IPMediumSignal 34/100
114.138.106.120
Location
Guiyang, GZ
ASN
AS4134
Chinanet GZ
First Seen
May 23, 2025
Last Seen
Apr 7, 2026
May 23
First Seen
385d ago
Apr 7
Last Seen
65d ago
8
Reports
source reports
34%
Confidence
medium
1/91
VirusTotal
detections
Found in 8 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
34%
Signal Score
34 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Network Information
Country
China
RegionGuiyang, GZ
ASNAS4134
OrganizationChinanet GZ
Feed Intelligence Summary
8 reports34% confidence
8
Source reports
34%
Confidence score
Category tags
abuseactive scanactive scanningasiabad reputationbotnetbotnet activitybrute forcebrute force attackchinacommand and controlcommunication technologiescredential accesscredential stuffingdata exfiltrationdata store exposureddosdenial of servicedistributed attacksexploit attemptsexploitation activityftp brute forcehttp brute forceidentity & access exploitationindicatorinjection activitylateral movementmalicious softwaremalwaremalware propagationmalware scanningmobile carriersmobile networksnetworknetwork probingnetwork scanningpassword attacksprocess injectionransomwarereconnaissanceremote accessremote servicesresearchedscannersmtp brute forcesocradar honeypotsql injection attemptsssh attackt1021t1021.001t1046t1055t1059t1071.001t1076t1078t1110t1110.001t1110.002t1110.003t1110.004t1133t1187t1190t1199t1210t1486t1496t1499.002t1499.003t1563t1565t1588t1595t1595.001t1595.002t1595.003targeting databasetelecom servicestelecommunications
Activity Timeline
Apr 7Apr 7
Threat Activity Heatmap
· Peak: 2026-04-07LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Intelligence SummaryAI Generated
This Indicator of Compromise (IOC), an IPv4 address `114.138.106.120`, carries significant weight due to its documented involvement in malicious network activity, as evidenced by a substantial threat score of 34.08 and its non-whitelisted status. This IP address has been observed actively attacking UK-based honeypots, indicating its use in aggressive reconnaissance and potential exploitation attempts against network infrastructure. If left unaddressed, the presence of this IOC in organizational …
Threat ScoreLow Risk
34
SIGNAL
Signal Score
34%
Confidence
8
Reports
First seenMay 23, 2025
Last seenApr 7, 2026
GeolocationCN
CountryChina
LocationGuiyang, GZ
ASNAS4134
OrgChinanet GZ
Coords26.5800, 106.7223
WHOIS
- raw
- inetnum: 114.138.76.0 - 114.138.111.255 netname: CHINANET-GZ country: CN descr: China Telecom descr: GuiYang County descr: GuiZhou admin-c: DL72-AP tech-c: DL72-AP status: ASSIGNED NON-PORTABLE mnt-by: MAINT-CHINANET-GZ last-modified: 2009-03-05T04:25:09Z source: APNIC person: dan lu nic-hdl: DL72-AP e-mail: [email protected] address: 3. east yanan road of guiyang address: 550001 china phone: +86-851-6861469 fax-no: +86-851-6857020 country: CN mnt-by: MAINT-CHINANET-GUIZHOU last-modified: 2021-03-10T06:36:56Z source: APNIC
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 1 year ago · Last seen 2 months ago
Appeared in 8 threat reports