IOC Radar
IPMediumSignal 73/100

138.197.78.104

Location
United StatesUnited States
Clifton, New Jersey
ASN
AS14061
Digital Ocean
First Seen
Mar 25, 2026
Last Seen
May 22, 2026
Mar 25
First Seen
79d ago
May 22
Last Seen
22d ago
7
Reports
source reports
73%
Confidence
medium
Found in 7 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
73%
Signal Score
73 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

11 techniques

Network Information

CountryUSUnited States
RegionClifton, New Jersey
ASNAS14061
OrganizationDigital Ocean

Feed Intelligence Summary

7 reports73% confidence
7
Source reports
73%
Confidence score
Category tags
abuseactive scanactive scanningaustraliabad reputationbad web botbotnet activitybrute forcebrute force attackbrute-forcecredential accesscredential stuffingddosdenial of serviceexploitation activityexploited hosthackingidentity & access exploitationindicatornetworknorth americaoceaniapassword attacksreconnaissanceresearchedscanscannersipssht1110.001t1110.002t1110.003t1110.004t1190t1203t1499.001t1595t1595.001t1595.002t1595.003united statesusweb app attackweb application attackweb exploitation

Activity Timeline

1 total obs
May 22May 22

Threat Activity Heatmap

· Peak: 2026-05-22
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Threat ScoreHigh Risk
73
SIGNAL
Signal Score
73%
Confidence
7
Reports
First seenMar 25, 2026
Last seenMay 22, 2026
GeolocationUS
CountryUnited States
LocationClifton, New Jersey
ASNAS14061
OrgDigital Ocean
Coords40.8302, -74.1299

VirusTotal

Not checked

WHOIS

description
IPV4 hosts detected performing scans on production environment located in Australia.
raw
NetRange: 138.197.0.0 - 138.197.255.255 CIDR: 138.197.0.0/16 NetName: DIGITALOCEAN-138-197-0-0 NetHandle: NET-138-197-0-0-1 Parent: NET138 (NET-138-0-0-0-0) NetType: Direct Allocation OriginAS: Organization: DigitalOcean, LLC (DO-13) RegDate: 2016-01-26 Updated: 2020-04-03 Comment: Routing and Peering Policy can be found at https://www.as14061.net Comment: Comment: Please submit abuse reports at https://www.digitalocean.com/company/contact/#abuse Ref: https://rdap.arin.net/registry/ip/138.197.0.0 OrgName: DigitalOcean, LLC OrgId: DO-13 Address: 105 Edgeview Drive, Suite 425 City: Broomfield StateProv: CO PostalCode: 80021 Country: US RegDate: 2012-05-14 Updated: 2025-04-11 Ref: https://rdap.arin.net/registry/entity/DO-13 OrgAbuseHandle: DIGIT19-ARIN OrgAbuseName: DigitalOcean Abuse OrgAbusePhone: +1-646-827-4366 OrgAbuseEmail: [email protected] OrgAbuseRef: https://rdap.arin.net/registry/entity/DIGIT19-ARIN OrgNOCHandle: NOC32014-ARIN OrgNOCName: Network Operations Center OrgNOCPhone: +1-646-827-4366 OrgNOCEmail: [email protected] OrgNOCRef: https://rdap.arin.net/registry/entity/NOC32014-ARIN OrgTechHandle: NOC32014-ARIN OrgTechName: Network Operations Center OrgTechPhone: +1-646-827-4366 OrgTechEmail: [email protected] OrgTechRef: https://rdap.arin.net/registry/entity/NOC32014-ARIN

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 2 months ago · Last seen 22 days ago
Appeared in 7 threat reports