IOC Radar
IPMediumSignal 50/100

116.108.1.126

Location
VietnamVietnam
Ho Chi Minh City, Ho Chi Minh
ASN
AS7552
VIETTEL
First Seen
Feb 14, 2025
Last Seen
Apr 19, 2026
Feb 14
First Seen
481d ago
Apr 19
Last Seen
53d ago
12
Reports
source reports
50%
Confidence
medium
Found in 12 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
50%
Signal Score
50 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

29 techniques

Network Information

CountryVNVietnam
RegionHo Chi Minh City, Ho Chi Minh
ASNAS7552
OrganizationVIETTEL

IP Category

Proxy
Proxy server

Feed Intelligence Summary

12 reports50% confidence
12
Source reports
50%
Confidence score
Category tags
active scanactive scanningasiabotnetbotnet activitybotnet iocsbotnet miraibotnet propagationbrute forcebrute force attackercommand and controlcommunication protocolconnected devicescredential accesscredential harvestingcredential stuffingdata exfiltrationdata store exposureddosddos attacksdenial of servicedevice managementdistributed attacksencryptionexploitationexploitation activitygorillabothttps proxyidentity & access exploitationindustrial iotinitial accessinjection activityinternet of thingsiocsiot analyticsiot applicationsiot botnetiot devicesiot platformsiot securityiot/ics attackipv4irclinuxmalicious softwaremalwaremirai botnetmirai internetnetworknetwork attacksnetwork protocolnetwork scanningnetwork securityoutlawphishingphishing attackprocess injectionprotocol exploitationproxyreconnaissanceresearchedscanning activitysmart devicessocial engineeringsocks proxyssh attacksslt1021t1021.001t1040t1053.005t1055t1059t1059.004t1071t1071.001t1078t1078.001t1105t1110.002t1190t1203t1486t1496t1497t1497.001t1498.001t1499.002t1499.003t1565t1566.001t1566.002t1566.003t1595.001t1595.002t1595.003tcp protocoltelnet threatthingsthreat actortor nodetwitterviet namvietnamvnxmrig

Activity Timeline

1 total obs
Apr 19Apr 19

Threat Activity Heatmap

· Peak: 2026-04-19
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreMedium Risk
50
SIGNAL
Signal Score
50%
Confidence
12
Reports
First seenFeb 14, 2025
Last seenApr 19, 2026
GeolocationVN
CountryVietnam
LocationHo Chi Minh City, Ho Chi Minh
ASNAS7552
OrgVIETTEL
Coords21.0278, 105.8340
Proxy

VirusTotal

Not checked

WHOIS

raw
inetnum: 116.96.0.0 - 116.111.255.255 netname: VIETTEL-VN descr: Viettel Group descr: No 1, Tran Huu Duc street, My Dinh 2 ward, Nam Tu Liem district, Ha Noi City country: VN admin-c: TVT8-AP tech-c: NDT9-AP remarks: For spamming matters, mail to [email protected] status: ALLOCATED PORTABLE mnt-by: MAINT-VN-VNNIC mnt-irt: IRT-VNNIC-AP last-modified: 2017-11-11T09:41:03Z source: APNIC irt: IRT-VNNIC-AP address: Ha Noi, VietNam phone: +84-24-35564944 fax-no: +84-24-37821462 e-mail: [email protected] abuse-mailbox: [email protected] admin-c: NTTT1-AP tech-c: NTTT1-AP auth: # Filtered mnt-by: MAINT-VN-VNNIC last-modified: 2017-11-08T09:40:06Z source: APNIC person: Nguyen Dang Tiep address: Viettel Network Corporation address: No 1, Tran Huu Duc street, My Dinh 2 ward, Nam Tu Liem district, Ha Noi City country: VN phone: +84-24-62989898 e-mail: [email protected] nic-hdl: NDT9-AP mnt-by: MAINT-VN-VIETEL last-modified: 2017-11-11T09:40:35Z source: APNIC person: Tran Van Thanh address: Viettel Network Corporation address: No 1, Tran Huu Duc street, My Dinh 2 ward, Nam Tu Liem district, Ha Noi City country: VN phone: +84-24-62989898 e-mail: [email protected] nic-hdl: TVT8-AP mnt-by: MAINT-VN-VIETEL last-modified: 2018-08-21T09:57:13Z source: APNIC route: 116.108.1.0/24 descr: VIETTEL-VN origin: AS24086 mnt-by: MAINT-VN-VNNIC last-modified: 2024-04-05T18:47:01Z source: APNIC route: 116.108.1.0/24 descr: VIETTEL-VN origin: AS7552 mnt-by: MAINT-VN-VNNIC last-modified: 2024-04-05T18:42:02Z source: APNIC
references
https://1275.ru/ioc/gs-25-1490-mirai-botnet-iocs_10200

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 1 month ago
Appeared in 12 threat reports