IOC Radar
IPMediumSignal 86/100

107.172.204.15

Location
United StatesUnited States
Los Angeles, California
ASN
AS36352
reverseproxies.com
First Seen
May 22, 2026
Last Seen
Jun 8, 2026
May 22
First Seen
24d ago
Jun 8
Last Seen
7d ago
18
Reports
source reports
86%
Confidence
medium
Found in 18 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
86%
Signal Score
86 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

1 techniques

Network Information

CountryUSUnited States
RegionLos Angeles, California
ASNAS36352
Organizationreverseproxies.com

IP Category

VPN
VPN exit node

Feed Intelligence Summary

18 reports86% confidence
18
Source reports
86%
Confidence score
Category tags
abuseactive scanbad reputationbad web botblocklist_allbotnetbotnet activitybrute forcebrute force attackerbrute-forcebruteforcecowrieddosddos attackdigital oceandionaeaexploitation activityexploited hostfattftp brute-forcehackinginbound scanindicatorinjection activityiot securityiot targetedmalicious ipmirainetworknorth americap0fphishingping of deathportscanransomwareresearchedsakura httpscanscannerscannerssensor-taggedservice scansocradar honeypotsql injectionsshssh attackt1595tannertargeting databasetcptelnettpotunited statesusvpnvpn ipvultrweb app attack

Activity Timeline

1 total obs
Jun 8Jun 8

Threat Activity Heatmap

· Peak: 2026-06-08
Less
More
Mon
Wed
Fri
Jun
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Threat ScoreHigh Risk
86
SIGNAL
Signal Score
86%
Confidence
18
Reports
First seenMay 22, 2026
Last seenJun 8, 2026
GeolocationUS
CountryUnited States
LocationLos Angeles, California
ASNAS36352
Orgreverseproxies.com
Coords34.0549, -118.2430
VPN

VirusTotal

Not checked

WHOIS

description
IPv4 hosts detected port scanning Vultr Melbourne (Australia) honeypot
raw
NetRange: 107.172.0.0 - 107.175.255.255 CIDR: 107.172.0.0/14 NetName: CC-17 NetHandle: NET-107-172-0-0-1 Parent: NET107 (NET-107-0-0-0-0) NetType: Direct Allocation OriginAS: Organization: HostPapa (HOSTP-7) RegDate: 2013-12-27 Updated: 2024-02-02 Comment: Geofeed https://geofeeds.oniaas.io/geofeeds.csv Ref: https://rdap.arin.net/registry/ip/107.172.0.0 OrgName: HostPapa OrgId: HOSTP-7 Address: 325 Delaware Avenue Address: Suite 300 City: Buffalo StateProv: NY PostalCode: 14202 Country: US RegDate: 2016-06-06 Updated: 2025-10-05 Ref: https://rdap.arin.net/registry/entity/HOSTP-7 OrgAbuseHandle: NETAB23-ARIN OrgAbuseName: NETABUSE OrgAbusePhone: +1-905-315-3455 OrgAbuseEmail: [email protected] OrgAbuseRef: https://rdap.arin.net/registry/entity/NETAB23-ARIN OrgTechHandle: NETTE9-ARIN OrgTechName: NETTECH OrgTechPhone: +1-905-315-3455 OrgTechEmail: [email protected] OrgTechRef: https://rdap.arin.net/registry/entity/NETTE9-ARIN RAbuseHandle: NETAB27-ARIN RAbuseName: NETABUSE-COLOCROSSING RAbusePhone: +1-800-518-9716 RAbuseEmail: [email protected] RAbuseRef: https://rdap.arin.net/registry/entity/NETAB27-ARIN RTechHandle: NETTE11-ARIN RTechName: NETTECH-COLOCROSSING RTechPhone: +1-800-518-9716 RTechEmail: [email protected] RTechRef: https://rdap.arin.net/registry/entity/NETTE11-ARIN

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 24 days ago · Last seen 7 days ago
Appeared in 18 threat reports