IOC Radar
IPMediumSignal 49/100

104.168.138.233

Location
United StatesUnited States
Seattle, Washington
ASN
AS54290
Hostwinds LLC
First Seen
May 29, 2025
Last Seen
Jun 7, 2026
May 29
First Seen
381d ago
Jun 7
Last Seen
7d ago
9
Reports
source reports
49%
Confidence
medium
Found in 9 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
49%
Signal Score
49 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

36 techniques

Network Information

CountryUSUnited States
RegionSeattle, Washington
ASNAS54290
OrganizationHostwinds LLC

Feed Intelligence Summary

9 reports49% confidence
9
Source reports
49%
Confidence score
Category tags
abuseaccount compromiseactive scanactive scanningattackaustraliabad reputationbad web botbotnetbotnet activitybrute forcebrute force attackbrute force attackerbrute force attacksbrute force attemptsbrute-forcecloud infrastructurecloud infrastructure attackcloud servicescommand and controlcommand injectioncommunication protocolcowriecowrie honeypotcredential accesscredential access attemptcredential attackcredential guessingcredential stuffingdata encryptiondata exfiltrationdata store exposuredatabase attackdatabase securityddosddos attack indicatorsdecoy systemdenial of servicedigital oceandionaeadionaea honeypotdnsdns attackencryptioneuropeexploitexploit attemptsexploit kit activityexploit public-facing applicationexploitation activityexploitation attemptexternal threatfattftpftp brute forceftp scanhackinghoneytrap honeypothttp brute forcehttp scanhttp scannerhttpsidentity & access exploitationindicatorinitial accessinjection activityinternet background noiseinternet wide scaninternet-facinginternet-wide scanintrusion detectioniocipv4ipv4 addresseslateral movementlondonmailoney honeypotmalicious activitymalicious softwaremalwaremalware behaviourmalware capturemalware distributionnetworknetwork enumerationnetwork intrusion attemptsnetwork probingnetwork protocolnetwork reconnaissancenetwork scanningnetwork scanning activitynetwork securitynetwork traffic analysisnorth americaoceaniap0fpassword attacksphishingphishing attackphishing trapportscanprocess injectionprotocol exploitationransomwareransomware activityrdp scanreconnaissanceremote accessremote servicesresearchedresource hijackingscannerscannersscanning activityscripting attackssensor-taggedsentrypeer botnetserver exploitationservice scansmtpsmtp brute forcesmtp scanspamsql injectionsql injection attemptsssh attackssh monitoringssh scansystem accesst1021t1021.001t1021.002t1040t1046t1055t1059t1059.003t1059.007t1071t1071.001t1076t1077t1078t1110t1110.001t1110.002t1110.003t1110.004t1133t1190t1203t1486t1496t1499.001t1499.002t1505.002t1563t1565t1589t1590t1592t1595t1595.001t1595.002t1595.003tannertargeting databasetcp scantelecommunicationstelnet scantelnet threatthreat actorthreat detectionthreat intelligencethreat intelligence feedtor nodetpotudp scanunited kingdomunited statesunknown actorunknown threat actorusvnc protocolvoipvoip attackvulnerability scanvultrweb app attackweb application attackweb application attacksweb attackweb exploitweb exploitationweb traffic

Activity Timeline

1 total obs
Jun 7Jun 7

Threat Activity Heatmap

· Peak: 2026-06-07
Less
More
Mon
Wed
Fri
Jun
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Threat ScoreMedium Risk
49
SIGNAL
Signal Score
49%
Confidence
9
Reports
First seenMay 29, 2025
Last seenJun 7, 2026
GeolocationUS
CountryUnited States
LocationSeattle, Washington
ASNAS54290
OrgHostwinds LLC
Coords47.6043, -122.3298

VirusTotal

Not checked

WHOIS

description
IPv4 hosts detected port scanning Vultr Paris (France) honeypot

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 7 days ago
Appeared in 9 threat reports