IPMediumSignal 30/100
121.62.22.63
Location
Shizishan, HB
ASN
AS148981
Chinanet HB
First Seen
Dec 7, 2024
Last Seen
Apr 7, 2026
Found in 11 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
30%
Signal Score
30 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Network Information
Country
China
RegionShizishan, HB
ASNAS148981
OrganizationChinanet HB
Feed Intelligence Summary
11 reports30% confidence
11
Source reports
30%
Confidence score
Category tags
abuseactive scanactive scanningasiaattackauto-generated securitybad reputationbotnetbotnet activitybrute forcechinacitrix securitycommand and controlcommunication protocolcowrie honeypotcredential accesscredential harvestingcredential stuffingctadata exfiltrationdata store exposureddosdecoy systemdenial of servicedionaea honeypotdistributed attacksenterprise securityexploit attemptsexploitation activityftpftp brute forcehoneytrap honeypothttp brute forceidentity & access exploitationindicatorinitial accessinjection activitykazakhstankaznetlampmailoney honeypotmalicious activitymalicious softwaremalwaremalware behaviourmalware capturemalware propagationnetworknetwork attacksnetwork probingnetwork protocolnetwork reconnaissancenetwork scanningnetwork traffic analysisphishingphishing attackphishing trappossible botnet activitypossible reconnaissance activityprocess injectionreconnaissanceremote accessremote servicesresearchedscannersftp attacksmtp brute forcesocial engineeringssh attackssh monitoringt1018t1021t1021.001t1040t1041t1046t1047t1053t1055t1059t1059.004t1071.001t1076t1078t1083t1110t1110.001t1110.002t1110.003t1190t1204.002t1210t1486t1496t1499.002t1499.003t1563t1565t1566t1566.001t1566.002t1566.003t1566.004t1583t1583.001t1583.002t1595t1595.001t1595.002t1595.003tannertcp protocoltelecommunicationsthreat actorthreat detectionthreat intelligencetor nodeunauthorized access attemptvulnerability scanweb application scanning
Activity Timeline
Apr 7Apr 7
Threat Activity Heatmap
· Peak: 2026-04-07LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreLow Risk
30
SIGNAL
Signal Score
30%
Confidence
11
Reports
First seenDec 7, 2024
Last seenApr 7, 2026
GeolocationCN
CountryChina
LocationShizishan, HB
ASNAS148981
OrgChinanet HB
Coords32.6540, 110.7742
VirusTotal
Not checked
WHOIS
- description
- 2024-12-10T05:49:49.935Z Honeypot : Dionaea : Source: 121.62.22.63 : Port: 1433 Connection: {'protocol': 'mssqld', 'type': 'accept', 'transport': 'tcp'}
- raw
- inetnum: 121.60.0.0 - 121.63.255.255 netname: CHINANET-HB descr: CHINANET Hubei province network descr: Data Communication Division descr: China Telecom country: CN admin-c: CH93-AP tech-c: CHA1-AP abuse-c: AC1573-AP status: ALLOCATED PORTABLE remarks: -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+ remarks: This object can only be updated by APNIC hostmasters. remarks: To update this object, please contact APNIC remarks: hostmasters and include your organisation's account remarks: name in the subject line. remarks: -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+ mnt-by: APNIC-HM mnt-lower: MAINT-CN-CHINANET-HB mnt-irt: IRT-CHINANET-CN last-modified: 2021-06-15T08:05:05Z source: APNIC irt: IRT-CHINANET-CN address: No.31 ,jingrong street,beijing address: 100032 e-mail: [email protected] abuse-mailbox: [email protected] admin-c: CH93-AP tech-c: CH93-AP auth: # Filtered remarks: [email protected] was validated on 2025-04-24 mnt-by: MAINT-CHINANET last-modified: 2025-04-24T03:21:26Z source: APNIC role: ABUSE CHINANETCN country: ZZ address: No.31 ,jingrong street,beijing address: 100032 phone: +000000000 e-mail: [email protected] admin-c: CH93-AP tech-c: CH93-AP nic-hdl: AC1573-AP remarks: Generated from irt object IRT-CHINANET-CN remarks: [email protected] was validated on 2025-04-24 abuse-mailbox: [email protected] mnt-by: APNIC-ABUSE last-modified: 2025-04-24T03:21:54Z source: APNIC role: CHINANET HB ADMIN address: 8th floor of JinGuang Building address: #232 of Macao Road address: HanKou Wuhan Hubei Province address: P.R.China country: CN phone: +86 27 82862199 fax-no: +86 27 82861499 e-mail: [email protected] remarks: send spam reports to [email protected] remarks: and abuse reports to [email protected] remarks: Please include detailed information and remarks: times in GMT+8 admin-c: YZ83-AP admin-c: ZC77-AP tech-c: YZ83-AP tech-c: ZC77-AP nic-hdl: CHA1-AP notify: [email protected] mnt-by: MAINT-CN-CHINANET-HB last-modified: 2013-08-06T11:09:18Z source: APNIC person: Chinanet Hostmaster nic-hdl: CH93-AP e-mail: [email protected] address: No.31 ,jingrong street,beijing address: 100032 phone: +86-10-58501724 fax-no: +86-10-58501724 country: CN mnt-by: MAINT-CHINANET last-modified: 2022-02-28T06:53:44Z source: APNIC
- references
- https://threats.kz, https://github.com/telekom-security/tpotce
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 1 year ago · Last seen 2 months ago
Appeared in 11 threat reports