IPMediumSignal 77/100
1.70.10.110
Location
Liuxiang, Shanxi
ASN
AS4134
Chinanet SX
First Seen
May 27, 2025
Last Seen
Oct 3, 2025
Found in 10 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
77%
Signal Score
77 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Network Information
Country
China
RegionLiuxiang, Shanxi
ASNAS4134
OrganizationChinanet SX
Feed Intelligence Summary
10 reports77% confidence
10
Source reports
77%
Confidence score
Category tags
abuseactive scanningasiaattackbotnetbrute forcebrute force attackchinacommand and controlcommunication technologiescowrie honeypotcredential accesscredential stuffingdata exfiltrationddosdecoy systemdenial of servicedistributed attacksexploit attemptsftp brute forcehttp brute forceindicatorlateral movementmalicious activitymalicious softwaremalwaremalware propagationmalware scanningmobile carriersmobile networksnetworknetwork probingnetwork scanningpassword attacksprocess injectionreconnaissanceremote accessremote servicesresearchedscannersftp attacksmtp brute forcesql injection attemptsssh attackssh monitoringt1021t1021.001t1041t1046t1055t1059t1071.001t1076t1078t1110t1110.001t1110.002t1110.003t1110.004t1133t1187t1190t1199t1210t1486t1496t1499.002t1499.003t1563t1565t1588t1595t1595.001t1595.002t1595.003telecom servicestelecommunicationsthreat actor
Activity Timeline
Oct 3Oct 3
Threat Activity Heatmap
· Peak: 2025-10-03LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Threat ScoreHigh Risk
77
SIGNAL
Signal Score
77%
Confidence
10
Reports
First seenMay 27, 2025
Last seenOct 3, 2025
GeolocationCN
CountryChina
LocationLiuxiang, Shanxi
ASNAS4134
OrgChinanet SX
Coords34.7732, 113.7220
VirusTotal
Not checked
WHOIS
- raw
- inetnum: 1.68.0.0 - 1.71.255.255 netname: CHINANET-SX descr: CHINANET SHANXI PROVINCE NETWORK descr: China Telecom descr: No.31,jingrong street descr: Beijing 100032 country: CN admin-c: sa49-ap tech-c: st53-ap abuse-c: AC1573-AP status: ALLOCATED PORTABLE remarks: service provider remarks: -------------------------------------------------------- remarks: To report network abuse, please contact mnt-irt remarks: For troubleshooting, please contact tech-c and admin-c remarks: Report invalid contact via www.apnic.net/invalidcontact remarks: -------------------------------------------------------- notify: [email protected] mnt-by: APNIC-HM mnt-lower: MAINT-CHINANET-SX mnt-routes: MAINT-CHINANET-SX mnt-irt: IRT-CHINANET-CN last-modified: 2021-06-15T08:04:49Z source: APNIC irt: IRT-CHINANET-CN address: No.31 ,jingrong street,beijing address: 100032 e-mail: [email protected] abuse-mailbox: [email protected] admin-c: CH93-AP tech-c: CH93-AP auth: # Filtered remarks: [email protected] was validated on 2025-04-24 mnt-by: MAINT-CHINANET last-modified: 2025-04-24T03:21:26Z source: APNIC role: ABUSE CHINANETCN country: ZZ address: No.31 ,jingrong street,beijing address: 100032 phone: +000000000 e-mail: [email protected] admin-c: CH93-AP tech-c: CH93-AP nic-hdl: AC1573-AP remarks: Generated from irt object IRT-CHINANET-CN remarks: [email protected] was validated on 2025-04-24 abuse-mailbox: [email protected] mnt-by: APNIC-ABUSE last-modified: 2025-04-24T03:21:54Z source: APNIC person: shanxitele admin nic-hdl: SA49-AP e-mail: [email protected] address: no.217 nanneihuan street address: taiyuan city 030012 phone: +86-351-5609863 fax-no: +86-351-5609868 country: cn mnt-by: MAINT-CHINANET-SX last-modified: 2008-09-04T08:55:34Z source: APNIC person: shanxitele tech nic-hdl: ST53-AP e-mail: [email protected] address: no.217 nanneihuan street address: taiyuan city 030012 phone: +86-351-5609963 fax-no: +86-351-5609868 country: cn mnt-by: MAINT-CHINATELECOM-SX last-modified: 2008-09-04T07:31:30Z source: APNIC
- references
- https://github.com/telekom-security/tpotce
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 1 year ago · Last seen 8 months ago
Appeared in 10 threat reports