IPMediumSignal 49/100
104.168.138.233
Location
Seattle, Washington
ASN
AS54290
Hostwinds LLC
First Seen
May 29, 2025
Last Seen
Jun 7, 2026
Found in 9 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
49%
Signal Score
49 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Network Information
Country
United States
RegionSeattle, Washington
ASNAS54290
OrganizationHostwinds LLC
Feed Intelligence Summary
9 reports49% confidence
9
Source reports
49%
Confidence score
Category tags
abuseaccount compromiseactive scanactive scanningattackaustraliabad reputationbad web botbotnetbotnet activitybrute forcebrute force attackbrute force attackerbrute force attacksbrute force attemptsbrute-forcecloud infrastructurecloud infrastructure attackcloud servicescommand and controlcommand injectioncommunication protocolcowriecowrie honeypotcredential accesscredential access attemptcredential attackcredential guessingcredential stuffingdata encryptiondata exfiltrationdata store exposuredatabase attackdatabase securityddosddos attack indicatorsdecoy systemdenial of servicedigital oceandionaeadionaea honeypotdnsdns attackencryptioneuropeexploitexploit attemptsexploit kit activityexploit public-facing applicationexploitation activityexploitation attemptexternal threatfattftpftp brute forceftp scanhackinghoneytrap honeypothttp brute forcehttp scanhttp scannerhttpsidentity & access exploitationindicatorinitial accessinjection activityinternet background noiseinternet wide scaninternet-facinginternet-wide scanintrusion detectioniocipv4ipv4 addresseslateral movementlondonmailoney honeypotmalicious activitymalicious softwaremalwaremalware behaviourmalware capturemalware distributionnetworknetwork enumerationnetwork intrusion attemptsnetwork probingnetwork protocolnetwork reconnaissancenetwork scanningnetwork scanning activitynetwork securitynetwork traffic analysisnorth americaoceaniap0fpassword attacksphishingphishing attackphishing trapportscanprocess injectionprotocol exploitationransomwareransomware activityrdp scanreconnaissanceremote accessremote servicesresearchedresource hijackingscannerscannersscanning activityscripting attackssensor-taggedsentrypeer botnetserver exploitationservice scansmtpsmtp brute forcesmtp scanspamsql injectionsql injection attemptsssh attackssh monitoringssh scansystem accesst1021t1021.001t1021.002t1040t1046t1055t1059t1059.003t1059.007t1071t1071.001t1076t1077t1078t1110t1110.001t1110.002t1110.003t1110.004t1133t1190t1203t1486t1496t1499.001t1499.002t1505.002t1563t1565t1589t1590t1592t1595t1595.001t1595.002t1595.003tannertargeting databasetcp scantelecommunicationstelnet scantelnet threatthreat actorthreat detectionthreat intelligencethreat intelligence feedtor nodetpotudp scanunited kingdomunited statesunknown actorunknown threat actorusvnc protocolvoipvoip attackvulnerability scanvultrweb app attackweb application attackweb application attacksweb attackweb exploitweb exploitationweb traffic
Activity Timeline
Jun 7Jun 7
Threat Activity Heatmap
· Peak: 2026-06-07LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Threat ScoreMedium Risk
49
SIGNAL
Signal Score
49%
Confidence
9
Reports
First seenMay 29, 2025
Last seenJun 7, 2026
GeolocationUS
CountryUnited States
LocationSeattle, Washington
ASNAS54290
OrgHostwinds LLC
Coords47.6043, -122.3298
VirusTotal
Not checked
WHOIS
- description
- IPv4 hosts detected port scanning Vultr Paris (France) honeypot
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 1 year ago · Last seen 7 days ago
Appeared in 9 threat reports