IOC Radar
IPHighVerifiedSignal 36/100

107.189.10.219

Location
SwitzerlandSwitzerland
Bissen, ME
ASN
AS53667
BuyVM
First Seen
Apr 17, 2026
Last Seen
Apr 24, 2026
Apr 17
First Seen
56d ago
Apr 24
Last Seen
49d ago
4
Reports
source reports
36%
Confidence
high
Found in 4 reports. Confidence: high. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
36%
Signal Score
36 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

10 techniques

Network Information

CountryCHSwitzerland
RegionBissen, ME
ASNAS53667
OrganizationBuyVM

Feed Intelligence Summary

4 reports36% confidence
4
Source reports
36%
Confidence score
Category tags
active scanadministratorschaoschlorinedosednp3encryptdecryptfunctionhaifaiot securityipv4istargetcountrykaijimalwaremodbusnathaniel billnation-state activitynetworknqvbdkproxyransomwareremote accessresearcheds7commt1021.004t1059.004t1070.004t1090.001t1105t1110.001t1190t1210t1222.002t1496targettor nodewritezionsiphon

Activity Timeline

1 total obs
Apr 24Apr 24

Threat Activity Heatmap

· Peak: 2026-04-24
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreLow Risk
36
SIGNAL
Signal Score
36%
Confidence
4
Reports
First seenApr 17, 2026
Last seenApr 24, 2026
Verified IOC
GeolocationCH
CountrySwitzerland
LocationBissen, ME
ASNAS53667
OrgBuyVM
Coords49.7895, 6.0679

VirusTotal

Not checked

WHOIS

description
CC=LU ASN=AS53667 frantech solutions
raw
FranTech Solutions PONYNET-11 (NET-107-189-0-0-1) 107.189.0.0 - 107.189.31.255 BuyVM BUYVM-LUXEMBOURG-03 (NET-107-189-8-0-1) 107.189.8.0 - 107.189.11.255
references
IOCs.2026.csv, https://www.darktrace.com/blog/darktrace-identifies-new-chaos-malware-variant-exploiting-misconfigurations-in-the-cloud

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

high
First detected 1 month ago · Last seen 1 month ago
Appeared in 4 threat reports