IOC Radar
IPMediumSignal 100/100

121.204.181.205

Location
ChinaChina
Xiamen, Fujian
ASN
AS133774
Chinanet FJ
First Seen
Feb 15, 2025
Last Seen
Jan 16, 2026
Feb 15
First Seen
484d ago
Jan 16
Last Seen
150d ago
17
Reports
source reports
99%
Confidence
medium
Found in 17 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
99%
Signal Score
100 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

25 techniques

Network Information

CountryCNChina
RegionXiamen, Fujian
ASNAS133774
OrganizationChinanet FJ

Feed Intelligence Summary

17 reports99% confidence
17
Source reports
99%
Confidence score
Category tags
abuseaccess attemptaccess controlactive scanningasiaattackauthentication attacksauthentication failuresbotnetbrute forcebrute force attackchinacncommand and controlcompromised credentialscowrie honeypotcredential accesscredential stuffingctadata exfiltrationdecoy systemdistributed attackseuropefail2ban blocked ipfail2ban logsfailed login attemptsftp brute forceindicatorlogin attemptsmalicious activitymalicious softwaremalwaremultiple failed loginsnetworknetwork intrusionnetwork scanningnetwork securitypassword attacksprocess injectionreconnaissanceresearchedscannersecurity monitoringsecurity operationssecurity policysftp attackssh attackssh monitoringt1021t1021.001t1021.002t1041t1055t1059t1071.001t1078t1110t1110.001t1110.002t1110.003t1110.004t1133t1187t1190t1486t1496t1499.002t1499.003t1565t1595t1595.001t1595.002t1595.003telecommunicationsthreat actorthreat intelligencethreat preventionunauthorized accessunited kingdom

Activity Timeline

1 total obs
Jan 16Jan 16

Threat Activity Heatmap

· Peak: 2026-01-16
Less
More
Mon
Wed
Fri
Jun
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Intelligence SummaryAI Generated

This Indicator of Compromise (IOC), an IPv4 address, represents a critical and immediate threat to organizational security due to its high malicious activity score of 100.0 and explicit non-whitelist status. This IP address has been extensively linked to aggressive reconnaissance activities, brute-force attacks, and credential stuffing attempts targeting various services, including SSH, MySQL, and RDP. Its presence in network logs or security device alerts signifies a direct attempt by malicious…

Threat ScoreHigh Risk
100
SIGNAL
Signal Score
99%
Confidence
17
Reports
First seenFeb 15, 2025
Last seenJan 16, 2026
GeolocationCN
CountryChina
LocationXiamen, Fujian
ASNAS133774
OrgChinanet FJ
Coords24.4795, 118.0890

VirusTotal

Not checked

WHOIS

description
Banned by Fail2Ban [sshd]
raw
inetnum: 121.204.0.0 - 121.207.255.255 netname: CHINANET-FJ descr: CHINANET Fujian province network descr: China Telecom descr: 7,East Street ,Fuzhou ,Fujian ,PRC country: CN admin-c: FH71-AP tech-c: FH71-AP abuse-c: AC1573-AP status: ALLOCATED PORTABLE remarks: service provider remarks: -------------------------------------------------------- remarks: To report network abuse, please contact mnt-irt remarks: For troubleshooting, please contact tech-c and admin-c remarks: Report invalid contact via www.apnic.net/invalidcontact remarks: -------------------------------------------------------- mnt-by: APNIC-HM mnt-lower: MAINT-CHINANET-FJ mnt-routes: MAINT-CHINANET-FJ mnt-irt: IRT-CHINANET-CN last-modified: 2021-06-15T08:05:32Z source: APNIC irt: IRT-CHINANET-CN address: No.31 ,jingrong street,beijing address: 100032 e-mail: [email protected] abuse-mailbox: [email protected] admin-c: CH93-AP tech-c: CH93-AP auth: # Filtered remarks: [email protected] was validated on 2025-04-24 mnt-by: MAINT-CHINANET last-modified: 2025-04-24T03:21:26Z source: APNIC role: ABUSE CHINANETCN country: ZZ address: No.31 ,jingrong street,beijing address: 100032 phone: +000000000 e-mail: [email protected] admin-c: CH93-AP tech-c: CH93-AP nic-hdl: AC1573-AP remarks: Generated from irt object IRT-CHINANET-CN remarks: [email protected] was validated on 2025-04-24 abuse-mailbox: [email protected] mnt-by: APNIC-ABUSE last-modified: 2025-04-24T03:21:54Z source: APNIC person: FUJIANNET HOSTMASTER nic-hdl: FH71-AP e-mail: [email protected] address: 7,East Street ,Fuzhou ,Fujian ,PRC phone: +86-591-83309761 fax-no: +86-591-83371954 country: CN mnt-by: MAINT-CHINANET-FJ last-modified: 2010-01-05T07:36:17Z source: APNIC
references
https://raw.githubusercontent.com/ahamed-rizvan/IOCs/refs/heads/main/Malicous%20IP%20Address.txt, https://github.com/telekom-security/tpotce

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 5 months ago
Appeared in 17 threat reports