IOC Radar
IPMediumSignal 51/100

139.0.29.221

Location
IndonesiaIndonesia
Tangerang, Jakarta
ASN
AS9905
PT. First Media, Tbk
First Seen
Apr 7, 2025
Last Seen
May 17, 2026
Apr 7
First Seen
430d ago
May 17
Last Seen
25d ago
13
Reports
source reports
51%
Confidence
medium
1/91
VirusTotal
detections
Found in 13 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
51%
Signal Score
51 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

54 techniques

Network Information

CountryIDIndonesia
RegionTangerang, Jakarta
ASNAS9905
OrganizationPT. First Media, Tbk

Feed Intelligence Summary

13 reports51% confidence
13
Source reports
51%
Confidence score
Category tags
abuseaccess controlactive scanactive scanningasiaattackaustraliabad reputationbad web botblacklist candidateblacklisted ipblog spambot trafficbotnetbotnet activitybrute forcebrute force attackbrute force attacksc2c2 communicationcommand & controlcommand and controlcommunication protocolcommunication technologiescompromised devicecompromised hostcompromised systemcowrie honeypotcredential accesscredential harvestingcredential stuffingdata encryptiondata exfiltrationdata store exposuredatabase securityddosddos attackddos attacksdecoy systemdenial of servicedionaea honeypotdistributed attacksencryptioneuropeexploitexploitation activityexploited hostfattfinlandfranceftp attacksftp brute forcegermanyhackinghoneynet connecthoneytrap honeypothttp brute forceididentity & access exploitationindicatorindonesiainjection activityinjection attacksinternet of thingsintrusion detectioniot botnetiot securityiot/ics attacklateral movementlogin attemptmailoney honeypotmalicious activitymalicious domainmalicious ipmalicious softwaremalicious trafficmalwaremalware behaviourmalware capturemalware detectionmalware distributionmiraimirai botnetmobile carriersmobile networksnetworknetwork attacksnetwork enumerationnetwork intrusionnetwork probenetwork probingnetwork protocolnetwork scannetwork scanningnetwork securitynetwork trafficnorth americaoceaniap0fpassword attackpassword attacksphishingphishing attackphishing trappolandprocess injectionprotocol exploitationreconnaissanceremote accessremote servicesresearchedresource hijackingscanscannerscanning activitysecurity operationssecurity policysensor-taggedsentrypeer botnetsmbsmb brute forcesmtp brute forcesocial engineeringspamssh attackssh attacksssh monitoringt1016t1021t1021.001t1021.002t1021.003t1021.004t1021.005t1040t1046t1055t1057t1059t1059.001t1059.003t1059.004t1068t1071t1071.001t1071.004t1076t1077t1078t1105t1110t1110.001t1110.002t1110.003t1110.004t1133t1190t1203t1210t1486t1496t1497.001t1499t1499.001t1499.002t1499.003t1550.003t1562t1563t1565t1566t1566.001t1566.002t1566.003t1573t1573.001t1592t1595t1595.001t1595.002t1595.003tannertcptcp protocoltcp scantelecom servicestelecommunicationstelnet threatthreat actorthreat detectionthreat intelligencethreat preventiontor nodetpotudp scanunauthorized access attemptunited statesvoip attackweb application attackweb exploitationweb exploitsweb spam

Activity Timeline

1 total obs
May 17May 17

Threat Activity Heatmap

· Peak: 2026-05-17
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Threat ScoreMedium Risk
51
SIGNAL
Signal Score
51%
Confidence
13
Reports
First seenApr 7, 2025
Last seenMay 17, 2026
GeolocationID
CountryIndonesia
LocationTangerang, Jakarta
ASNAS9905
OrgPT. First Media, Tbk
Coords-6.2339, 106.8240

