IOC Radar
IPHighVerifiedSignal 67/100

125.163.209.76

Location
IndonesiaIndonesia
Semarang, Central Java
ASN
AS7713
PT. TELKOM INDONESIA
First Seen
Apr 17, 2026
Last Seen
Apr 23, 2026
Apr 17
First Seen
58d ago
Apr 23
Last Seen
52d ago
4
Reports
source reports
67%
Confidence
high
Found in 4 reports. Confidence: high. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
67%
Signal Score
67 / 100
IDS Rule
No
Threat Context
Tags

Network Information

CountryIDIndonesia
RegionSemarang, Central Java
ASNAS7713
OrganizationPT. TELKOM INDONESIA

Feed Intelligence Summary

4 reports67% confidence
4
Source reports
67%
Confidence score
Category tags
active scanasiabrute forcebrute force attackerindicatorindonesianetworkportscanresearchedscannersservice scanvultr

Activity Timeline

1 total obs
Apr 23Apr 23

Threat Activity Heatmap

· Peak: 2026-04-23
Less
More
Mon
Wed
Fri
Jun
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Intelligence SummaryAI Generated

The IPv4 address 125.163.209.76 is a critical Indicator of Compromise (IOC) with a high score of 66.597, signaling its strong association with malicious activities. Identified across multiple reputable threat intelligence feeds, including "Brute Force Attackers" and "ThreatHose," this IP address has been explicitly linked to aggressive port scanning and potential brute-force attacks. Its presence interacting with organizational assets could denote an active reconnaissance phase, a preliminary st…

Threat ScoreMedium Risk
67
SIGNAL
Signal Score
67%
Confidence
4
Reports
First seenApr 17, 2026
Last seenApr 23, 2026
Verified IOC
GeolocationID
CountryIndonesia
LocationSemarang, Central Java
ASNAS7713
OrgPT. TELKOM INDONESIA
Coords-7.5333, 110.7500

VirusTotal

Not checked

WHOIS

description
IPv4 hosts detected port scanning Vultr Melbourne (Australia) honeypot
raw
inetnum: 125.163.192.0 - 125.163.223.255 netname: TLKM_BB_INF_125_163 country: ID descr: PT TELKOM INDONESIA descr: Menara Multimedia Lt. 7 descr: Jl. Kebonsirih No.12 descr: JAKARTA admin-c: AR165-AP tech-c: HM444-AP remarks: ----------------------------------------------------------- remarks: Broadband Service for Semarang (Jawa Tengah). remarks: ** These IP was used dinamically for end user. ** remarks: Send ABUSE and SPAM reports with plain ASCII text only to remarks: to [email protected]. remarks: The netname enclosed in square bracket is included in the subject. remarks: ----------------------------------------------------------- status: ASSIGNED NON-PORTABLE mnt-by: MAINT-TELKOMNET last-modified: 2009-02-13T06:53:36Z source: APNIC mnt-by: MAINT-TELKOMNET role: PT Telkom Indonesia APNIC Resources Management address: PT. TELKOM INDONESIA address: Menara Multimedia Lt. 7 address: Jl. Kebonsirih No.12 address: JAKARTA country: ID phone: +62-21-3860500 fax-no: +62-21-3861215 e-mail: [email protected] admin-c: HM444-AP tech-c: HM444-AP nic-hdl: AR165-AP notify: [email protected] mnt-by: MAINT-TELKOMNET last-modified: 2008-09-04T07:54:16Z source: APNIC person: PT Telkom Indonesia Hostmaster nic-hdl: HM444-AP e-mail: [email protected] address: PT. TELKOM INDONESIA address: Menara Multimedia Lt. 7 address: Jl. Kebonsirih No.12 address: JAKARTA phone: +62-21-3860500 fax-no: +62-21-3861215 country: ID notify: [email protected] mnt-by: MAINT-TELKOMNET last-modified: 2008-09-04T07:29:40Z source: APNIC route: 125.163.208.0/21 descr: PT. TELKOM INDONESIA descr: JAKARTA country: ID origin: AS17974 mnt-by: MAINT-TELKOMNET last-modified: 2015-05-27T03:33:18Z source: APNIC route: 125.163.208.0/21 origin: AS7713 descr: Telekomunikasi Indonesia (PT) PT Telkom - Divisi Infratel Gedung STO Gambir LT 3 Sub Divisi Resource Management & Operation Jalan Merdeka Selatan No .12 mnt-by: MAINT-TELKOMNET last-modified: 2021-07-16T03:03:28Z source: APNIC

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

high
First detected 1 month ago · Last seen 1 month ago
Appeared in 4 threat reports