IOC Radar
IPMediumSignal 69/100

130.41.87.199

Location
GermanyGermany
Frankfurt am Main, Hesse
ASN
AS394089
Palo Alto Networks
First Seen
Feb 22, 2025
Last Seen
Apr 23, 2026
Feb 22
First Seen
477d ago
Apr 23
Last Seen
52d ago
7
Reports
source reports
69%
Confidence
medium
Found in 7 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
69%
Signal Score
69 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

23 techniques

Network Information

CountryDEGermany
RegionFrankfurt am Main, Hesse
ASNAS394089
OrganizationPalo Alto Networks

Feed Intelligence Summary

7 reports69% confidence
7
Source reports
69%
Confidence score
Category tags
access controlactive scanactive scanningattackbad reputationblacklist candidatebotnetbotnet activitybrute forcebrute force attackbrute force attackerbrute-forcecommand and controlcommunication protocolcredential accesscredential stuffingdata encryptiondata exfiltrationdata store exposureddosddos attackddos attacksdecoy systemdigital oceandistributed attacksencryptioneuropeexploitation activityexploited hostgermanyhackingidentity & access exploitationindicatorinjection activityinternet of thingsintrusion detectioniot botnetiot securityiot/ics attacklateral movementmalicious activitymalicious ipmalicious softwaremalwaremiraimirai botnetnetworknetwork attacksnetwork probingnetwork protocolnetwork scannetwork scanningnetwork securitynorth americapassword attacksping of deathportscanprocess injectionreconnaissanceresearchedscanscannerscannerssecurity policyservice scansmbt1021.002t1040t1046t1055t1068t1071.001t1077t1105t1110.001t1110.002t1110.003t1110.004t1210t1486t1496t1499.001t1499.002t1499.003t1550.003t1565t1595.001t1595.002t1595.003tcptcp protocolthreat actorthreat intelligencethreat preventiontor nodeunited states

Activity Timeline

1 total obs
Apr 23Apr 23

Threat Activity Heatmap

· Peak: 2026-04-23
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreMedium Risk
69
SIGNAL
Signal Score
69%
Confidence
7
Reports
First seenFeb 22, 2025
Last seenApr 23, 2026
GeolocationDE
CountryGermany
LocationFrankfurt am Main, Hesse
ASNAS394089
OrgPalo Alto Networks
Coords37.7510, -97.8220

VirusTotal

Not checked

WHOIS

description
IPv4 hosts detected port scanning DigitalOcean London (UK) honeypot
raw
inetnum: 130.38.0.0 - 130.42.255.255 netname: NON-RIPE-NCC-MANAGED-ADDRESS-BLOCK descr: IPv4 address block not managed by the RIPE NCC remarks: ------------------------------------------------------ remarks: remarks: For registration information, remarks: you can consult the following sources: remarks: remarks: IANA remarks: http://www.iana.org/assignments/ipv4-address-space remarks: http://www.iana.org/assignments/iana-ipv4-special-registry remarks: http://www.iana.org/assignments/ipv4-recovered-address-space remarks: remarks: AFRINIC (Africa) remarks: http://www.afrinic.net/ whois.afrinic.net remarks: remarks: APNIC (Asia Pacific) remarks: http://www.apnic.net/ whois.apnic.net remarks: remarks: ARIN (Northern America) remarks: http://www.arin.net/ whois.arin.net remarks: remarks: LACNIC (Latin America and the Carribean) remarks: http://www.lacnic.net/ whois.lacnic.net remarks: remarks: ------------------------------------------------------ country: EU # Country is really world wide admin-c: IANA1-RIPE tech-c: IANA1-RIPE status: ALLOCATED UNSPECIFIED mnt-by: RIPE-NCC-HM-MNT created: 2019-01-07T10:44:21Z last-modified: 2019-01-07T10:44:21Z source: RIPE role: Internet Assigned Numbers Authority address: see http://www.iana.org. admin-c: IANA1-RIPE tech-c: IANA1-RIPE nic-hdl: IANA1-RIPE remarks: For more information on IANA services remarks: go to IANA web site at http://www.iana.org. mnt-by: RIPE-NCC-MNT created: 1970-01-01T00:00:00Z last-modified: 2001-09-22T09:31:27Z source: RIPE # Filtered
references
https://jamesbrine.com.au/digitaloceanlondon-portscan-bruteforce-ip-list-2026-04-16/, https://jamesbrine.com.au

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 1 month ago
Appeared in 7 threat reports