Decision for 45.115.26.203
Reasons
- Permanent enforcement applied due to coordinated distributed activity.
- Threat activity was observed independently on multiple nodes.
- Multiple stages of an attack chain were observed within a short time window.
- Observed behavior consistent with post-compromise activity, such as backdoors, webshells, or lateral movement.
- High-confidence indicators of post-exploitation activity were detected.
MITRE ATT&CK Mappings
- Tactics:
Command and Control / Persistence,
Reconnaissance
- Techniques:
T1059,
T1105,
T1595
Evidence
- Nodes observed: 4
-
Severity:
CRITICAL
-
TTL remaining:
12d 5h
Back to Dashboard