IOC Radar
IPMediumSignal 100/100

123.138.71.67

Location
ChinaChina
Xi'an, SN
ASN
AS4837
CNC Group CHINA169 Shanni Province Network
First Seen
Dec 22, 2024
Last Seen
Jan 29, 2026
Dec 22
First Seen
541d ago
Jan 29
Last Seen
138d ago
18
Reports
source reports
99%
Confidence
medium
Found in 18 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
99%
Signal Score
100 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

31 techniques

Network Information

CountryCNChina
RegionXi'an, SN
ASNAS4837
OrganizationCNC Group CHINA169 Shanni Province Network

Feed Intelligence Summary

18 reports99% confidence
18
Source reports
99%
Confidence score
Category tags
abuseaccess controlactive scanningasiaatif feedaustraliaauthenticationauthentication attackauto-generated securitybanlist feedbinary defensebotnetbrute forcebrute force attackbrute force attemptchinacncommand and controlcommunication protocolcowrie honeypotcredential accesscredential harvestingcredential stuffingctadata exfiltrationdecoy systemdistributed attacksindicatorinfrastructure acquisitionreconnaissancemalicious activitymalicious softwaremalwaremanualnetworknetwork intrusionnetwork probingnetwork scanningnetwork securityoceaniapassword attackpassword attacksphishing attackprocess injectionreconnaissanceremote accessresearchedscanscannersecurity policysocial engineeringssh attackssh monitoringt1021.004t1040t1046t1055t1059t1071.001t1078t1078.004t1110t1110.001t1110.002t1110.003t1110.004t1190t1486t1496t1499.002t1499.003t1565t1566.001t1566.002t1566.003t1587.001t1588.004t1589t1589.002t1590.001t1595t1595.001t1595.002t1595.003telecommunicationsthreat actorthreat intelligencethreat preventionunauthorized accessvoip

Activity Timeline

1 total obs
Jan 29Jan 29

Threat Activity Heatmap

· Peak: 2026-01-29
Less
More
Mon
Wed
Fri
Jun
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Threat ScoreHigh Risk
100
SIGNAL
Signal Score
99%
Confidence
18
Reports
First seenDec 22, 2024
Last seenJan 29, 2026
GeolocationCN
CountryChina
LocationXi'an, SN
ASNAS4837
OrgCNC Group CHINA169 Shanni Province Network
Coords38.2880, 109.7373

VirusTotal

Not checked

WHOIS

description
Host bruteforcing SSH
raw
inetnum: 123.138.71.0 - 123.138.71.255 netname: PPPoe country: CN descr: XiAnCity-IpAddressPool-128 admin-c: CH679-AP tech-c: CH679-AP status: ASSIGNED NON-PORTABLE mnt-by: MAINT-CNCGROUP-SN last-modified: 2008-11-13T02:30:47Z source: APNIC person: CNCGroup-SN Hostmaster nic-hdl: CH679-AP e-mail: [email protected] address: China Network Communication ,SVT address: NO.2 GuangDe Road, High Tec Zone address: Xi'an, Shannxi, China phone: +86-29-88192060 fax-no: +86-29-88192037 country: CN mnt-by: MAINT-CNCGROUP-SN last-modified: 2008-09-04T07:35:34Z source: APNIC route: 123.138.0.0/15 descr: CNC Group CHINA169 Shanni Province Network country: CN origin: AS4837 mnt-by: MAINT-CNCGROUP-RR last-modified: 2008-09-04T07:54:55Z source: APNIC
references
https://blog.edie.io/2020/04/30/diy-ip-threat-feed/, https://github.com/tankmek/threatfeed, https://raw.githubusercontent.com/ahamed-rizvan/IOCs/refs/heads/main/Malicous%20IP%20Address.txt, https://redpiranha.net, https://blocklist.greensnow.co/greensnow.txt, https://www.binarydefense.com/banlist.txt, https://lists.blocklist.de/lists/all.txt, https://rules.emergingthreats.net/blockrules/compromised-ips.txt

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 4 months ago
Appeared in 18 threat reports