IPMediumSignal 68/100
151.242.30.224
Location
Centurion, Gauteng
ASN
AS214209
Internet Magnate (Pty) Ltd
First Seen
Feb 11, 2026
Last Seen
Jun 10, 2026
Found in 9 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
68%
Signal Score
68 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Network Information
Country
South Africa
RegionCenturion, Gauteng
ASNAS214209
OrganizationInternet Magnate (Pty) Ltd
Feed Intelligence Summary
9 reports68% confidence
9
Source reports
68%
Confidence score
Category tags
abuseactive scanactive scanningafricaaptbad reputationbad web botbotnet activitybrute forcebrute-forceddosddos attackeuropeexploitation activityexploited hosthackinginbound scanindicatormalwarenetworkphishingreconnaissanceresearchedroromaniascannersouth africassht1595t1595.001t1595.002t1595.003threat actortpotweb app attackza
Activity Timeline
Jun 10Jun 10
Threat Activity Heatmap
LessMore
Mon
Wed
Fri
24h
1
Minimal
7d
1
Minimal
30d
1
Minimal
3mo
1
Minimal
Intelligence SummaryAI Generated
The IP address 151.242.30.224 represents a significant and urgent threat, evidenced by its high threat score and repeated inclusion in numerous threat intelligence feeds. This Indicator of Compromise (IOC) is strongly associated with reconnaissance activities, including active scanning, vulnerability scanning, and port scanning, which typically precede more sophisticated attacks. Its detection suggests potential preparatory phases of an attack targeting organizational assets, increasing the risk…
Threat ScoreMedium Risk
68
SIGNAL
Signal Score
68%
Confidence
9
Reports
First seenFeb 11, 2026
Last seenJun 10, 2026
GeolocationZA
CountrySouth Africa
LocationCenturion, Gauteng
ASNAS214209
OrgInternet Magnate (Pty) Ltd
Coords-26.2022, 28.0435
VirusTotal
Not checked
WHOIS
- description
- Score: 84/100. Labels: abuseipdb:critical, abuseipdb:exploited-host, abuseipdb:hacking, abuseipdb:multi-reported, abuseipdb:port-scan, abuseipdb:reported. 151.242.30.224 classified as botnet node participating in coordinated attack campaigns (high confidence). Origin: enriched. Listed on: AbuseIPDB (critical, exploited-host, hacking).
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 3 months ago · Last seen today
Appeared in 9 threat reports