IOC Radar
IPMediumSignal 36/100

113.199.226.203

Location
NepalNepal
Kathmandu, P3
ASN
AS23752
Nepal Telecommunications Corporation
First Seen
Dec 2, 2025
Last Seen
Jun 2, 2026
Dec 2
First Seen
193d ago
Jun 2
Last Seen
11d ago
9
Reports
source reports
36%
Confidence
medium
Found in 9 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
36%
Signal Score
36 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

13 techniques

Network Information

CountryNPNepal
RegionKathmandu, P3
ASNAS23752
OrganizationNepal Telecommunications Corporation

Feed Intelligence Summary

9 reports36% confidence
9
Source reports
36%
Confidence score
Category tags
abuseactive scanactive scanningapacheapache attackeraptasiabad reputationbad web botblocklistbotnet activitybrute forcebrute force attackcredential accesscredential stuffingdata exfiltrationdata store exposuredatabase securityddosddos attackdenial of serviceexploitation activityexploited hostidentity & access exploitationindicatorinjection activityinjection attacksmalwarenepalnetworknppassword attacksreconnaissanceresearchedscannert1059.003t1110.001t1110.002t1110.003t1110.004t1190t1203t1486t1499.001t1499.002t1595.001t1595.002t1595.003threat actortor nodeweb application attackweb exploitation

Activity Timeline

1 total obs
Jun 2Jun 2

Threat Activity Heatmap

· Peak: 2026-06-02
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Threat ScoreLow Risk
36
SIGNAL
Signal Score
36%
Confidence
9
Reports
First seenDec 2, 2025
Last seenJun 2, 2026
GeolocationNP
CountryNepal
LocationKathmandu, P3
ASNAS23752
OrgNepal Telecommunications Corporation
Coords27.7142, 85.3145

VirusTotal

Not checked

WHOIS

description
The following is the full list of names given to Vye32GsS2g38eKhmaKrLdDjgrnf2YBT4/FGx8SNCa4txePA
raw
inetnum: 113.199.224.0 - 113.199.255.255 netname: NTCINTERNET descr: Nepal Telecommunications Corporation country: NP admin-c: bj15-ap tech-c: bj15-ap tech-c: KK816-AP abuse-c: AN1031-AP status: ALLOCATED NON-PORTABLE mnt-by: MAINT-NP-NPTELECOM mnt-irt: IRT-NPTELECOM-NP last-modified: 2024-07-25T05:42:00Z source: APNIC irt: IRT-NPTELECOM-NP address: Nepal Telecom address: IT Directorate address: Jawlakhel, Lalitpur address: Nepal e-mail: [email protected] abuse-mailbox: [email protected] admin-c: BJ15-AP tech-c: BJ15-AP auth: # Filtered remarks: [email protected] remarks: [email protected] was validated on 2025-10-17 remarks: [email protected] was validated on 2025-10-17 mnt-by: MAINT-NP-NPTELECOM last-modified: 2025-11-18T00:26:21Z source: APNIC role: ABUSE NPTELECOMNP country: ZZ address: Nepal Telecom address: IT Directorate address: Jawlakhel, Lalitpur address: Nepal phone: +000000000 e-mail: [email protected] admin-c: BJ15-AP tech-c: BJ15-AP nic-hdl: AN1031-AP remarks: Generated from irt object IRT-NPTELECOM-NP remarks: [email protected] was validated on 2025-10-17 remarks: [email protected] was validated on 2025-10-17 abuse-mailbox: [email protected] mnt-by: APNIC-ABUSE last-modified: 2025-10-17T07:52:32Z source: APNIC person: Bimlesh Jha nic-hdl: BJ15-AP e-mail: [email protected] address: Nepal Telecom address: IT Directorate address: Pulchowk, Lalitpur address: Nepal phone: +977-1554-4132 fax-no: +977-1554-5878 country: NP mnt-by: MAINT-NP-NPTELECOM last-modified: 2022-02-24T07:21:38Z source: APNIC person: Kshitiz Shrestha nic-hdl: KK816-AP e-mail: [email protected] address: Jawalakhel,Lalitpur address: Nepal phone: +977-001-5544132 fax-no: +977-001-545878 country: NP mnt-by: MAINT-NP-NPTELECOM last-modified: 2010-09-01T04:45:33Z source: APNIC route: 113.199.226.0/24 origin: AS23752 descr: Nepal Telecommunications Corporation Corporation Information System Support Directorate mnt-by: MAINT-NP-NPTELECOM last-modified: 2017-02-24T02:05:38Z source: APNIC
references
https://malware-filter.gitlab.io/malware-filter/botnet-filter.txt

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 6 months ago · Last seen 11 days ago
Appeared in 9 threat reports