IOC Radar
IPHighVerifiedSignal 67/100

154.242.28.134

Location
AlgeriaAlgeria
Biskra, 06
ASN
AS36947
new
First Seen
Apr 17, 2026
Last Seen
Apr 24, 2026
Apr 17
First Seen
58d ago
Apr 24
Last Seen
51d ago
4
Reports
source reports
67%
Confidence
high
Found in 4 reports. Confidence: high. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
67%
Signal Score
67 / 100
IDS Rule
No
Threat Context
Tags

Network Information

CountryDZAlgeria
RegionBiskra, 06
ASNAS36947
Organizationnew

Feed Intelligence Summary

4 reports67% confidence
4
Source reports
67%
Confidence score
Category tags
active scanafricaalgeriabrute forcebrute force attackerindicatornetworkportscanresearchedscannersservice scanvultr

Activity Timeline

1 total obs
Apr 24Apr 24

Threat Activity Heatmap

· Peak: 2026-04-24
Less
More
Mon
Wed
Fri
Jun
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreMedium Risk
67
SIGNAL
Signal Score
67%
Confidence
4
Reports
First seenApr 17, 2026
Last seenApr 24, 2026
Verified IOC
GeolocationDZ
CountryAlgeria
LocationBiskra, 06
ASNAS36947
Orgnew
Coords36.7494, 5.0877

VirusTotal

Not checked

WHOIS

description
IPv4 hosts detected port scanning Vultr Melbourne (Australia) honeypot
raw
inetnum: 154.242.0.0 - 154.242.255.255 netname: LTE-4G-2016-2 descr: Reseau 4G LTE new2 country: DZ admin-c: SD6-AFRINIC tech-c: SD6-AFRINIC status: ASSIGNED PA mnt-by: DJAWEB-MNT source: AFRINIC # Filtered parent: 154.240.0.0 - 154.255.255.255 person: Security Departement address: Alger phone: tel:+213-21-91-12-24 fax-no: tel:+213-21-91-12-08 nic-hdl: SD6-AFRINIC mnt-by: GENERATED-IRIXFFLWUREDGEB9HMRODGUJH3OJCIPE-MNT source: AFRINIC # Filtered route: 154.240.0.0/12 descr: route for new pool origin: AS36947 mnt-by: DJAWEB-MNT source: AFRINIC # Filtered
references
https://jamesbrine.com.au/vultrmelbournetest-portscan-bruteforce-ip-list-2026-04-16/, https://jamesbrine.com.au

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

high
First detected 1 month ago · Last seen 1 month ago
Appeared in 4 threat reports