IOC Radar
IPMediumSignal 100/100

103.91.85.51

Location
IndiaIndia
Namakkal, TN
ASN
AS58898
Rainbow Internet Teleservices Private Limited
First Seen
Nov 29, 2023
Last Seen
Jan 30, 2026
Nov 29
First Seen
930d ago
Jan 30
Last Seen
136d ago
15
Reports
source reports
99%
Confidence
medium
Found in 15 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
99%
Signal Score
100 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

38 techniques

Network Information

CountryINIndia
RegionNamakkal, TN
ASNAS58898
OrganizationRainbow Internet Teleservices Private Limited

Feed Intelligence Summary

15 reports99% confidence
15
Source reports
99%
Confidence score
Category tags
abuseaccess controlactive scanningasiaattackbotnetbrute forcebrute force attackc2cisco devicecommand and controlcommunication protocolcommunication technologiescompromised hostcowrie honeypotcredential accesscredential harvestingcredential stuffingdata exfiltrationddos attackddos attacksdecoy systemdenial of servicedevice managementdistributed attacksenterprise networkingeuropeexploited hostftphoneytrap honeypothttp scannerinindiaindicatorinfrastructure acquisitionreconnaissanceinitial accessinitiator ipinternet of thingsintrusion detectioniot botnetiot/ics attackkfsensor honeypotlamplateral movementloginmailoney honeypotmalicious activitymalicious softwaremalwaremalware capturemanualmirai botnetmobile carriersmobile networksnetworknetwork attacksnetwork infrastructurenetwork intrusionnetwork protocolnetwork scanningnetwork securitynetwork service scanningnorth americapassword attacksphishingphishing attackphishing trapprocess injectionprotocol exploitationreconnaissanceremote accessremote servicesresearchedscanscannersecurity operationssecurity policysftp attacksocial engineeringssh attackssh monitoringt1018t1021t1021.001t1021.004t1040t1041t1046t1055t1059t1059.001t1071t1071.001t1076t1078t1110t1110.001t1110.002t1110.003t1110.004t1190t1486t1496t1499.001t1499.002t1499.003t1563t1565t1566.001t1566.002t1566.003t1566.004t1573t1587.001t1590.001t1595t1595.001t1595.002t1595.003tcp protocoltcp/23telecom servicestelecommunicationstelnet threatthreat actorthreat detectionthreat intelligencethreat preventionunited kingdomunited statesweb traffic

Activity Timeline

1 total obs
Jan 30Jan 30

Threat Activity Heatmap

· Peak: 2026-01-30
Less
More
Mon
Wed
Fri
Jun
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Threat ScoreHigh Risk
100
SIGNAL
Signal Score
99%
Confidence
15
Reports
First seenNov 29, 2023
Last seenJan 30, 2026
GeolocationIN
CountryIndia
LocationNamakkal, TN
ASNAS58898
OrgRainbow Internet Teleservices Private Limited
Coords11.2203, 78.1663

VirusTotal

Not checked

WHOIS

description
Logged 1 visit on 1 honeypot. Duration: 31.5s, did not supply credentials
raw
inetnum: 103.91.84.0 - 103.91.85.255 netname: RAINBOW descr: Rainbow Internet Teleservices Private Limited admin-c: MN685-AP tech-c: MN685-AP country: IN mnt-by: MAINT-IN-IRINN mnt-lower: MAINT-IN-IRINN mnt-irt: IRT-RAINBOW-IN mnt-routes: MAINT-IN-RAINBOW mnt-routes: MAINT-IN-IRINN status: ALLOCATED PORTABLE last-modified: 2025-08-11T22:49:45Z source: APNIC irt: IRT-RAINBOW-IN address: 34E,ARTHANARI SCHOOL STREET,S.P.PUDUR.NAMAKKAL,Namakkal,Tamil Nadu-637001 e-mail: [email protected] abuse-mailbox: [email protected] admin-c: MN685-AP tech-c: MN685-AP auth: # Filtered mnt-by: MAINT-IN-RAINBOW last-modified: 2025-09-05T00:12:50Z source: APNIC role: Manager noc address: 34E,ARTHANARI SCHOOL STREET,S.P.PUDUR.NAMAKKAL,Namakkal,Tamil Nadu-637001 country: IN phone: +91 914446741111 e-mail: [email protected] admin-c: GR370-AP tech-c: GR370-AP nic-hdl: MN685-AP mnt-by: MAINT-IN-RAINBOW last-modified: 2017-04-25T05:18:05Z source: APNIC
references
https://malware-filter.gitlab.io/malware-filter/botnet-filter.txt, https://github.com/telekom-security/tpotce, https://raw.githubusercontent.com/ahamed-rizvan/IOCs/refs/heads/main/Malicous%20IP%20Address.txt

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 2 years ago · Last seen 4 months ago
Appeared in 15 threat reports