IOC Radar
IPMediumSignal 38/100

110.178.41.176

Location
ChinaChina
Taiyuan, Shanxi
ASN
AS4134
Sxtybas
First Seen
Mar 29, 2025
Last Seen
Apr 7, 2026
Mar 29
First Seen
441d ago
Apr 7
Last Seen
67d ago
11
Reports
source reports
38%
Confidence
medium
Found in 11 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
38%
Signal Score
38 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

37 techniques

Network Information

CountryCNChina
RegionTaiyuan, Shanxi
ASNAS4134
OrganizationSxtybas

Feed Intelligence Summary

11 reports38% confidence
11
Source reports
38%
Confidence score
Category tags
active scanactive scanningarmasciiasiabackdoorbotnetbotnet activitybrute forcebrute force attackcensyschinacobaltstrikecoinminercommand and controlcommand executioncommunication technologiescredential accesscredential stuffingcryptocurrencydata exfiltrationdata store exposuredcratddosddos attacksdenial of servicedistributed attacksdonutloaderdropped-by-amadeyelfencodedexecutable fileexploit attemptsexploitation activityftp brute forceguloaderhajimehtahttp brute forceidentity & access exploitationindicatorinfostealerinjection activityinternet of thingsiot botnetiot securityiot/ics attackjpg-base64-loaderladvixlateral movementlnklummastealermalicious powershell activitymalicious softwaremalwaremalware propagationmalware scanningmetastealermipsmirai botnetmobile carriersmobile networksmozimsinetworknetwork probingnetwork scanningnjratopendirpassword attacksprivateloaderprocess injectionps1ransomwareratreconnaissanceredlinestealerremcosratremote accessremote servicesresearchedrev-base64-loaderscriptscripting attackssmtp brute forcesql injection attemptsssh attacksshdkitt1021t1021.001t1027t1046t1055t1059t1059.001t1071t1071.001t1076t1078t1086t1105t1110t1110.001t1110.002t1110.003t1110.004t1133t1187t1190t1199t1204t1204.002t1210t1486t1496t1499.002t1499.003t1563t1565t1566t1588t1595t1595.001t1595.002t1595.003targeting databasetelecom servicestelecommunicationsthreat actortor nodeua-wgetwsgidavxml-opendir

Activity Timeline

1 total obs
Apr 7Apr 7

Threat Activity Heatmap

· Peak: 2026-04-07
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreLow Risk
38
SIGNAL
Signal Score
38%
Confidence
11
Reports
First seenMar 29, 2025
Last seenApr 7, 2026
GeolocationCN
CountryChina
LocationTaiyuan, Shanxi
ASNAS4134
OrgSxtybas
Coords34.7732, 113.7220

VirusTotal

Not checked

WHOIS

raw
inetnum: 110.177.0.0 - 110.179.255.255 netname: sxtybas descr: shanxi telecom taiyuan branch ip node links to customer ip address country: CN admin-c: sa49-ap tech-c: st53-ap abuse-c: AC2532-AP status: ASSIGNED NON-PORTABLE mnt-by: MAINT-CHINANET-SX mnt-irt: IRT-CHINANET-SX last-modified: 2022-01-12T13:25:44Z source: APNIC irt: IRT-CHINANET-SX address: NO.3,SHUMA ROAD,TAIYUAN e-mail: [email protected] abuse-mailbox: [email protected] admin-c: SA49-AP tech-c: ST53-AP auth: # Filtered remarks: [email protected] was validated on 2025-05-08 mnt-by: MAINT-CHINANET-SX last-modified: 2025-05-08T01:02:58Z source: APNIC role: ABUSE CHINANETSX country: ZZ address: NO.3,SHUMA ROAD,TAIYUAN phone: +000000000 e-mail: [email protected] admin-c: SA49-AP tech-c: ST53-AP nic-hdl: AC2532-AP remarks: Generated from irt object IRT-CHINANET-SX remarks: [email protected] was validated on 2025-05-08 abuse-mailbox: [email protected] mnt-by: APNIC-ABUSE last-modified: 2025-05-08T01:03:21Z source: APNIC person: shanxitele admin nic-hdl: SA49-AP e-mail: [email protected] address: no.217 nanneihuan street address: taiyuan city 030012 phone: +86-351-5609863 fax-no: +86-351-5609868 country: cn mnt-by: MAINT-CHINANET-SX last-modified: 2008-09-04T08:55:34Z source: APNIC person: shanxitele tech nic-hdl: ST53-AP e-mail: [email protected] address: no.217 nanneihuan street address: taiyuan city 030012 phone: +86-351-5609963 fax-no: +86-351-5609868 country: cn mnt-by: MAINT-CHINATELECOM-SX last-modified: 2008-09-04T07:31:30Z source: APNIC
references
https://urlhaus.abuse.ch/browse/

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 2 months ago
Appeared in 11 threat reports