IOC Radar
IPMediumSignal 83/100

149.102.142.170

Location
GermanyGermany
Lauterbourg, North Rhine-Westphalia
ASN
AS51167
Contabo GmbH
First Seen
Apr 15, 2026
Last Seen
May 29, 2026
Apr 15
First Seen
59d ago
May 29
Last Seen
15d ago
12
Reports
source reports
83%
Confidence
medium
6/91
VirusTotal
detections
Found in 12 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
83%
Signal Score
83 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

8 techniques

Network Information

CountryDEGermany
RegionLauterbourg, North Rhine-Westphalia
ASNAS51167
OrganizationContabo GmbH

Feed Intelligence Summary

12 reports83% confidence
12
Source reports
83%
Confidence score
Category tags
active scanactive scanningaustraliabrute forcebrute force attackbrute force attackerbrute-forcecredential accesscredential stuffingeuropeexploitation activityfrfrancegermanyhackingidentity & access exploitationindicatornetworkoceaniapassword attacksportscanreconnaissanceresearchedscannerscannersself-signedservice scansshssh attackt1110t1110.001t1110.002t1110.003t1110.004t1595.001t1595.002t1595.003vultr

Activity Timeline

1 total obs
May 29May 29

Threat Activity Heatmap

· Peak: 2026-05-29
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Threat ScoreHigh Risk
83
SIGNAL
Signal Score
83%
Confidence
12
Reports
First seenApr 15, 2026
Last seenMay 29, 2026
GeolocationDE
CountryGermany
LocationLauterbourg, North Rhine-Westphalia
ASNAS51167
OrgContabo GmbH
Coords51.2230, 6.7824

VirusTotal

6/ 91vendors flagged
7% detection rateJun 6, 2026

WHOIS

description
Host bruteforcing SSH
raw
NetRange: 149.102.0.0 - 149.102.255.255 CIDR: 149.102.0.0/16 NetName: COGENT-149-102-16 NetHandle: NET-149-102-0-0-1 Parent: NET149 (NET-149-0-0-0-0) NetType: Direct Allocation OriginAS: Organization: Cogent Communications, LLC (COGC) RegDate: 1992-01-28 Updated: 2025-09-23 Ref: https://rdap.arin.net/registry/ip/149.102.0.0 OrgName: Cogent Communications, LLC OrgId: COGC Address: 2450 N Street NW City: Washington StateProv: DC PostalCode: 20037 Country: US RegDate: 2000-05-30 Updated: 2025-09-23 Comment: Geofeed https://geofeed.cogentco.com/geofeed.csv Ref: https://rdap.arin.net/registry/entity/COGC ReferralServer: rwhois://rwhois.cogentco.com:4321 OrgNOCHandle: ZC108-ARIN OrgNOCName: Cogent Communications OrgNOCPhone: +1-877-875-4311 OrgNOCEmail: [email protected] OrgNOCRef: https://rdap.arin.net/registry/entity/ZC108-ARIN OrgAbuseHandle: COGEN-ARIN OrgAbuseName: Cogent Abuse OrgAbusePhone: +1-877-875-4311 OrgAbuseEmail: [email protected] OrgAbuseRef: https://rdap.arin.net/registry/entity/COGEN-ARIN OrgTechHandle: IPALL-ARIN OrgTechName: IP Allocation OrgTechPhone: +1-877-875-4311 OrgTechEmail: [email protected] OrgTechRef: https://rdap.arin.net/registry/entity/IPALL-ARIN

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 month ago · Last seen 15 days ago
Appeared in 12 threat reports