IPMediumSignal 100/100
121.204.181.205
Location
Xiamen, Fujian
ASN
AS133774
Chinanet FJ
First Seen
Feb 15, 2025
Last Seen
Jan 16, 2026
Found in 17 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
99%
Signal Score
100 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Network Information
Country
China
RegionXiamen, Fujian
ASNAS133774
OrganizationChinanet FJ
Feed Intelligence Summary
17 reports99% confidence
17
Source reports
99%
Confidence score
Category tags
abuseaccess attemptaccess controlactive scanningasiaattackauthentication attacksauthentication failuresbotnetbrute forcebrute force attackchinacncommand and controlcompromised credentialscowrie honeypotcredential accesscredential stuffingctadata exfiltrationdecoy systemdistributed attackseuropefail2ban blocked ipfail2ban logsfailed login attemptsftp brute forceindicatorlogin attemptsmalicious activitymalicious softwaremalwaremultiple failed loginsnetworknetwork intrusionnetwork scanningnetwork securitypassword attacksprocess injectionreconnaissanceresearchedscannersecurity monitoringsecurity operationssecurity policysftp attackssh attackssh monitoringt1021t1021.001t1021.002t1041t1055t1059t1071.001t1078t1110t1110.001t1110.002t1110.003t1110.004t1133t1187t1190t1486t1496t1499.002t1499.003t1565t1595t1595.001t1595.002t1595.003telecommunicationsthreat actorthreat intelligencethreat preventionunauthorized accessunited kingdom
Activity Timeline
Jan 16Jan 16
Threat Activity Heatmap
· Peak: 2026-01-16LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Intelligence SummaryAI Generated
This Indicator of Compromise (IOC), an IPv4 address, represents a critical and immediate threat to organizational security due to its high malicious activity score of 100.0 and explicit non-whitelist status. This IP address has been extensively linked to aggressive reconnaissance activities, brute-force attacks, and credential stuffing attempts targeting various services, including SSH, MySQL, and RDP. Its presence in network logs or security device alerts signifies a direct attempt by malicious…
Threat ScoreHigh Risk
100
SIGNAL
Signal Score
99%
Confidence
17
Reports
First seenFeb 15, 2025
Last seenJan 16, 2026
GeolocationCN
CountryChina
LocationXiamen, Fujian
ASNAS133774
OrgChinanet FJ
Coords24.4795, 118.0890
VirusTotal
Not checked
WHOIS
- description
- Banned by Fail2Ban [sshd]
- raw
- inetnum: 121.204.0.0 - 121.207.255.255 netname: CHINANET-FJ descr: CHINANET Fujian province network descr: China Telecom descr: 7,East Street ,Fuzhou ,Fujian ,PRC country: CN admin-c: FH71-AP tech-c: FH71-AP abuse-c: AC1573-AP status: ALLOCATED PORTABLE remarks: service provider remarks: -------------------------------------------------------- remarks: To report network abuse, please contact mnt-irt remarks: For troubleshooting, please contact tech-c and admin-c remarks: Report invalid contact via www.apnic.net/invalidcontact remarks: -------------------------------------------------------- mnt-by: APNIC-HM mnt-lower: MAINT-CHINANET-FJ mnt-routes: MAINT-CHINANET-FJ mnt-irt: IRT-CHINANET-CN last-modified: 2021-06-15T08:05:32Z source: APNIC irt: IRT-CHINANET-CN address: No.31 ,jingrong street,beijing address: 100032 e-mail: [email protected] abuse-mailbox: [email protected] admin-c: CH93-AP tech-c: CH93-AP auth: # Filtered remarks: [email protected] was validated on 2025-04-24 mnt-by: MAINT-CHINANET last-modified: 2025-04-24T03:21:26Z source: APNIC role: ABUSE CHINANETCN country: ZZ address: No.31 ,jingrong street,beijing address: 100032 phone: +000000000 e-mail: [email protected] admin-c: CH93-AP tech-c: CH93-AP nic-hdl: AC1573-AP remarks: Generated from irt object IRT-CHINANET-CN remarks: [email protected] was validated on 2025-04-24 abuse-mailbox: [email protected] mnt-by: APNIC-ABUSE last-modified: 2025-04-24T03:21:54Z source: APNIC person: FUJIANNET HOSTMASTER nic-hdl: FH71-AP e-mail: [email protected] address: 7,East Street ,Fuzhou ,Fujian ,PRC phone: +86-591-83309761 fax-no: +86-591-83371954 country: CN mnt-by: MAINT-CHINANET-FJ last-modified: 2010-01-05T07:36:17Z source: APNIC
- references
- https://raw.githubusercontent.com/ahamed-rizvan/IOCs/refs/heads/main/Malicous%20IP%20Address.txt, https://github.com/telekom-security/tpotce
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 1 year ago · Last seen 5 months ago
Appeared in 17 threat reports