IOC Radar
IPMediumSignal 100/100

106.14.213.29

Location
ChinaChina
Shanghai, Shanghai
ASN
AS37963
Aliyun Computing Co., LTD
First Seen
Aug 9, 2024
Last Seen
May 10, 2026
Aug 9
First Seen
679d ago
May 10
Last Seen
40d ago
16
Reports
source reports
99%
Confidence
medium
Found in 16 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
99%
Signal Score
100 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

42 techniques

Network Information

CountryCNChina
RegionShanghai, Shanghai
ASNAS37963
OrganizationAliyun Computing Co., LTD

IP Category

Hosting
Hosting provider

Feed Intelligence Summary

16 reports99% confidence
16
Source reports
99%
Confidence score
Category tags
active scanningadversary simulation toolamadeyantiaptasiaasyncrataurora stealerauto-generated securityavemariaratazorultb5tubeaconbeaconing activitybotnetbrute forcec2c2 communicationc2 frameworkc2 serverchinacncobalt strikecobaltstrikecoinminercommand and controlcompromised hostcompromised hostscredential harvestingdanabotdarkgatedarksidedarktortilladata encryptiondata exfiltrationdata theftddosdharmadistributed attacksdonutdridexearthwormexploitextortiongetshellguloaderhackingindicatorinfrastructure acquisitionreconnaissanceingress tool transferioclaplasclipperlateral movementlateral movement techniquesloaderlokilummastealermalicious linksmalicious softwaremalwaremalware distributionmanualmetasploitmetastealermozineshtanetworknetwork traffic analysisparallaxratpayloadpayload deploymentpayload generationpenetration testing toolphishingphishing attackphonkpiratestealerpost-exploitationpost-exploitation activitiesprocess injectionpurecrypterqakbotquasarratraccoonstealerransomwarereconnaissanceredlineredlinestealerredosdruremcosratresearchedrevengeratscannersliversocial engineeringspamspynotestealcstormkittysystem disruptionsystembct1003t1016t1018t1027t1041t1047t1055t1059t1059.001t1071t1071.001t1078t1083t1090t1090.001t1105t1189t1190t1204t1204.001t1210t1486t1490t1496t1499.002t1499.003t1565t1566t1566.001t1566.002t1566.003t1567t1567.002t1568.002t1569.002t1573t1573.001t1587.001t1590.001t1595.001t1595.002t1595.003tofseetriadatrojan malwarevenomratvidarvirusweb securitywingo

Activity Timeline

1 total obs
May 10May 10

Threat Activity Heatmap

· Peak: 2026-05-10
Less
More
Mon
Wed
Fri
Jun
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreHigh Risk
100
SIGNAL
Signal Score
99%
Confidence
16
Reports
First seenAug 9, 2024
Last seenMay 10, 2026
GeolocationCN
CountryChina
LocationShanghai, Shanghai
ASNAS37963
OrgAliyun Computing Co., LTD
Coords31.2222, 121.4581
Hosting

VirusTotal

Not checked

WHOIS

description
Imported indicator
references
https://raw.githubusercontent.com/openphish/public_feed/refs/heads/main/feed.txt, https://urlhaus.abuse.ch/downloads/text_online/, https://www.shodan.io/search?query=product%3A%22Cobalt+Strike+Beacon%22, https://urlhaus.abuse.ch/downloads/json_online/

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 1 month ago
Appeared in 16 threat reports