IOC Radar
IPMediumSignal 69/100

143.198.96.197

Location
United StatesUnited States
Santa Clara, California
ASN
AS14061
DigitalOcean, LLC
First Seen
Nov 17, 2022
Last Seen
Feb 15, 2026
Nov 17
First Seen
1304d ago
Feb 15
Last Seen
118d ago
9
Reports
source reports
69%
Confidence
medium
1/91
VirusTotal
detections
Found in 9 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
69%
Signal Score
69 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

30 techniques

Network Information

CountryUSUnited States
RegionSanta Clara, California
ASNAS14061
OrganizationDigitalOcean, LLC

Feed Intelligence Summary

9 reports69% confidence
9
Source reports
69%
Confidence score
Category tags
abuseactive scanningaerospace & defenseattackautomotive manufacturingblog spambotnetbrute forcebrute force attackcivil servicescommand and controlcompromised credentialsconpotconpot honeypotcowriecowrie honeypotcredential accesscredential harvestingcredential stuffingcyber securitydata exfiltrationddos attackdecoy systemdefensedefense contractingdefense logisticsdefense systemsdefense technologydenial of servicedionaeadionaea honeypotdistributed attackselectronics manufacturingemailexploit kit activityftp brute forceftp brute-forcegithubgovernment technologyhoneytrap honeypotics securityindicatorindustrial automationindustrial control systemsindustrial iotindustrial productioniociot/ics attacklamplateral movementmailoney honeypotmalicious activitymalicious softwaremalwaremalware behaviourmalware capturemanufacturing technologymilitary operationsnational securitynetworknetwork intrusionnetwork intrusion attemptsnetwork scanningnextraynorth americapassword attacksphishingphishing attackphishing trapping of deathprocess injectionprocess manufacturingpublic administrationpublic infrastructurepublic policypythonquality controlreconnaissanceregulatory agenciesresearchedscannersecurity operationssftpsftp attackslugsocial engineeringsshssh attackssh monitoringsupply chain managementsurface webt1021t1041t1046t1053t1055t1059t1071.001t1078t1110t1110.001t1110.002t1110.003t1110.004t1190t1203t1486t1496t1499.001t1499.002t1499.003t1555t1565t1566.001t1566.002t1566.003t1566.004t1595t1595.001t1595.002t1595.003tannertelecommunicationsthreat actorthreat detectionthreat intelligenceunauthorized access attemptunited statesusweb application attackweb exploitationweb spam

Activity Timeline

1 total obs
Feb 15Feb 15

Threat Activity Heatmap

· Peak: 2026-02-15
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Intelligence SummaryAI Generated

This Indicator of Compromise (IOC), an IPv4 address, signals a significant potential threat to organizational security. With a high score of 68.85 and no whitelisting, this IP address is strongly associated with malicious activities observed across multiple threat intelligence feeds. Its presence in network logs could indicate ongoing reconnaissance, attempts at unauthorized access, or command-and-control communications. Unaddressed, this IOC poses risks including data exfiltration, system compr…

Threat ScoreMedium Risk
69
SIGNAL
Signal Score
69%
Confidence
9
Reports
First seenNov 17, 2022
Last seenFeb 15, 2026
GeolocationUS
CountryUnited States
LocationSanta Clara, California
ASNAS14061
OrgDigitalOcean, LLC
Coords37.3931, -121.9620

VirusTotal

1/ 91vendors flagged
1% detection rateJun 3, 2026

WHOIS

description
2025-02-01T10:05:06.678Z Honeypot : ConPot : Source: 143.198.96.197 : Port: 2404 Data Type: IEC104 Event Type: CONNECTION_LOST
raw
NetRange: 143.198.0.0 - 143.198.255.255 CIDR: 143.198.0.0/16 NetName: DIGITALOCEAN-143-198-0-0 NetHandle: NET-143-198-0-0-1 Parent: NET143 (NET-143-0-0-0-0) NetType: Direct Allocation OriginAS: AS14061 Organization: DigitalOcean, LLC (DO-13) RegDate: 2020-01-24 Updated: 2020-04-03 Comment: Routing and Peering Policy can be found at https://www.as14061.net Comment: Comment: Please submit abuse reports at https://www.digitalocean.com/company/contact/#abuse Ref: https://rdap.arin.net/registry/ip/143.198.0.0 OrgName: DigitalOcean, LLC OrgId: DO-13 Address: 101 Ave of the Americas Address: FL2 City: New York StateProv: NY PostalCode: 10013 Country: US RegDate: 2012-05-14 Updated: 2023-10-23 Ref: https://rdap.arin.net/registry/entity/DO-13 OrgTechHandle: NOC32014-ARIN OrgTechName: Network Operations Center OrgTechPhone: +1-347-875-6044 OrgTechEmail: [email protected] OrgTechRef: https://rdap.arin.net/registry/entity/NOC32014-ARIN OrgAbuseHandle: ABUSE5232-ARIN OrgAbuseName: Abuse, DigitalOcean OrgAbusePhone: +1-347-875-6044 OrgAbuseEmail: [email protected] OrgAbuseRef: https://rdap.arin.net/registry/entity/ABUSE5232-ARIN OrgNOCHandle: NOC32014-ARIN OrgNOCName: Network Operations Center OrgNOCPhone: +1-347-875-6044 OrgNOCEmail: [email protected] OrgNOCRef: https://rdap.arin.net/registry/entity/NOC32014-ARIN

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 3 years ago · Last seen 3 months ago
Appeared in 9 threat reports