// soc investigation 2026-12-07
SOC325 Unauthorized Cloud Region Access Attempt Detected
letsdefend Low ✓ true positive
mitre/T1110mitre/T1535
analyst verdict TRUE POSITIVE
✓

SOC325 - Unauthorized Cloud Region Access Attempt Detected

Verdict: True Positive — Unsuccessful
Severity: Low
Date: 2024-09-25


Summary

IP 134.209.145[.]73 made repeated POST requests to /accounts/login targeting test[@]letsdefend.io from an unsupported cloud region (DigitalOcean infrastructure). All attempts were blocked by firewall policy and returned HTTP 403. No successful authentication occurred and no containment was required.


Source IP Analysis

FieldValue
IP134.209.145[.]73
ClassificationMalicious
Intel SourceAbuseIPDB
OriginUnsupported cloud region — DigitalOcean node

Legitimate users authenticate via corporate VPN, routing through approved US-based IPs. A DigitalOcean origin indicates automated tooling or deliberate credential attack activity, not an accidental geo-policy violation.


Log Findings

Proxy Log

Firewall Log


Endpoint Review


MITRE ATT&CK

Technique IDTacticTechnique
T1110Credential AccessBrute Force
T1535Defense EvasionUnused/Unsupported Cloud Regions

Analysis Reports


IOCs

TypeValue
IP134.209.145[.]73
Usertest[@]letsdefend.io
Domainapp.letsdefend[.]io
URL/accounts/login

Summary:
A known malicious DigitalOcean-hosted IP attempted repeated credential attacks against test[@]letsdefend.io from an unsupported cloud region. All attempts were blocked at the perimeter with HTTP 403 responses. Endpoint review confirmed no successful access, lateral movement, or persistence — no containment action was required.