IPMediumSignal 92/100
161.35.220.181
Location
Frankfurt am Main, Hesse
ASN
AS14061
DigitalOcean, LLC
First Seen
Nov 1, 2024
Last Seen
Aug 5, 2025
Found in 10 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
92%
Signal Score
92 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Network Information
Country
United States
RegionFrankfurt am Main, Hesse
ASNAS14061
OrganizationDigitalOcean, LLC
Feed Intelligence Summary
10 reports92% confidence
10
Source reports
92%
Confidence score
Category tags
abuseactive scanningattackbotnetbrute forcebrute force attackbrute force attacksbrute force attemptscisco attackcisco devicecisco device attackcisco exploit attemptcisco exploitation attemptscitrix exploitation attemptscitrix securitycommand and controlcowrie activitycowrie honeypotcowrie interactionscredential accesscredential stuffingctadata exfiltrationdecoy systemdevice managementdionaea activitydionaea honeypotdionaea interactionsdistributed attacksenterprise networkingenterprise securityexploitationftp brute forcehoneytrap honeypotinitial accesslamplamp attacklamp exploitationlamp exploitation attemptslamp stack attackmalicious activitymalicious payloadmalicious softwaremalwaremalware behaviourmalware capturenetworknetwork infrastructurenetwork intrusion attemptsnetwork probingnetwork reconnaissancenetwork scanningnorth americapassword attackpassword attacksprocess injectionproxyreconnaissanceresearchedscannersftp access attemptssftp attackssh attackssh monitoringt1016t1016.001t1021t1021.001t1021.002t1021.004t1041t1046t1047t1055t1059t1059.004t1068t1071.001t1078t1078.001t1110t1110.001t1110.002t1110.003t1110.004t1133t1189t1190t1199t1203t1204.002t1210t1486t1496t1499.001t1499.002t1499.003t1565t1566.001t1588t1595t1595.001t1595.002t1595.003tannerthreat actorthreat detectionthreat intelligenceunauthorized access attemptunauthorized login attemptunited statesweb application attacks
Activity Timeline
Aug 5Aug 5
Threat Activity Heatmap
· Peak: 2025-08-05LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Threat ScoreHigh Risk
92
SIGNAL
Signal Score
92%
Confidence
10
Reports
First seenNov 1, 2024
Last seenAug 5, 2025
GeolocationUS
CountryUnited States
LocationFrankfurt am Main, Hesse
ASNAS14061
OrgDigitalOcean, LLC
Coords50.1169, 8.6837
VirusTotal
Not checked
WHOIS
- description
- 2024-11-24T21:10:00.000Z Honeypot : Honeytrap : Source: 161.35.220.181 : Port: 46009 Message: {'payload': {'data_hex': '', 'md5_hash': 'd41d8cd98f00b204e9800998ecf8427e', 'sha512_hash': 'cf83e1357eefb8bdf1542850d66d8007d620e4050b5715dc83f4a921d36ce9ce47d0d13c5d85f2b0ff8318d2877eec2f63b931bd47417a81a538327af927da3e', 'length': 0}, 'protocol': 'tcp'}
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 1 year ago · Last seen 10 months ago
Appeared in 10 threat reports