IOC Radar
IPMediumSignal 57/100

116.204.67.139

Location
ChinaChina
Beijing, Beijing
ASN
AS55990
Wonten Network Ltd.
First Seen
Mar 26, 2026
Last Seen
Apr 26, 2026
Mar 26
First Seen
79d ago
Apr 26
Last Seen
48d ago
5
Reports
source reports
57%
Confidence
medium
Found in 5 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
57%
Signal Score
57 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

9 techniques

Network Information

CountryCNChina
RegionBeijing, Beijing
ASNAS55990
OrganizationWonten Network Ltd.

Feed Intelligence Summary

5 reports57% confidence
5
Source reports
57%
Confidence score
Category tags
active scanactive scanningafricaargentinaasiaaustraliaauto-blockedbad reputationbad web botbangladeshbelgiumbotnet activitybrazilcambodiacanadachinaddosdenial of serviceencryptioneuropeeurope/asiaexploitation activityexploited hostfinlandfrancegermanyhackinghong kongindiaindicatorirelandjamaicajapankenyakorea, republic ofkyrgyzstanlithuaniamalaysiamexicomorocconetherlandsnetworknew zealandnorth americanorwayoceaniapolandreconnaissanceresearchedromaniarussiascannerserbiasingaporesouth africasouth americassl-enrichmentswedensyrian arab republict1071.001t1105t1190t1203t1499.001t1573.002t1595.001t1595.002t1595.003taiwanthreat-intelturkeyukraineunited kingdomunited statesvenezuela, bolivarian republic ofweb application attackweb exploitation

Activity Timeline

1 total obs
Apr 26Apr 26

Threat Activity Heatmap

· Peak: 2026-04-26
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreMedium Risk
57
SIGNAL
Signal Score
57%
Confidence
5
Reports
First seenMar 26, 2026
Last seenApr 26, 2026
GeolocationCN
CountryChina
LocationBeijing, Beijing
ASNAS55990
OrgWonten Network Ltd.
Coords39.9042, 116.4073

VirusTotal

Not checked

WHOIS

description
AbuseIPDB 11% | CN | Huawei Public Cloud Service (Huawei Software Technologies Ltd.Co)
raw
inetnum: 116.204.64.0 - 116.204.127.255 netname: HWCSNET descr: Huawei Public Cloud Service (Huawei Software Technologies Ltd.Co) descr: No.2018 Xuegang Road,Bantian street,Longgang District, descr: Shenzhen,Guangdong Province, 518129 P.R.China country: CN admin-c: LL3172-AP tech-c: GX1759-AP abuse-c: AC1601-AP status: ALLOCATED PORTABLE mnt-by: MAINT-CNNIC-AP mnt-lower: MAINT-CNNIC-AP mnt-routes: MAINT-CNNIC-AP mnt-irt: IRT-CNNIC-CN last-modified: 2022-04-18T05:52:09Z source: APNIC irt: IRT-CNNIC-CN address: Beijing, China e-mail: [email protected] abuse-mailbox: [email protected] admin-c: IP50-AP tech-c: IP50-AP auth: # Filtered remarks: Please note that CNNIC is not an ISP and is not remarks: empowered to investigate complaints of network abuse. remarks: Please contact the tech-c or admin-c of the network. remarks: [email protected] is invalid mnt-by: MAINT-CNNIC-AP last-modified: 2025-11-17T23:08:37Z source: APNIC role: ABUSE CNNICCN country: ZZ address: Beijing, China phone: +000000000 e-mail: [email protected] admin-c: IP50-AP tech-c: IP50-AP nic-hdl: AC1601-AP remarks: Generated from irt object IRT-CNNIC-CN remarks: [email protected] is invalid abuse-mailbox: [email protected] mnt-by: APNIC-ABUSE last-modified: 2025-09-19T17:20:32Z source: APNIC person: Gui xiaowei address: HUAWEI CLOUD Data Center, Jiaoxinggong Road, Qianzhong Avenue, Gui'an New District, Guizhou Province country: CN phone: +86-18566251984 e-mail: [email protected] nic-hdl: GX1759-AP mnt-by: MAINT-CNNIC-AP last-modified: 2022-04-18T05:32:41Z source: APNIC person: Liu Liqun address: HUAWEI CLOUD Data Center, Jiaoxinggong Road, Qianzhong Avenue, Gui'an New District, Guizhou Province country: CN phone: +86-13360099887 e-mail: [email protected] nic-hdl: LL3172-AP mnt-by: MAINT-CNNIC-AP last-modified: 2022-04-18T05:33:15Z source: APNIC

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 2 months ago · Last seen 1 month ago
Appeared in 5 threat reports