IOC Radar
IPLowSignal 40/100

103.13.231.249

Location
ThailandThailand
Bangkok, Krung Thep Maha Nakhon
ASN
AS23884
CH-CH
First Seen
Oct 28, 2023
Last Seen
Jun 7, 2026
Oct 28
First Seen
956d ago
Jun 7
Last Seen
4d ago
6
Reports
source reports
40%
Confidence
low
0/91
VirusTotal
detections
Found in 6 reports. Confidence: low. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
40%
Signal Score
40 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

29 techniques

Network Information

CountryTHThailand
RegionBangkok, Krung Thep Maha Nakhon
ASNAS23884
OrganizationCH-CH

Feed Intelligence Summary

6 reports40% confidence
6
Source reports
40%
Confidence score
Category tags
abuseactive scanactive scanningasiaaustraliaautomated attacksbad reputationbotnetbotnet activitybrute forcebrute force attackcommunication protocolcompromised hostcowrie honeypotcredential accesscredential guessingcredential stuffingdata encryptiondata exfiltrationdata store exposuredatabase securitydecoy systemdionaea honeypotencryptionexploitation activityfattftphackinghoneytrap honeypothttp scanneridentity & access exploitationindicatorinjection activityinjection attackslateral movementmailoney honeypotmalicious activitymalicious softwaremalwaremalware behaviourmalware capturemanualnetworknetwork probingnetwork protocolnetwork scanningnetwork securityoceaniap0fpassword attacksphishingphishing attackphishing trapprocess injectionprotocol exploitationreconnaissanceremote accessremote servicesresearchedresource hijackingscannersensor-taggedsentrypeer botnetsmtpssh attackssh monitoringt1021.001t1021.002t1040t1046t1055t1059t1059.003t1071t1071.001t1076t1077t1078t1110t1110.001t1110.002t1110.003t1110.004t1190t1210t1486t1496t1499.001t1499.002t1563t1565t1595t1595.001t1595.002t1595.003tannertelecommunicationstelnet threatththailandthreat actorthreat detectionthreat intelligencetor nodetpotvoipvoip attackweb traffic

Activity Timeline

1 total obs
Jun 7Jun 7

Threat Activity Heatmap

· Peak: 2026-06-07
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
1
Minimal
30d
1
Minimal
3mo
1
Minimal
Threat ScoreMedium Risk
40
SIGNAL
Signal Score
40%
Confidence
6
Reports
First seenOct 28, 2023
Last seenJun 7, 2026
GeolocationTH
CountryThailand
LocationBangkok, Krung Thep Maha Nakhon
ASNAS23884
OrgCH-CH
Coords13.7551, 100.5057

VirusTotal

0/ 91vendors flagged
0% detection rateJun 7, 2026

WHOIS

raw
inetnum: 103.13.231.0 - 103.13.231.255 netname: PUBLIC-TH descr: CH-CH country: TH geoloc: 13.726943 100.514036 admin-c: CHCA1-AP tech-c: CHCA1-AP abuse-c: AC1621-AP status: ASSIGNED NON-PORTABLE mnt-by: MAINT-CLOUDHOSTING-TH mnt-irt: IRT-CLOUDHOSTING-TH last-modified: 2025-07-23T15:00:43Z geofeed: https://ns1.vpshispeed.com/geofeed.csv source: APNIC irt: IRT-CLOUDHOSTING-TH address: 25/1 Moo 2, T. Pabong, A.Sarapee Chiang Mai 50140 e-mail: [email protected] abuse-mailbox: [email protected] admin-c: CHCA1-AP tech-c: CHCA1-AP auth: # Filtered remarks: [email protected] was validated on 2025-07-22 mnt-by: MAINT-CLOUDHOSTING-TH last-modified: 2025-07-22T13:19:23Z source: APNIC role: ABUSE CLOUDHOSTINGTH country: ZZ address: 25/1 Moo 2, T. Pabong, A.Sarapee Chiang Mai 50140 phone: +000000000 e-mail: [email protected] admin-c: CHCA1-AP tech-c: CHCA1-AP nic-hdl: AC1621-AP remarks: Generated from irt object IRT-CLOUDHOSTING-TH remarks: [email protected] was validated on 2025-07-22 abuse-mailbox: [email protected] mnt-by: APNIC-ABUSE last-modified: 2025-07-22T13:19:31Z source: APNIC role: Cloud Hosting CoLtd administrator address: 25/1 Moo 2, T. Pabong, A.Sarapee Chiang Mai 50140 country: TH phone: +66-8-2018-9138 fax-no: +66-8-2018-9138 e-mail: [email protected] admin-c: CHCA1-AP tech-c: CHCA1-AP nic-hdl: CHCA1-AP mnt-by: MAINT-CLOUDHOSTING-TH last-modified: 2014-11-27T09:34:45Z source: APNIC

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

low
First detected 2 years ago · Last seen 4 days ago
Appeared in 6 threat reports