IPMediumSignal 47/100
152.32.185.104
Location
Hong Kong, Kowloon
ASN
AS135377
Ucloud Information Technology (hk) Limited
First Seen
Feb 12, 2025
Last Seen
Jun 14, 2026
Found in 20 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
47%
Signal Score
47 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Network Information
Country
Hong Kong
RegionHong Kong, Kowloon
ASNAS135377
OrganizationUcloud Information Technology (hk) Limited
Feed Intelligence Summary
20 reports47% confidence
20
Source reports
47%
Confidence score
Category tags
abuseaccessactive scanactive scanningadbhoney activityadbhoney honeypotapplication layer protocolasiaattackauthentication attackbad reputationbankingblacklisted indicatorsbotnetbotnet activitybrute forcebrute force attackc2 communicationc2 servercommand & controlcommand and controlcommunication protocolcompromised credentialscompromised hostscompromised systemsconnectconpot activityconpot honeypotconpot ics attackcowriecowrie activitycowrie honeypotcowrie interactionscowrie ssh attackcowrie ssh attackscredential accesscredential harvestingcredential stuffingcredit card servicesctadata encryptiondata exfiltrationdata store exposuredata theftdatabase securityddosdecoy systemdenial of servicedictionary attackdionaeadionaea activitydionaea honeypotdionaea interactionsdionaea malware detectiondistributed attackselasticpot honeypotelasticsearch monitoringemailencryptionexploit kit activityexploit probingexploitation activityextortionfinancefinancial servicesfinancial technologyftp brute forcegroupshkhoneytrap honeypothong kongics securityidentity & access exploitationimapindicatorindustrial control systemsinitial accessinjection activityiociot securityiot/ics attackipphoney honeypotlamplamp exploitation attemptslateral movementmailoney activitymailoney email attacksmailoney email spoofingmailoney honeypotmalicious activitymalicious activity detectedmalicious indicator blockingmalicious indicators blockingmalicious payload detectionmalicious python scriptsmalicious softwaremalicious trafficmalwaremalware behaviourmalware capturemalware distributionmalware hostingnetworknetwork intrusion attemptsnetwork iocnetwork probingnetwork scanningnetwork securitynetwork service scanningnetwork traffic analysisnorth americaonline sextortionpassword attackspayment processingphishingphishing attackphishing trapphishing urlspotential malware deliverypotential malware distributionprocess injectionprotocol exploitationransomwarereadmereconnaissanceredis honeypotremote servicesresearchedresource hijackingscannerscanning activityscriptsecurity operationssentrypeer activitysentrypeer attackssentrypeer botnetsentrypeer p2p attackservice scansftpsftp access attemptsftp activitysftp attacksftp scanningshell access attemptssipsip attackssip brute forcesip probingsip scanningslugsmtpsmtp brute forcesocial engineeringsocradar honeypotspamsshssh attackssh monitoringstorm-2603surface websystem disruptiont1003t1005t1016t1018t1021t1021.001t1021.002t1021.004t1027t1040t1041t1046t1048t1053t1055t1056t1059t1059.001t1059.004t1068t1071t1071.001t1078t1078.001t1078.002t1078.003t1078.004t1083t1105t1106t1110t1110.001t1110.002t1110.003t1110.004t1119t1124t1133t1189t1190t1199t1203t1204t1204.002t1486t1490t1496t1499.001t1499.002t1499.003t1565t1566t1566.001t1566.002t1566.003t1566.004t1571t1573t1583t1588t1589t1589.002t1590t1595t1595.001t1595.002t1595.003tannertanner activitytanner interactionstanner web attacktargeting databasetcptelecommunicationstelnet threatthreat actorthreat detectionthreat intelligencetor nodetpotceunited statesvoipvoip attackvulnerability scanwealth managementweb application attackweb exploitationweb scanner
Activity Timeline
Jun 14Jun 14
Threat Activity Heatmap
· Peak: 2026-06-14LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Threat ScoreMedium Risk
47
SIGNAL
Signal Score
47%
Confidence
20
Reports
First seenFeb 12, 2025
Last seenJun 14, 2026
GeolocationHK
CountryHong Kong
LocationHong Kong, Kowloon
ASNAS135377
OrgUcloud Information Technology (hk) Limited
Coords22.2578, 114.1657
VirusTotal
Not checked
WHOIS
- description
- 2025-02-12T16:27:28.950Z Honeypot : Dionaea : Source: 152.32.185.104 : Port: 27017 Connection: {'protocol': 'mongod', 'type': 'accept', 'transport': 'tcp'}
- raw
- inetnum: 152.32.185.0 - 152.32.185.255 netname: UCLOUD-HK descr: UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED country: HK admin-c: UITH2-AP tech-c: UITH2-AP status: ALLOCATED NON-PORTABLE mnt-by: MAINT-UCLOUD-HK mnt-irt: IRT-UCLOUD-HK abuse-c: AU164-AP last-modified: 2024-08-21T11:32:37Z source: APNIC irt: IRT-UCLOUD-HK address: FLAT/RM 603 6/F, LAWS COMMERCIAL PLAZA, 788 CHEUNG SHA WAN ROAD, KL,, Hong Kong e-mail: [email protected] abuse-mailbox: [email protected] admin-c: UITH2-AP tech-c: UITH2-AP auth: # Filtered remarks: [email protected] was validated on 2025-07-01 remarks: [email protected] was validated on 2025-07-01 mnt-by: MAINT-UCLOUD-HK last-modified: 2025-09-04T07:41:27Z source: APNIC role: ABUSE UCLOUDHK country: ZZ address: FLAT/RM 603 6/F, LAWS COMMERCIAL PLAZA, 788 CHEUNG SHA WAN ROAD, KL,, Hong Kong phone: +000000000 e-mail: [email protected] admin-c: UITH2-AP tech-c: UITH2-AP nic-hdl: AU164-AP remarks: Generated from irt object IRT-UCLOUD-HK remarks: [email protected] was validated on 2025-07-01 remarks: [email protected] was validated on 2025-07-01 abuse-mailbox: [email protected] mnt-by: APNIC-ABUSE last-modified: 2025-07-01T09:51:21Z source: APNIC role: UCLOUD INFORMATION TECHNOLOGY HK LIMITED address: FLAT/RM 603 6/F, LAWS COMMERCIAL PLAZA, 788 CHEUNG SHA WAN ROAD, KL,, Hong Kong country: HK phone: +000000000 e-mail: [email protected] admin-c: UITH2-AP tech-c: UITH2-AP nic-hdl: UITH2-AP notify: [email protected] mnt-by: MAINT-UCLOUD-HK last-modified: 2022-05-16T03:54:14Z source: APNIC route: 152.32.185.0/24 origin: AS135377 descr: UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED FLAT/RM 603 6/F LAWS COMMERCIAL PLAZA 788 CHEUNG SHA WAN ROAD, KL, mnt-by: MAINT-UCLOUD-HK last-modified: 2020-11-26T07:29:44Z source: APNIC route: 152.32.185.0/24 origin: AS62610 descr: UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED FLAT/RM 603 6/F LAWS COMMERCIAL PLAZA 788 CHEUNG SHA WAN ROAD, KL, mnt-by: MAINT-UCLOUD-HK last-modified: 2025-07-27T10:04:43Z source: APNIC
- references
- https://github.com/telekom-security/tpotce, https://malware-filter.gitlab.io/malware-filter/botnet-filter.txt, https://raw.githubusercontent.com/ahamed-rizvan/IOCs/refs/heads/main/Malicous%20IP%20Address.txt
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 1 year ago · Last seen 12 days ago
Appeared in 20 threat reports