IOC Radar
IPMediumSignal 31/100

122.144.4.94

Location
IndonesiaIndonesia
Bekasi, JK
ASN
AS38320
Maxindo
First Seen
Jan 20, 2021
Last Seen
Apr 7, 2026
Jan 20
First Seen
1984d ago
Apr 7
Last Seen
81d ago
11
Reports
source reports
31%
Confidence
medium
Found in 11 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
31%
Signal Score
31 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

39 techniques

Network Information

CountryIDIndonesia
RegionBekasi, JK
ASNAS38320
OrganizationMaxindo

Feed Intelligence Summary

11 reports31% confidence
11
Source reports
31%
Confidence score
Category tags
abuseactive scanactive scanningadbhoney attacksadbhoney honeypotasiaattackbad reputationbotnetbotnet activitybrute forcebrute force attackcode executioncommand and controlcommand executioncommunication protocolcompromised credentialscowrie attackscowrie honeypotcowrie interactionscowrie ssh attackscredential accesscredential harvestingcredential stuffingctadata exfiltrationdata store exposuredatabase securitydecoy systemdefense evasiondionaea honeypotdionaea interactionsdionaea malware analysisdionaea malware collectiondistributed attackselasticpot honeypotelasticsearch monitoringexploitation activityftp brute forceheralding attack patternididentity & access exploitationindicatorindonesiainitial accessinjection activityiot securitylateral movementmailoney email attacksmailoney honeypotmalicious activitymalicious softwaremalwaremalware behaviourmalware capturenetworknetwork intrusion attemptsnetwork probingnetwork scanningnetwork securitypassword attacksphishingphishing attackphishing trapprocess injectionpython script activityreconnaissanceresearchedresource hijackingsentrypeer botnetsftp attacksocial engineeringsoftware exploitationssh attackssh monitoringt1021t1021.002t1021.004t1027t1040t1041t1046t1055t1059t1059.004t1059.005t1071.001t1078t1110t1110.001t1110.002t1110.003t1110.004t1190t1195.001t1203t1204.002t1486t1496t1499.001t1499.002t1499.003t1555t1565t1566t1566.001t1566.002t1566.003t1566.004t1583.001t1595t1595.001t1595.002t1595.003tannertanner web attackstargeting databasetelecommunicationsthreat actorthreat intelligencetor nodetpotcevoipvoip attack

Activity Timeline

1 total obs
Apr 7Apr 7

Threat Activity Heatmap

· Peak: 2026-04-07
Less
More
Mon
Wed
Fri
Jun
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreLow Risk
31
SIGNAL
Signal Score
31%
Confidence
11
Reports
First seenJan 20, 2021
Last seenApr 7, 2026
GeolocationID
CountryIndonesia
LocationBekasi, JK
ASNAS38320
OrgMaxindo
Coords-6.1741, 106.8296

VirusTotal

Not checked

WHOIS

description
2025-05-11T06:31:16.296Z Honeypot : Heralding : Source: 122.144.4.94 : Username/Password: AdMIN/asdf12345 Port: 1080 Message: 2025-05-11 06:31:16.296753,cfcfd0d7-5df9-4203-823a-f7b72bad27bb,0d21dd52-912d-41ac-8d49-1b4726488147,122.144.4.94,38236,99.18.26.21,1080,socks5,AdMIN,asdf12345,
raw
inetnum: 122.144.0.0 - 122.144.7.255 netname: MMS-ID descr: PT. Maxindo Mitra Solusi descr: Internet Service Provider descr: Jl. Kelapa Puan Raya Blok FU 1/9 descr: Jakarta country: ID admin-c: MA1623-AP tech-c: MA1623-AP remarks: Send Spam & Abuse report to: [email protected] status: ALLOCATED PORTABLE mnt-by: MNT-APJII-ID mnt-lower: MAINT-ID-MMS mnt-routes: MAINT-ID-MMS mnt-irt: IRT-MMS-ID last-modified: 2023-01-11T07:22:18Z source: APNIC irt: IRT-MMS-ID address: PT. Maxindo Mitra Solusi address: Jl. Pantai Indah Kapuk Ruko Cordoba Blok H No. 77, Jakarta, 14460 address: Jakarta e-mail: [email protected] e-mail: [email protected] abuse-mailbox: [email protected] admin-c: MA1623-AP tech-c: MA1623-AP auth: # Filtered mnt-by: MAINT-ID-MMS last-modified: 2022-09-06T08:09:46Z source: APNIC person: Muhammad Alim address: PT. Maxindo Mitra Solusi address: Jl. Pantai Indah Kapuk Ruko Cordoba Blok H No. 77, Jakarta, 14460 country: ID phone: +62-21-80624645 e-mail: [email protected] nic-hdl: MA1623-AP mnt-by: MAINT-ID-MMS last-modified: 2022-08-31T08:01:35Z source: APNIC route: 122.144.0.0/21 descr: Route Object of Maxindo descr: Internet Service Provider descr: Jl. Pantai Indah Kapuk descr: Ruko Cordoba Blok H no. 77 descr: Jakarta 14470 origin: AS38320 mnt-by: MAINT-ID-MMS last-modified: 2015-09-15T04:48:34Z source: APNIC inetnum: 122.144.4.0 - 122.144.4.255 netname: MAXINDOMITRASOLUSI-ID descr: Maxindo Mitra Solusi, PT. descr: ISP - Internet Service Provider descr: JAKARTA country: ID geoloc: -6.144135 106.723992 language: id language: en admin-c: MA1623-AP tech-c: MA1623-AP remarks: -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+- remarks: These IP was used for Maxindo Mitra Solusi's Infrastructure. remarks: http://www.maxindo.net.id remarks: -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+- status: ALLOCATED NON-PORTABLE mnt-by: MAINT-MAXINDOMITRASOLUSI-ID mnt-routes: MAINT-MAXINDOMITRASOLUSI-ID mnt-irt: IRT-MMS-ID last-modified: 2022-09-01T09:34:36Z source: IDNIC irt: IRT-MMS-ID address: PT. Maxindo Mitra Solusi address: Jl. Pantai Indah Kapuk Ruko Cordoba Blok H No. 77, Jakarta, 14460 address: Jakarta e-mail: [email protected] e-mail: [email protected] abuse-mailbox: [email protected] admin-c: MA1623-AP tech-c: MA1623-AP auth: # Filtered mnt-by: MAINT-ID-MMS last-modified: 2022-09-01T10:07:34Z source: IDNIC person: Muhammad Alim address: PT. Maxindo Mitra Solusi address: Jl. Pantai Indah Kapuk Ruko Cordoba Blok H No. 77, Jakarta, 14460 country: ID phone: +62-21-80624645 e-mail: [email protected] nic-hdl: MA1623-AP mnt-by: MAINT-ID-MMS last-modified: 2022-08-31T08:01:56Z source: IDNIC route: 122.144.0.0/21 descr: Route Object of Maxindo descr: Internet Service Provider descr: Jl. Pantai Indah Kapuk descr: Ruko Cordoba Blok H no. 77 descr: Jakarta 14470 origin: AS38320 mnt-by: MAINT-ID-MMS last-modified: 2015-09-15T04:48:34Z source: IDNIC
references
https://github.com/telekom-security/tpotce

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 5 years ago · Last seen 2 months ago
Appeared in 11 threat reports