IOC Radar
IPMediumSignal 62/100

103.194.184.192

Location
Hong KongHong Kong
Queen's Terrace, Central and Western District
ASN
AS45753
Netsec
First Seen
Apr 16, 2026
Last Seen
Apr 22, 2026
Apr 16
First Seen
61d ago
Apr 22
Last Seen
55d ago
5
Reports
source reports
62%
Confidence
medium
1/91
VirusTotal
detections
Found in 5 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
62%
Signal Score
62 / 100
IDS Rule
No
Threat Context
Tags

Network Information

CountryHKHong Kong
RegionQueen's Terrace, Central and Western District
ASNAS45753
OrganizationNetsec

Feed Intelligence Summary

5 reports62% confidence
5
Source reports
62%
Confidence score
Category tags
abuseactive scanasiabad reputationbrute forcebrute force attackerdigital oceanhong kongindicatornetworkportscanresearchedscannersservice scan

Activity Timeline

1 total obs
Apr 22Apr 22

Threat Activity Heatmap

· Peak: 2026-04-22
Less
More
Mon
Wed
Fri
Jun
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Intelligence SummaryAI Generated

The IP address `103.194.184.192` is highly significant as it represents an actively malicious IP address involved in aggressive reconnaissance and brute-force activities. Its high threat score of 61.99 indicates a substantial and immediate risk to organizational assets. If left unaddressed, connections from this IP could facilitate unauthorized access, lead to account compromises, and serve as a precursor to more severe attacks such as data exfiltration or ransomware deployment. This indicator d…

Threat ScoreMedium Risk
62
SIGNAL
Signal Score
62%
Confidence
5
Reports
First seenApr 16, 2026
Last seenApr 22, 2026
GeolocationHK
CountryHong Kong
LocationQueen's Terrace, Central and Western District
ASNAS45753
OrgNetsec
Coords22.2578, 114.1657

VirusTotal

1/ 91vendors flagged
1% detection rateJun 5, 2026

WHOIS

description
IPv4 hosts detected port scanning DigitalOcean London (UK) honeypot
raw
inetnum: 103.194.184.0 - 103.194.185.255 netname: Netsec descr: Netsec country: HK admin-c: NN541-AP tech-c: NN541-AP abuse-c: AM2614-AP status: ALLOCATED NON-PORTABLE mnt-by: MAINT-M8CLOUDLIMITED-HK mnt-irt: IRT-M8CLOUDLIMITED-HK last-modified: 2025-05-17T10:55:11Z source: APNIC irt: IRT-M8CLOUDLIMITED-HK address: RM 1502, 15/F, NAN DAO COMM BLDG, NO. 359-361 QUEEN'S ROAD,, CENTRAL, , SHEUNG WAN, , HONG KONG., HO e-mail: [email protected] abuse-mailbox: [email protected] admin-c: RCLA8-AP tech-c: RCLA8-AP auth: # Filtered remarks: [email protected] was validated on 2025-11-18 mnt-by: MAINT-M8CLOUDLIMITED-HK last-modified: 2025-11-18T02:29:03Z source: APNIC role: ABUSE M8CLOUDLIMITEDHK country: ZZ address: RM 1502, 15/F, NAN DAO COMM BLDG, NO. 359-361 QUEEN'S ROAD,, CENTRAL, , SHEUNG WAN, , HONG KONG., HO phone: +000000000 e-mail: [email protected] admin-c: RCLA8-AP tech-c: RCLA8-AP nic-hdl: AM2614-AP remarks: Generated from irt object IRT-M8CLOUDLIMITED-HK remarks: [email protected] was validated on 2025-11-18 abuse-mailbox: [email protected] mnt-by: APNIC-ABUSE last-modified: 2025-11-18T03:11:17Z source: APNIC role: NETSEC NOC address: Suite 1007, 10/F, The Bay Hub, 17 Kai Cheung Rd, Kowloon Bay country: HK phone: +85227511100 e-mail: [email protected] admin-c: NN541-AP tech-c: NN541-AP nic-hdl: NN541-AP mnt-by: MAINT-NETSEC-HK last-modified: 2025-03-14T05:55:40Z source: APNIC route: 103.194.184.0/24 origin: AS45753 descr: 8 CLOUD LIMITED RM 1502, 15/F, NAN DAO COMM BLDG NO. 359-361 QUEEN'S ROAD, CENTRAL, , SHEUNG WAN, , HONG KONG. mnt-by: MAINT-M8CLOUDLIMITED-HK last-modified: 2021-10-15T03:05:54Z source: APNIC
references
https://jamesbrine.com.au/digitaloceanlondon-portscan-bruteforce-ip-list-2026-04-15/, https://jamesbrine.com.au

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 2 months ago · Last seen 1 month ago
Appeared in 5 threat reports