IPMediumSignal 38/100
110.178.41.176
Location
Taiyuan, Shanxi
ASN
AS4134
Sxtybas
First Seen
Mar 29, 2025
Last Seen
Apr 7, 2026
Found in 11 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
38%
Signal Score
38 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Network Information
Country
China
RegionTaiyuan, Shanxi
ASNAS4134
OrganizationSxtybas
Feed Intelligence Summary
11 reports38% confidence
11
Source reports
38%
Confidence score
Category tags
active scanactive scanningarmasciiasiabackdoorbotnetbotnet activitybrute forcebrute force attackcensyschinacobaltstrikecoinminercommand and controlcommand executioncommunication technologiescredential accesscredential stuffingcryptocurrencydata exfiltrationdata store exposuredcratddosddos attacksdenial of servicedistributed attacksdonutloaderdropped-by-amadeyelfencodedexecutable fileexploit attemptsexploitation activityftp brute forceguloaderhajimehtahttp brute forceidentity & access exploitationindicatorinfostealerinjection activityinternet of thingsiot botnetiot securityiot/ics attackjpg-base64-loaderladvixlateral movementlnklummastealermalicious powershell activitymalicious softwaremalwaremalware propagationmalware scanningmetastealermipsmirai botnetmobile carriersmobile networksmozimsinetworknetwork probingnetwork scanningnjratopendirpassword attacksprivateloaderprocess injectionps1ransomwareratreconnaissanceredlinestealerremcosratremote accessremote servicesresearchedrev-base64-loaderscriptscripting attackssmtp brute forcesql injection attemptsssh attacksshdkitt1021t1021.001t1027t1046t1055t1059t1059.001t1071t1071.001t1076t1078t1086t1105t1110t1110.001t1110.002t1110.003t1110.004t1133t1187t1190t1199t1204t1204.002t1210t1486t1496t1499.002t1499.003t1563t1565t1566t1588t1595t1595.001t1595.002t1595.003targeting databasetelecom servicestelecommunicationsthreat actortor nodeua-wgetwsgidavxml-opendir
Activity Timeline
Apr 7Apr 7
Threat Activity Heatmap
· Peak: 2026-04-07LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreLow Risk
38
SIGNAL
Signal Score
38%
Confidence
11
Reports
First seenMar 29, 2025
Last seenApr 7, 2026
GeolocationCN
CountryChina
LocationTaiyuan, Shanxi
ASNAS4134
OrgSxtybas
Coords34.7732, 113.7220
VirusTotal
Not checked
WHOIS
- raw
- inetnum: 110.177.0.0 - 110.179.255.255 netname: sxtybas descr: shanxi telecom taiyuan branch ip node links to customer ip address country: CN admin-c: sa49-ap tech-c: st53-ap abuse-c: AC2532-AP status: ASSIGNED NON-PORTABLE mnt-by: MAINT-CHINANET-SX mnt-irt: IRT-CHINANET-SX last-modified: 2022-01-12T13:25:44Z source: APNIC irt: IRT-CHINANET-SX address: NO.3,SHUMA ROAD,TAIYUAN e-mail: [email protected] abuse-mailbox: [email protected] admin-c: SA49-AP tech-c: ST53-AP auth: # Filtered remarks: [email protected] was validated on 2025-05-08 mnt-by: MAINT-CHINANET-SX last-modified: 2025-05-08T01:02:58Z source: APNIC role: ABUSE CHINANETSX country: ZZ address: NO.3,SHUMA ROAD,TAIYUAN phone: +000000000 e-mail: [email protected] admin-c: SA49-AP tech-c: ST53-AP nic-hdl: AC2532-AP remarks: Generated from irt object IRT-CHINANET-SX remarks: [email protected] was validated on 2025-05-08 abuse-mailbox: [email protected] mnt-by: APNIC-ABUSE last-modified: 2025-05-08T01:03:21Z source: APNIC person: shanxitele admin nic-hdl: SA49-AP e-mail: [email protected] address: no.217 nanneihuan street address: taiyuan city 030012 phone: +86-351-5609863 fax-no: +86-351-5609868 country: cn mnt-by: MAINT-CHINANET-SX last-modified: 2008-09-04T08:55:34Z source: APNIC person: shanxitele tech nic-hdl: ST53-AP e-mail: [email protected] address: no.217 nanneihuan street address: taiyuan city 030012 phone: +86-351-5609963 fax-no: +86-351-5609868 country: cn mnt-by: MAINT-CHINATELECOM-SX last-modified: 2008-09-04T07:31:30Z source: APNIC
- references
- https://urlhaus.abuse.ch/browse/
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 1 year ago · Last seen 2 months ago
Appeared in 11 threat reports