VirusTotal

1/ 91vendors flagged
1% detection rateJun 12, 2026

WHOIS

description
Scans hitting the server at TCP port 445 SMB. Same IP should not appear more than once in 96 hours in our lists S3#.
raw
inetnum: 139.0.0.0 - 139.0.255.255 netname: BM-ID descr: PT. First Media,Tbk descr: Broadband Internet Service descr: Citra Graha Building 4th Floor descr: Jl. Gatot Subroto Kav 35-36 descr: Jakarta - Indonesia country: ID admin-c: EB26-AP tech-c: PA170-AP remarks: Spam and Abuse send to: [email protected] mnt-by: MNT-APJII-ID mnt-lower: MAINT-ID-BM mnt-irt: IRT-BM-ID status: ALLOCATED PORTABLE last-modified: 2016-06-06T06:23:16Z source: APNIC irt: IRT-BM-ID address: PT. First Media,Tbk address: Citra Graha Building 4th Floor address: Jl. Gatot Subroto Kav 35-36 address: Jakarta - Indonesia, 12950 e-mail: [email protected] abuse-mailbox: [email protected] admin-c: EB26-AP tech-c: HFN1-AP auth: # Filtered mnt-by: MAINT-ID-BM last-modified: 2020-03-13T07:22:43Z source: APNIC person: Eko Budirahardjo nic-hdl: EB26-AP e-mail: [email protected] address: Lippo Cyber Park address: Jl. Bulevar Gajah Mada No.2088 address: Lippo Karawaci 100, Tangerang 15811. Indonesia phone: +62-21-55777755 fax-no: +62-21-5530752 country: ID mnt-by: MAINT-ID-LINKNET last-modified: 2008-09-04T07:30:20Z source: APNIC person: Putut Ardiyanto address: Citra Graha Building fl.04 address: Gatot Subroto Kav. 35-36 address: Jakarta country: ID phone: +62-21-5278811 fax-no: +62-21-5278833 e-mail: [email protected] nic-hdl: PA170-AP mnt-by: MAINT-ID-BM last-modified: 2012-08-07T08:30:02Z source: APNIC route: 139.0.29.0/24 descr: Route object of PT. LINKNET descr: Internet Service Provider origin: AS9905 mnt-by: MAINT-ID-LINKNET last-modified: 2017-05-24T02:33:48Z source: APNIC inetnum: 139.0.0.0 - 139.0.255.255 netname: BM-ID descr: PT. First Media,Tbk descr: Broadband Internet Service descr: Citra Graha Building 4th Floor descr: Jl. Gatot Subroto Kav 35-36 descr: Jakarta - Indonesia country: ID admin-c: EB26-AP tech-c: PA170-AP remarks: Spam and Abuse send to: [email protected] mnt-by: MNT-APJII-ID mnt-lower: MAINT-ID-BM mnt-irt: IRT-BM-ID status: ALLOCATED PORTABLE last-modified: 2016-06-06T06:23:16Z source: IDNIC irt: IRT-BM-ID address: PT. First Media,Tbk address: Citra Graha Building 4th Floor address: Jl. Gatot Subroto Kav 35-36 address: Jakarta - Indonesia, 12950 e-mail: [email protected] abuse-mailbox: [email protected] admin-c: EB26-AP tech-c: HFN1-AP auth: # Filtered mnt-by: MAINT-ID-BM last-modified: 2020-03-13T07:23:43Z source: IDNIC person: Eko Budirahardjo nic-hdl: EB26-AP e-mail: [email protected] address: Lippo Cyber Park address: Jl. Bulevar Gajah Mada No.2088 address: Lippo Karawaci 100, Tangerang 15811. Indonesia phone: +62-21-55777755 fax-no: +62-21-5530752 country: ID mnt-by: MAINT-ID-LINKNET last-modified: 2008-09-04T07:30:20Z source: IDNIC person: Putut Ardiyanto address: Citra Graha Building fl.04 address: Gatot Subroto Kav. 35-36 address: Jakarta country: ID phone: +62-21-5278811 fax-no: +62-21-5278833 e-mail: [email protected] nic-hdl: PA170-AP mnt-by: MAINT-ID-BM last-modified: 2012-08-07T08:30:02Z source: IDNIC route: 139.0.29.0/24 descr: Route object of PT. LINKNET descr: Internet Service Provider origin: AS9905 mnt-by: MAINT-ID-LINKNET last-modified: 2017-05-24T02:33:48Z source: IDNIC

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 25 days ago
Appeared in 13 threat reports