root/To: <sip:nm2@nm2>
1x
πŸ”SOAPAction: "MSMQMessage"/Proxy-Accept: NonInteractiveClient
1x
πŸ” <path xmlns="http://schemas.xmlsoap.org/rp/" se:mustUnderstand="1">/ <action>MSMQ:poc</action>
1x
πŸ”b'\x00\x00\x00\x00\x00\xf4\x01\x00\x00\x0c\x04\x00\x00\x07\x00\x00\x00\xe3\x03\x00\x00POST /msmq HTTP/1.1'/Content-Length: 816
1x
πŸ” <expiresAt>20600609T164419</expiresAt>/ <sentAt>20230724T164419</sentAt>
1x
πŸ” </path>/ <properties se:mustUnderstand="1">
1x

Risk Assessment

70
/100
LowMediumHighCritical