IOC Radar
IPMediumSignal 36/100

154.26.209.250

Location
United StatesUnited States
Singapore, North West
ASN
AS8796
STARCLOUD GLOBAL PTE. LTD., KURUN CLOUD INC
First Seen
Apr 17, 2026
Last Seen
Apr 24, 2026
Apr 17
First Seen
59d ago
Apr 24
Last Seen
52d ago
3
Reports
source reports
36%
Confidence
medium
2/91
VirusTotal
detections
Found in 3 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
36%
Signal Score
36 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

10 techniques

Network Information

CountryUSUnited States
RegionSingapore, North West
ASNAS8796
OrganizationSTARCLOUD GLOBAL PTE. LTD., KURUN CLOUD INC

Feed Intelligence Summary

3 reports36% confidence
3
Source reports
36%
Confidence score
Category tags
active scanadministratorschaoschlorinedosednp3encryptdecryptfunctionhaifaindicatoriot securityipv4istargetcountrykaijimalwaremodbusnathaniel billnation-state activitynetworknorth americanqvbdkransomwareremote accessresearcheds7commt1021.004t1059.004t1070.004t1090.001t1105t1110.001t1190t1210t1222.002t1496targettor nodeunited stateswritezionsiphon

Activity Timeline

1 total obs
Apr 24Apr 24

Threat Activity Heatmap

· Peak: 2026-04-24
Less
More
Mon
Wed
Fri
Jun
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Intelligence SummaryAI Generated

This Internet Protocol (IP) address has been identified as a critical Indicator of Compromise, signaling a potential severe threat to organizational security. Its presence within network logs or infrastructure strongly suggests compromise or active targeting by malicious entities. Specifically, this IOC is linked to the VoidCrypt ransomware group and the Chaos malware family, known for their aggressive tactics including resource hijacking, data encryption, and system disruption. An unaddressed c…

Threat ScoreLow Risk
36
SIGNAL
Signal Score
36%
Confidence
3
Reports
First seenApr 17, 2026
Last seenApr 24, 2026
GeolocationUS
CountryUnited States
LocationSingapore, North West
ASNAS8796
OrgSTARCLOUD GLOBAL PTE. LTD., KURUN CLOUD INC
Coords37.7510, -97.8220

VirusTotal

2/ 91vendors flagged
2% detection rateJun 3, 2026

WHOIS

description
CC=US ASN=AS8796 kurun cloud inc
raw
Cogent Communications, LLC COGENT-154-26-16 (NET-154-26-0-0-1) 154.26.0.0 - 154.26.255.255 STARCLOUD GLOBAL PTE. LTD. STARCLOUD-GLOBAL-CGNT-NET-11 (NET-154-26-192-0-1) 154.26.192.0 - 154.26.255.255 KURUN CLOUD INC KURUNCLOUD-US (NET-154-26-208-0-1) 154.26.208.0 - 154.26.223.255
references
IOCs.2026.csv, https://www.darktrace.com/blog/darktrace-identifies-new-chaos-malware-variant-exploiting-misconfigurations-in-the-cloud

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 month ago · Last seen 1 month ago
Appeared in 3 threat reports