IPMediumSignal 69/100
143.198.96.197
Location
Santa Clara, California
ASN
AS14061
DigitalOcean, LLC
First Seen
Nov 17, 2022
Last Seen
Feb 15, 2026
Nov 17
First Seen
1304d ago
Feb 15
Last Seen
118d ago
9
Reports
source reports
69%
Confidence
medium
1/91
VirusTotal
detections
Found in 9 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
69%
Signal Score
69 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Network Information
Country
United States
RegionSanta Clara, California
ASNAS14061
OrganizationDigitalOcean, LLC
Feed Intelligence Summary
9 reports69% confidence
9
Source reports
69%
Confidence score
Category tags
abuseactive scanningaerospace & defenseattackautomotive manufacturingblog spambotnetbrute forcebrute force attackcivil servicescommand and controlcompromised credentialsconpotconpot honeypotcowriecowrie honeypotcredential accesscredential harvestingcredential stuffingcyber securitydata exfiltrationddos attackdecoy systemdefensedefense contractingdefense logisticsdefense systemsdefense technologydenial of servicedionaeadionaea honeypotdistributed attackselectronics manufacturingemailexploit kit activityftp brute forceftp brute-forcegithubgovernment technologyhoneytrap honeypotics securityindicatorindustrial automationindustrial control systemsindustrial iotindustrial productioniociot/ics attacklamplateral movementmailoney honeypotmalicious activitymalicious softwaremalwaremalware behaviourmalware capturemanufacturing technologymilitary operationsnational securitynetworknetwork intrusionnetwork intrusion attemptsnetwork scanningnextraynorth americapassword attacksphishingphishing attackphishing trapping of deathprocess injectionprocess manufacturingpublic administrationpublic infrastructurepublic policypythonquality controlreconnaissanceregulatory agenciesresearchedscannersecurity operationssftpsftp attackslugsocial engineeringsshssh attackssh monitoringsupply chain managementsurface webt1021t1041t1046t1053t1055t1059t1071.001t1078t1110t1110.001t1110.002t1110.003t1110.004t1190t1203t1486t1496t1499.001t1499.002t1499.003t1555t1565t1566.001t1566.002t1566.003t1566.004t1595t1595.001t1595.002t1595.003tannertelecommunicationsthreat actorthreat detectionthreat intelligenceunauthorized access attemptunited statesusweb application attackweb exploitationweb spam
Activity Timeline
Feb 15Feb 15
Threat Activity Heatmap
· Peak: 2026-02-15LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Intelligence SummaryAI Generated
This Indicator of Compromise (IOC), an IPv4 address, signals a significant potential threat to organizational security. With a high score of 68.85 and no whitelisting, this IP address is strongly associated with malicious activities observed across multiple threat intelligence feeds. Its presence in network logs could indicate ongoing reconnaissance, attempts at unauthorized access, or command-and-control communications. Unaddressed, this IOC poses risks including data exfiltration, system compr…
Threat ScoreMedium Risk
69
SIGNAL
Signal Score
69%
Confidence
9
Reports
First seenNov 17, 2022
Last seenFeb 15, 2026
GeolocationUS
CountryUnited States
LocationSanta Clara, California
ASNAS14061
OrgDigitalOcean, LLC
Coords37.3931, -121.9620
WHOIS
- description
- 2025-02-01T10:05:06.678Z Honeypot : ConPot : Source: 143.198.96.197 : Port: 2404 Data Type: IEC104 Event Type: CONNECTION_LOST
- raw
- NetRange: 143.198.0.0 - 143.198.255.255 CIDR: 143.198.0.0/16 NetName: DIGITALOCEAN-143-198-0-0 NetHandle: NET-143-198-0-0-1 Parent: NET143 (NET-143-0-0-0-0) NetType: Direct Allocation OriginAS: AS14061 Organization: DigitalOcean, LLC (DO-13) RegDate: 2020-01-24 Updated: 2020-04-03 Comment: Routing and Peering Policy can be found at https://www.as14061.net Comment: Comment: Please submit abuse reports at https://www.digitalocean.com/company/contact/#abuse Ref: https://rdap.arin.net/registry/ip/143.198.0.0 OrgName: DigitalOcean, LLC OrgId: DO-13 Address: 101 Ave of the Americas Address: FL2 City: New York StateProv: NY PostalCode: 10013 Country: US RegDate: 2012-05-14 Updated: 2023-10-23 Ref: https://rdap.arin.net/registry/entity/DO-13 OrgTechHandle: NOC32014-ARIN OrgTechName: Network Operations Center OrgTechPhone: +1-347-875-6044 OrgTechEmail: [email protected] OrgTechRef: https://rdap.arin.net/registry/entity/NOC32014-ARIN OrgAbuseHandle: ABUSE5232-ARIN OrgAbuseName: Abuse, DigitalOcean OrgAbusePhone: +1-347-875-6044 OrgAbuseEmail: [email protected] OrgAbuseRef: https://rdap.arin.net/registry/entity/ABUSE5232-ARIN OrgNOCHandle: NOC32014-ARIN OrgNOCName: Network Operations Center OrgNOCPhone: +1-347-875-6044 OrgNOCEmail: [email protected] OrgNOCRef: https://rdap.arin.net/registry/entity/NOC32014-ARIN
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 3 years ago · Last seen 3 months ago
Appeared in 9 threat reports