IOC Radar
IPMediumSignal 34/100

114.138.106.120

Location
ChinaChina
Guiyang, GZ
ASN
AS4134
Chinanet GZ
First Seen
May 23, 2025
Last Seen
Apr 7, 2026
May 23
First Seen
385d ago
Apr 7
Last Seen
65d ago
8
Reports
source reports
34%
Confidence
medium
1/91
VirusTotal
detections
Found in 8 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
34%
Signal Score
34 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

29 techniques

Network Information

CountryCNChina
RegionGuiyang, GZ
ASNAS4134
OrganizationChinanet GZ

Feed Intelligence Summary

8 reports34% confidence
8
Source reports
34%
Confidence score
Category tags
abuseactive scanactive scanningasiabad reputationbotnetbotnet activitybrute forcebrute force attackchinacommand and controlcommunication technologiescredential accesscredential stuffingdata exfiltrationdata store exposureddosdenial of servicedistributed attacksexploit attemptsexploitation activityftp brute forcehttp brute forceidentity & access exploitationindicatorinjection activitylateral movementmalicious softwaremalwaremalware propagationmalware scanningmobile carriersmobile networksnetworknetwork probingnetwork scanningpassword attacksprocess injectionransomwarereconnaissanceremote accessremote servicesresearchedscannersmtp brute forcesocradar honeypotsql injection attemptsssh attackt1021t1021.001t1046t1055t1059t1071.001t1076t1078t1110t1110.001t1110.002t1110.003t1110.004t1133t1187t1190t1199t1210t1486t1496t1499.002t1499.003t1563t1565t1588t1595t1595.001t1595.002t1595.003targeting databasetelecom servicestelecommunications

Activity Timeline

1 total obs
Apr 7Apr 7

Threat Activity Heatmap

· Peak: 2026-04-07
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Intelligence SummaryAI Generated

This Indicator of Compromise (IOC), an IPv4 address `114.138.106.120`, carries significant weight due to its documented involvement in malicious network activity, as evidenced by a substantial threat score of 34.08 and its non-whitelisted status. This IP address has been observed actively attacking UK-based honeypots, indicating its use in aggressive reconnaissance and potential exploitation attempts against network infrastructure. If left unaddressed, the presence of this IOC in organizational …

Threat ScoreLow Risk
34
SIGNAL
Signal Score
34%
Confidence
8
Reports
First seenMay 23, 2025
Last seenApr 7, 2026
GeolocationCN
CountryChina
LocationGuiyang, GZ
ASNAS4134
OrgChinanet GZ
Coords26.5800, 106.7223

VirusTotal

1/ 91vendors flagged
1% detection rateJun 3, 2026

WHOIS

raw
inetnum: 114.138.76.0 - 114.138.111.255 netname: CHINANET-GZ country: CN descr: China Telecom descr: GuiYang County descr: GuiZhou admin-c: DL72-AP tech-c: DL72-AP status: ASSIGNED NON-PORTABLE mnt-by: MAINT-CHINANET-GZ last-modified: 2009-03-05T04:25:09Z source: APNIC person: dan lu nic-hdl: DL72-AP e-mail: [email protected] address: 3. east yanan road of guiyang address: 550001 china phone: +86-851-6861469 fax-no: +86-851-6857020 country: CN mnt-by: MAINT-CHINANET-GUIZHOU last-modified: 2021-03-10T06:36:56Z source: APNIC

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 2 months ago
Appeared in 8 threat reports