Loading threats
SMTP client issued a STARTTLS command to request upgrading the current plaintext SMTP session to a TLS-encrypted channel. This is part of normal protocol behavior for secure mail delivery, but in honeypot or exposed services it may also appear during automated probing where bots test whether encrypted submission is supported before continuing authentication attempts, relay testing, or message delivery workflows.
| IP Address | Risk | Events | Sessions | Country | ASN | Last Seen |
|---|---|---|---|---|---|---|
| 154.83.15.73 | 97% | 114,863 | 1,091 | 🇭🇰 HK | AS142403 | 2026-02-05 |
| 109.122.18.73 | 99% | 111,472 | 1,059 | 🇺🇸 US | AS22439 | 2026-02-06 |
| 81.29.142.100 | 100% | 20,831 | 11,697 | 🇷🇺 RU | AS210259 | 2026-03-02 |
| 81.29.142.6 | 99% | 13,985 | 8,279 | 🇷🇺 RU | AS210259 | 2026-03-02 |
| 45.91.64.6 | 100% | 13,853 | 7,474 | 🇷🇺 RU | AS214664 | 2026-03-03 |
| 95.215.0.144 | 97% | 7,740 | 4,586 | 🇷🇺 RU | AS44050 | 2026-03-03 |
| 207.90.244.28 | 100% | 6,627 | 3,753 | 🇺🇸 US | AS174 | 2026-03-03 |
| 185.242.226.19 | 88% | 5,510 | 2,294 | 🇺🇸 US | AS202425 | 2026-03-02 |
| 207.90.244.14 | 100% | 5,330 | 3,177 | 🇺🇸 US | AS174 | 2026-03-03 |
| 80.13.153.140 | 99% | 4,091 | 2,270 | 🇫🇷 FR | AS3215 | 2026-03-03 |
| 80.82.77.202 | 96% | 4,035 | 2,835 | 🇳🇱 NL | AS202425 | 2026-03-03 |
| 92.154.95.236 | 99% | 3,629 | 1,984 | 🇫🇷 FR | AS3215 | 2026-03-03 |
| 45.91.64.7 | 98% | 3,461 | 2,372 | 🇷🇺 RU | AS214664 | 2026-03-03 |
| 71.6.199.23 | 100% | 3,331 | 1,563 | 🇺🇸 US | AS10439 | 2026-03-03 |
| 185.93.89.18 | 96% | 3,186 | 3,175 | 🇮🇷 IR | AS213790 | 2026-03-03 |
| 165.154.221.151 | 85% | 2,952 | 669 | 🇻🇳 VN | AS135377 | 2026-03-03 |
| 66.132.153.114 | 100% | 2,951 | 1,648 | 🇺🇸 US | AS398324 | 2026-03-03 |
| 66.132.153.117 | 100% | 2,917 | 1,495 | 🇺🇸 US | AS398324 | 2026-03-03 |
| 66.132.153.122 | 100% | 2,868 | 1,469 | 🇺🇸 US | AS398324 | 2026-03-03 |
| 167.94.138.191 | 30% | 2,828 | 1,408 | 🇺🇸 US | AS398324 | 2026-03-03 |