IPMediumSignal 100/100
123.138.71.67
Location
Xi'an, SN
ASN
AS4837
CNC Group CHINA169 Shanni Province Network
First Seen
Dec 22, 2024
Last Seen
Jan 29, 2026
Found in 18 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
99%
Signal Score
100 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Network Information
Country
China
RegionXi'an, SN
ASNAS4837
OrganizationCNC Group CHINA169 Shanni Province Network
Feed Intelligence Summary
18 reports99% confidence
18
Source reports
99%
Confidence score
Category tags
abuseaccess controlactive scanningasiaatif feedaustraliaauthenticationauthentication attackauto-generated securitybanlist feedbinary defensebotnetbrute forcebrute force attackbrute force attemptchinacncommand and controlcommunication protocolcowrie honeypotcredential accesscredential harvestingcredential stuffingctadata exfiltrationdecoy systemdistributed attacksindicatorinfrastructure acquisitionreconnaissancemalicious activitymalicious softwaremalwaremanualnetworknetwork intrusionnetwork probingnetwork scanningnetwork securityoceaniapassword attackpassword attacksphishing attackprocess injectionreconnaissanceremote accessresearchedscanscannersecurity policysocial engineeringssh attackssh monitoringt1021.004t1040t1046t1055t1059t1071.001t1078t1078.004t1110t1110.001t1110.002t1110.003t1110.004t1190t1486t1496t1499.002t1499.003t1565t1566.001t1566.002t1566.003t1587.001t1588.004t1589t1589.002t1590.001t1595t1595.001t1595.002t1595.003telecommunicationsthreat actorthreat intelligencethreat preventionunauthorized accessvoip
Activity Timeline
Jan 29Jan 29
Threat Activity Heatmap
· Peak: 2026-01-29LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Threat ScoreHigh Risk
100
SIGNAL
Signal Score
99%
Confidence
18
Reports
First seenDec 22, 2024
Last seenJan 29, 2026
GeolocationCN
CountryChina
LocationXi'an, SN
ASNAS4837
OrgCNC Group CHINA169 Shanni Province Network
Coords38.2880, 109.7373
VirusTotal
Not checked
WHOIS
- description
- Host bruteforcing SSH
- raw
- inetnum: 123.138.71.0 - 123.138.71.255 netname: PPPoe country: CN descr: XiAnCity-IpAddressPool-128 admin-c: CH679-AP tech-c: CH679-AP status: ASSIGNED NON-PORTABLE mnt-by: MAINT-CNCGROUP-SN last-modified: 2008-11-13T02:30:47Z source: APNIC person: CNCGroup-SN Hostmaster nic-hdl: CH679-AP e-mail: [email protected] address: China Network Communication ,SVT address: NO.2 GuangDe Road, High Tec Zone address: Xi'an, Shannxi, China phone: +86-29-88192060 fax-no: +86-29-88192037 country: CN mnt-by: MAINT-CNCGROUP-SN last-modified: 2008-09-04T07:35:34Z source: APNIC route: 123.138.0.0/15 descr: CNC Group CHINA169 Shanni Province Network country: CN origin: AS4837 mnt-by: MAINT-CNCGROUP-RR last-modified: 2008-09-04T07:54:55Z source: APNIC
- references
- https://blog.edie.io/2020/04/30/diy-ip-threat-feed/, https://github.com/tankmek/threatfeed, https://raw.githubusercontent.com/ahamed-rizvan/IOCs/refs/heads/main/Malicous%20IP%20Address.txt, https://redpiranha.net, https://blocklist.greensnow.co/greensnow.txt, https://www.binarydefense.com/banlist.txt, https://lists.blocklist.de/lists/all.txt, https://rules.emergingthreats.net/blockrules/compromised-ips.txt
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 1 year ago · Last seen 4 months ago
Appeared in 18 threat reports