Verdict: True Positive — Unsuccessful
Severity: Low
Date: 2024-09-25
IP 134.209.145[.]73 made repeated POST requests to /accounts/login targeting test[@]letsdefend.io from an unsupported cloud region (DigitalOcean infrastructure). All attempts were blocked by firewall policy and returned HTTP 403. No successful authentication occurred and no containment was required.
| Field | Value |
|---|---|
| IP | 134.209.145[.]73 |
| Classification | Malicious |
| Intel Source | AbuseIPDB |
| Origin | Unsupported cloud region — DigitalOcean node |
Legitimate users authenticate via corporate VPN, routing through approved US-based IPs. A DigitalOcean origin indicates automated tooling or deliberate credential attack activity, not an accidental geo-policy violation.
Proxy Log
403 on all requestsMozilla/5.0 — generic, consistent with automated toolingFirewall Log
blocked / Reason: access_denied1443app.letsdefend[.]ioPOST to /accounts/logintest[@]letsdefend.io confirmed| Technique ID | Tactic | Technique |
|---|---|---|
| T1110 | Credential Access | Brute Force |
| T1535 | Defense Evasion | Unused/Unsupported Cloud Regions |
| Type | Value |
|---|---|
| IP | 134.209.145[.]73 |
| User | test[@]letsdefend.io |
| Domain | app.letsdefend[.]io |
| URL | /accounts/login |
Summary:
A known malicious DigitalOcean-hosted IP attempted repeated credential attacks against test[@]letsdefend.io from an unsupported cloud region. All attempts were blocked at the perimeter with HTTP 403 responses. Endpoint review confirmed no successful access, lateral movement, or persistence — no containment action was required.