IOC Radar
IPMediumSignal 100/100

134.249.202.156

Location
UkraineUkraine
Kyiv, Kyiv City
ASN
AS15895
Kyivstar LLC
First Seen
Aug 14, 2024
Last Seen
Feb 15, 2026
Aug 14
First Seen
678d ago
Feb 15
Last Seen
129d ago
14
Reports
source reports
99%
Confidence
medium
Found in 14 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
99%
Signal Score
100 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

34 techniques

Network Information

CountryUAUkraine
RegionKyiv, Kyiv City
ASNAS15895
OrganizationKyivstar LLC

Feed Intelligence Summary

14 reports99% confidence
14
Source reports
99%
Confidence score
Category tags
abuseaccess controlaccount discoveryaccount profilingaccount takeoveractive scanningattackauthenticationbotnetbrute forcebrute force attackbrute force attemptcommand and controlcommunication protocolcredential accesscredential stuffingctadata exfiltrationddosddos attacksdecoy systemdistributed attackseuropeindicatorinternet of thingsintrusion detectioniociot botnetiot/ics attackloginlogin brute-forcemalicious activitymalicious network activitymalicious softwaremalwaremirai botnetnetworknetwork attacksnetwork intrusionnetwork probingnetwork protocolnetwork scanningnetwork securitynetwork service scanningnorth americapassword attacksprocess injectionprotocol exploitationreconnaissanceremote accessremote servicesresearchedrtbhscanscannersecurity policysocradar honeypotssh attackt1021t1021.002t1021.004t1040t1046t1055t1056.001t1059.001t1071.001t1078t1078.001t1110t1110.001t1110.002t1110.003t1110.004t1133t1187t1190t1486t1496t1499.001t1499.002t1499.003t1550t1550.002t1555t1555.004t1565t1567t1595t1595.001t1595.002t1595.003tcp protocoltelecommunicationstelnet threatthreat actorthreat intelligencethreat preventionukraineunited statesus source ipvalid accounts

Activity Timeline

1 total obs
Feb 15Feb 15

Threat Activity Heatmap

· Peak: 2026-02-15
Less
More
Mon
Wed
Fri
Jun
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Threat ScoreHigh Risk
100
SIGNAL
Signal Score
99%
Confidence
14
Reports
First seenAug 14, 2024
Last seenFeb 15, 2026
GeolocationUA
CountryUkraine
LocationKyiv, Kyiv City
ASNAS15895
OrgKyivstar LLC
Coords50.4501, 30.5234

VirusTotal

Not checked

WHOIS

description
Telnet bruteforce client IP
raw
inetnum: 134.249.128.0 - 134.249.255.255 netname: KYIVSTAR-NET-10 descr: Kyivstar GSM descr: Ukrainian mobile phone operator country: UA admin-c: KSUA-RIPE tech-c: KSUA-RIPE status: ASSIGNED PA mnt-by: KYIVSTAR-MNT mnt-lower: KYIVSTAR-MNT mnt-routes: KYIVSTAR-MNT created: 2011-12-07T15:35:12Z last-modified: 2011-12-07T15:35:12Z source: RIPE role: Kyivstar PJSC address: Degtyarevskaya, 53 address: Kiev, Ukraine admin-c: AEL17-RIPE admin-c: EB14332-RIPE tech-c: NP1533-RIPE tech-c: EB14332-RIPE tech-c: AEL17-RIPE nic-hdl: KSUA-RIPE remarks: Please send all abuse reports here: abuse-mailbox: [email protected] mnt-by: KYIVSTAR-MNT created: 2003-05-19T14:48:31Z last-modified: 2023-02-23T14:09:33Z source: RIPE # Filtered route: 134.249.0.0/16 descr: Kyivstar GSM, Kiev, Ukraine origin: AS15895 mnt-by: KYIVSTAR-MNT created: 2011-11-07T11:07:26Z last-modified: 2011-11-07T11:07:26Z source: RIPE
references
https://list.rtbh.com.tr/output.txt, https://raw.githubusercontent.com/ahamed-rizvan/IOCs/refs/heads/main/Malicous%20IP%20Address.txt

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 4 months ago
Appeared in 14 threat reports