IOC Radar
IPMediumSignal 74/100

1.94.6.230

Location
ChinaChina
Shanghai, Shanghai
ASN
AS55990
Huawei Cloud Service
First Seen
Nov 11, 2025
Last Seen
Jun 9, 2026
Nov 11
First Seen
211d ago
Jun 9
Last Seen
yesterday
24
Reports
source reports
74%
Confidence
medium
Found in 24 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
74%
Signal Score
74 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

48 techniques

Network Information

CountryCNChina
RegionShanghai, Shanghai
ASNAS55990
OrganizationHuawei Cloud Service

Feed Intelligence Summary

24 reports74% confidence
24
Source reports
74%
Confidence score
Category tags
abuseaccess controlaccount compromiseaccount-takeover-attemptactive scanactive scanningactive-attackadbhoney honeypotapacheapache attackeraptasiaattackattackers ip addressesaustraliaauthenticationauthentication attackautomated attackautomated attacksautomated-attackbad reputationbad web botblocklist_allbothammerbothammer-feedbotnetbotnet activitybotnet-activitybrute forcebrute force attackbrute force attackerbrute force attemptbrute-forcebrute-force-attackbruteforcec2chinacisco brute forcecisco devicecisco exploitation attemptcloud infrastructurecloud infrastructure attackcloud servicescloud-servicecncommand & controlcommand and controlcommunication protocolcompromised hostcowrie attackscowrie honeypotcredential accesscredential harvestingcredential stuffingcredential-guessingcyberattackdaily-threat-feeddata encryptiondata exfiltrationdata store exposuredatabase securityddosddos attackdecoy systemdenial of servicedenial-of-servicedenial-of-service-attackdevice managementdigital oceandionaea attacksdionaea honeypotdistributed attacksencryptionenterprise networkingenumerationeuropeexploitation activityexploited hostexternal-facing-servicefranceftpftp brute forcehackinghoneytrap honeypothttp scannerhttpsidentity & access exploitationindicatorinfected hostinitial accessinitial-accessinjection activityinjection attacksinternet_scannersiot securityiot targetedip-addressipv4ipv4-attackersjapankill-chain exploitationkill-chain reconnaissancelamplamp attacklamp exploitation attemptslateral movementlogin attacklow-riskmailoney honeypotmalicious activitymalicious activity detectedmalicious payloadmalicious softwaremalwaremalware behaviourmalware capturemalware distributionnetworknetwork attacksnetwork discoverynetwork infrastructurenetwork intrusionnetwork probenetwork probingnetwork protocolnetwork reconnaissancenetwork scanningnetwork securitynetwork service scanningnorth americaoceaniaopenctiosintparispassword attackpassword attacksphishingphishing attackphishing trappossible malware distributionpotential vulnerability probingprocess injectionprotocol exploitationransomwarerealtime-wafreconnaissanceremote accessremote servicesresearchedresource hijackingscannerscannersscanning activityscripting attackssecurity operationssecurity policysentrypeer activitysentrypeer botnetservice scansftp attacksftp exploitation attemptssiemsingaporesingapore-regionsip brute forcesip scanningsmtp probingsocial engineeringsocradar honeypotspamsshssh attackssh monitoringsyn scant1018t1021t1021.001t1021.002t1021.004t1040t1041t1046t1055t1059t1059.003t1059.004t1059.007t1071t1071.001t1076t1077t1078t1078.001t1110t1110.001t1110.002t1110.003t1110.004t1133t1190t1203t1204.002t1486t1496t1499t1499.001t1499.002t1499.003t1563t1565t1566t1566.001t1566.002t1566.003t1566.004t1588.004t1589t1590t1595t1595.001t1595.002t1595.003tannertcp protocoltcp-23telecommunicationstelnet threatthreat actorthreat detectionthreat intelligencethreat preventiontor nodeudp port scanunattributed activityunauthorized access attemptunited statesus sourcevoipvoip attackvulnerability scanvulnerability-scanningweb app attackweb application attackweb application scanningweb attackweb exploitationweb traffic

Activity Timeline

1 total obs
Jun 9Jun 9

Threat Activity Heatmap

Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
1
Minimal
30d
1
Minimal
3mo
1
Minimal
Threat ScoreHigh Risk
74
SIGNAL
Signal Score
74%
Confidence
24
Reports
First seenNov 11, 2025
Last seenJun 9, 2026
GeolocationCN
CountryChina
LocationShanghai, Shanghai
ASNAS55990
OrgHuawei Cloud Service
Coords31.2304, 121.4737

VirusTotal

Not checked

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 7 months ago · Last seen 1 day ago
Appeared in 24 threat reports