IOC Radar
IPMediumSignal 43/100

103.178.171.36

Location
IndonesiaIndonesia
Pacitan, Jakarta Raya
ASN
AS139952
PT Trisari Data Indonusa
First Seen
Dec 17, 2024
Last Seen
May 27, 2026
Dec 17
First Seen
543d ago
May 27
Last Seen
17d ago
8
Reports
source reports
43%
Confidence
medium
Found in 8 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
43%
Signal Score
43 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

27 techniques

Network Information

CountryIDIndonesia
RegionPacitan, Jakarta Raya
ASNAS139952
OrganizationPT Trisari Data Indonusa

IP Category

Proxy
Proxy server

Feed Intelligence Summary

8 reports43% confidence
8
Source reports
43%
Confidence score
Category tags
active scanactive scanningasiabotnetbotnet iocsbotnet miraibotnet propagationbrute forcecommand and controlcommunication protocolconnected devicescredential accesscredential stuffingdata exfiltrationddosddos attackddos attacksdenial of servicedevice managementdistributed attacksexploitationgorillabothackingidindonesiaindustrial iotinitial accessinternet of thingsiocsiot analyticsiot applicationsiot botnetiot devicesiot platformsiot securityiot/ics attackipv4irclinuxmalicious softwaremalwaremirai botnetmirai internetnetworknetwork attacksnetwork protocolnetwork scanningnetwork securityoutlawprocess injectionprotocol exploitationproxyreconnaissanceresearchedscannerscanning activitysmart devicesssh attackt1021t1021.001t1040t1053.005t1055t1059t1059.004t1071t1071.001t1078t1078.001t1105t1110.002t1190t1203t1486t1496t1497t1497.001t1498.001t1499.001t1499.002t1499.003t1565t1595.001t1595.002t1595.003tcp protocoltelnet threatthingstwitterweb application attackweb exploitationxmrig

Activity Timeline

1 total obs
May 27May 27

Threat Activity Heatmap

· Peak: 2026-05-27
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Threat ScoreMedium Risk
43
SIGNAL
Signal Score
43%
Confidence
8
Reports
First seenDec 17, 2024
Last seenMay 27, 2026
GeolocationID
CountryIndonesia
LocationPacitan, Jakarta Raya
ASNAS139952
OrgPT Trisari Data Indonusa
Coords0.0000, 0.0000
Proxy

VirusTotal

Not checked

WHOIS

raw
inetnum: 103.178.170.0 - 103.178.171.255 netname: IDNIC-PRADANAKOMINKA-ID descr: PT Pradana Komunika Indonesia descr: Corporate / Direct Member IDNIC descr: Gedung STC Senayan Lt.4 No.31-34 descr: Gelora, Tanah Abang descr: Jakarta Pusat, DKI Jakarta 10270 admin-c: HW2246-AP tech-c: HW2246-AP remarks: Send Spam & Abuse Report to: [email protected] country: ID mnt-by: MNT-APJII-ID mnt-lower: MAINT-ID-PRADANAKOMINKA mnt-irt: IRT-PRADANAKOMINKA-ID mnt-routes: MAINT-ID-PRADANAKOMINKA status: ALLOCATED PORTABLE last-modified: 2021-12-28T09:25:44Z source: APNIC irt: IRT-PRADANAKOMINKA-ID address: PT Pradana Komunika Indonesia address: Gedung STC Senayan Lt.4 No.31-34 address: Gelora, Tanah Abang address: Jakarta Pusat, DKI Jakarta 10270 e-mail: [email protected] abuse-mailbox: [email protected] admin-c: HW2246-AP tech-c: HW2246-AP auth: # Filtered mnt-by: MAINT-ID-PRADANAKOMINKA last-modified: 2021-12-27T09:58:51Z source: APNIC person: Hendra Wijaya address: Gedung STC Senayan Lt.4 No.31-34 address: Jl. Asia Afrika Pintu IX Gelora address: Gelora, Tanah Abang address: Jakarta Pusat, DKI Jakarta 10270 country: ID phone: +62-856-9457-6984 e-mail: [email protected] nic-hdl: HW2246-AP mnt-by: MAINT-ID-PRADANAKOMINKA last-modified: 2021-12-27T09:59:06Z source: APNIC inetnum: 103.178.171.0 - 103.178.171.255 netname: TRIDATA-ID descr: PT Trisari Data Indonusa descr: Internet Service Provider descr: Perum Bumi Mas 1 Blok P no 1 descr: Kel. Mojorejo Kec. Taman descr: Kota Madiun, Jawa Timur country: ID admin-c: SS3921-AP tech-c: SS3921-AP status: ALLOCATED NON-PORTABLE mnt-by: MAINT-ID-TRIDATA mnt-irt: IRT-TRIDATA-ID last-modified: 2022-01-17T07:27:20Z source: IDNIC irt: IRT-TRIDATA-ID address: PT Trisari Data Indonusa address: Perum Bumi Mas 1 Blok P no 1 address: Kel. Mojorejo Kec. Taman address: Kota Madiun Jawa Timur e-mail: [email protected] abuse-mailbox: [email protected] admin-c: SS3921-AP tech-c: SS3921-AP auth: # Filtered mnt-by: MAINT-ID-TRIDATA last-modified: 2021-02-17T08:24:08Z source: IDNIC person: Sugianto Sugianto address: Jl. Taman Raya No 1 address: Kel. Banjarejo Kec. Taman Kota Madiun address: Jawa Timur, Indonesia country: ID phone: +62-351-2810501 e-mail: [email protected] nic-hdl: SS3921-AP mnt-by: MAINT-ID-TRIDATA fax-no: +62-351-2810501 last-modified: 2021-02-17T08:24:22Z source: IDNIC route: 103.178.171.0/24 descr: Route Object of PT Trisari Data Indonusa descr: Internet Service Provider descr: Madiun, Jawa Timur origin: AS139952 mnt-by: MAINT-ID-TRIDATA last-modified: 2022-01-17T07:31:04Z source: IDNIC
references
https://1275.ru/ioc/gs-25-19131-mirai-botnet-iocs_11023, https://1275.ru/ioc/gs-25-19129-mirai-botnet-iocs_11015, https://1275.ru/ioc/gs-25-19128-mirai-botnet-iocs_11001, https://1275.ru/ioc/gs-25-19127-mirai-botnet-iocs_10989, https://1275.ru/ioc/gs-25-19125-mirai-botnet-iocs_10956, https://1275.ru/ioc/gs-25-19126-mirai-botnet-iocs_10970, https://1275.ru/ioc/gs-25-18122-mirai-botnet-iocs_10913, https://1275.ru/ioc/gs-25-18120-mirai-botnet-iocs_10854, https://1275.ru/ioc/gs-25-18119-mirai-botnet-iocs_10829, https://1275.ru/ioc/gs-25-18118-mirai-botnet-iocs_10825, https://1275.ru/ioc/gs-25-17115-mirai-botnet-iocs-2_10696, https://1275.ru/ioc/gs-25-17115-mirai-botnet-iocs_10682, https://1275.ru/ioc/gs-25-17113-mirai-botnet-iocs_10658, https://1275.ru/ioc/gs-25-17112-mirai-botnet-iocs_10640, https://1275.ru/ioc/gs-25-1490-mirai-botnet-iocs_10200

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 17 days ago
Appeared in 8 threat reports