IOC Radar
IPHighVerifiedSignal 57/100

122.51.136.129

Location
ChinaChina
Shanghai, Shanghai
ASN
AS45090
Guangzhou Haizhiguang communication technology Limited
First Seen
Apr 9, 2026
Last Seen
Apr 23, 2026
Apr 9
First Seen
65d ago
Apr 23
Last Seen
51d ago
4
Reports
source reports
57%
Confidence
high
Found in 4 reports. Confidence: high. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
57%
Signal Score
57 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

8 techniques

Network Information

CountryCNChina
RegionShanghai, Shanghai
ASNAS45090
OrganizationGuangzhou Haizhiguang communication technology Limited

Feed Intelligence Summary

4 reports57% confidence
4
Source reports
57%
Confidence score
Category tags
active scanactive scanningasiaaustraliabrute forcebrute force attackchinacredential accesscredential stuffingexploitation activityidentity & access exploitationindicatornetworkoceaniapassword attacksreconnaissanceresearchedscannersshssh attackt1110t1110.001t1110.002t1110.003t1110.004t1595.001t1595.002t1595.003

Activity Timeline

1 total obs
Apr 23Apr 23

Threat Activity Heatmap

· Peak: 2026-04-23
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreMedium Risk
57
SIGNAL
Signal Score
57%
Confidence
4
Reports
First seenApr 9, 2026
Last seenApr 23, 2026
Verified IOC
GeolocationCN
CountryChina
LocationShanghai, Shanghai
ASNAS45090
OrgGuangzhou Haizhiguang communication technology Limited
Coords31.2222, 121.4581

VirusTotal

Not checked

WHOIS

description
Host bruteforcing SSH
raw
inetnum: 122.51.0.0 - 122.51.255.255 netname: TencentCloud descr: Tencent cloud computing (Beijing) Co., Ltd. descr: Floor 6, Yinke Building,38 Haidian St, descr: Haidian District Beijing country: CN admin-c: JT1125-AP tech-c: JX1747-AP abuse-c: AC1601-AP status: ALLOCATED PORTABLE mnt-by: MAINT-CNNIC-AP mnt-irt: IRT-TENCENTCLOUD-CN mnt-lower: MAINT-CNNIC-AP mnt-routes: MAINT-CNNIC-AP last-modified: 2023-11-28T00:57:03Z source: APNIC irt: IRT-TencentCloud-CN address: 9F, FIYTA Building, Gaoxinnanyi Road, Southern address: District of Hi-tech Park, Shenzhen e-mail: [email protected] admin-c: JT1125-AP tech-c: JX1747-AP abuse-mailbox: [email protected] remarks: [email protected] was validated on 2025-10-29 remarks: [email protected] was validated on 2025-10-29 auth: # Filtered mnt-by: MAINT-CNNIC-AP last-modified: 2025-11-18T00:34:40Z source: APNIC role: ABUSE CNNICCN country: ZZ address: Beijing, China phone: +000000000 e-mail: [email protected] admin-c: IP50-AP tech-c: IP50-AP nic-hdl: AC1601-AP remarks: Generated from irt object IRT-CNNIC-CN remarks: [email protected] is invalid abuse-mailbox: [email protected] mnt-by: APNIC-ABUSE last-modified: 2025-09-19T17:20:32Z source: APNIC person: James Tian address: 9F, FIYTA Building, Gaoxinnanyi Road,Southern address: District of Hi-tech Park, Shenzhen country: CN phone: +86-755-86013388-84952 e-mail: [email protected] nic-hdl: JT1125-AP mnt-by: MAINT-CNNIC-AP last-modified: 2024-03-19T08:21:31Z source: APNIC person: Jimmy Xiao address: 9F, FIYTA Building, Gaoxinnanyi Road,Southern address: District of Hi-tech Park, Shenzhen country: CN phone: +86-755-86013388-80224 e-mail: [email protected] nic-hdl: JX1747-AP mnt-by: MAINT-CNNIC-AP last-modified: 2021-09-17T00:38:09Z source: APNIC route: 122.51.0.0/16 descr: Shenzhen Tencent Computer Systems Company Limited country: CN origin: AS45090 notify: [email protected] mnt-by: MAINT-CNNIC-AP last-modified: 2019-04-18T03:50:02Z source: APNIC

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

high
First detected 2 months ago · Last seen 1 month ago
Appeared in 4 threat reports