IPMediumSignal 83/100
160.119.76.41
Location
Amsterdam, North Holland
ASN
AS49870
HostUS Solutions LLC
First Seen
Mar 23, 2026
Last Seen
Jun 14, 2026
Found in 12 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
83%
Signal Score
83 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Network Information
Country
Netherlands
RegionAmsterdam, North Holland
ASNAS49870
OrganizationHostUS Solutions LLC
Feed Intelligence Summary
12 reports83% confidence
12
Source reports
83%
Confidence score
Category tags
abuseaccess controlaccount compromiseaccount securityactive scanactive scanningadminadministrative accessattacker-ipaustraliaauthentication-failurebad reputationbad web botbotnetbotnet activitybrute forcebrute force attackbrute-forcecloud infrastructurecloud infrastructure attackcloud servicescommand and controlcommunication protocolcowriecowrie honeypotcredential accesscredential harvestingcredential stuffingcredential-dumpingdata exfiltrationdata store exposuredatabase securitydatabase-attackdatabase-bruteforceddosddos attackddos attacksdecoy systemdenial of servicedigital oceandionaea honeypotdistributed attackseuropeexploitation activityexploited hostfatthackinghoneytrap honeypotidentity & access exploitationindicatorinjection activityinjection attacksinternet of thingsintrusion detectioniot botnetiot securityiot targetediot/ics attackmailoney honeypotmalicious activitymalicious ipmalicious-ipmalwaremalware behaviourmalware capturemiraimirai botnetnetherlandsnetworknetwork attacksnetwork scanningnetwork securitynloceaniaoperating systemoperating system securityp0fpassword attacksphishingphishing attackphishing trapping of deathportscanprivilege escalationransomwarerdpreconnaissanceremote accessremote servicesresearchresearchedresource hijackingscanscannerscannerssecurity policysensor-taggedsentrypeer botnetservice scansocial engineeringsocradar honeypotsqlsql injectionsshssh attackssh monitoringssh-brutet1021.001t1040t1055t1059.003t1069.001t1071.001t1076t1078t1088t1110t1110.001t1110.002t1110.003t1110.004t1190t1203t1486t1496t1499.001t1499.002t1499.003t1563t1566.001t1566.002t1566.003t1595t1595.001t1595.002t1595.003tannertargeting databasetcptcp protocoltelecommunicationsthreat actorthreat detectionthreat intelligencethreat preventiontor nodetpotturkeyvoidtrapvoipvoip attackvultrweb app attackweb application attackweb exploitationwinwindows
Activity Timeline
Jun 14Jun 14
Threat Activity Heatmap
· Peak: 2026-06-14LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Threat ScoreHigh Risk
83
SIGNAL
Signal Score
83%
Confidence
12
Reports
First seenMar 23, 2026
Last seenJun 14, 2026
GeolocationNL
CountryNetherlands
LocationAmsterdam, North Holland
ASNAS49870
OrgHostUS Solutions LLC
Coords52.3676, 4.9041
VirusTotal
Not checked
WHOIS
- description
- Observed on T-Pot within last 24h; sensors=p0f; threshold?1; private IPs excluded. geo=SC; ports=3389 Location=Sydney, Australia.
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 3 months ago · Last seen 8 days ago
Appeared in 12 threat reports