IOC Radar
IPMediumSignal 92/100

161.35.220.181

Location
United StatesUnited States
Frankfurt am Main, Hesse
ASN
AS14061
DigitalOcean, LLC
First Seen
Nov 1, 2024
Last Seen
Aug 5, 2025
Nov 1
First Seen
599d ago
Aug 5
Last Seen
322d ago
10
Reports
source reports
92%
Confidence
medium
Found in 10 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
92%
Signal Score
92 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

40 techniques

Network Information

CountryUSUnited States
RegionFrankfurt am Main, Hesse
ASNAS14061
OrganizationDigitalOcean, LLC

Feed Intelligence Summary

10 reports92% confidence
10
Source reports
92%
Confidence score
Category tags
abuseactive scanningattackbotnetbrute forcebrute force attackbrute force attacksbrute force attemptscisco attackcisco devicecisco device attackcisco exploit attemptcisco exploitation attemptscitrix exploitation attemptscitrix securitycommand and controlcowrie activitycowrie honeypotcowrie interactionscredential accesscredential stuffingctadata exfiltrationdecoy systemdevice managementdionaea activitydionaea honeypotdionaea interactionsdistributed attacksenterprise networkingenterprise securityexploitationftp brute forcehoneytrap honeypotinitial accesslamplamp attacklamp exploitationlamp exploitation attemptslamp stack attackmalicious activitymalicious payloadmalicious softwaremalwaremalware behaviourmalware capturenetworknetwork infrastructurenetwork intrusion attemptsnetwork probingnetwork reconnaissancenetwork scanningnorth americapassword attackpassword attacksprocess injectionproxyreconnaissanceresearchedscannersftp access attemptssftp attackssh attackssh monitoringt1016t1016.001t1021t1021.001t1021.002t1021.004t1041t1046t1047t1055t1059t1059.004t1068t1071.001t1078t1078.001t1110t1110.001t1110.002t1110.003t1110.004t1133t1189t1190t1199t1203t1204.002t1210t1486t1496t1499.001t1499.002t1499.003t1565t1566.001t1588t1595t1595.001t1595.002t1595.003tannerthreat actorthreat detectionthreat intelligenceunauthorized access attemptunauthorized login attemptunited statesweb application attacks

Activity Timeline

1 total obs
Aug 5Aug 5

Threat Activity Heatmap

· Peak: 2025-08-05
Less
More
Mon
Wed
Fri
Jun
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Threat ScoreHigh Risk
92
SIGNAL
Signal Score
92%
Confidence
10
Reports
First seenNov 1, 2024
Last seenAug 5, 2025
GeolocationUS
CountryUnited States
LocationFrankfurt am Main, Hesse
ASNAS14061
OrgDigitalOcean, LLC
Coords50.1169, 8.6837

VirusTotal

Not checked

WHOIS

description
2024-11-24T21:10:00.000Z Honeypot : Honeytrap : Source: 161.35.220.181 : Port: 46009 Message: {'payload': {'data_hex': '', 'md5_hash': 'd41d8cd98f00b204e9800998ecf8427e', 'sha512_hash': 'cf83e1357eefb8bdf1542850d66d8007d620e4050b5715dc83f4a921d36ce9ce47d0d13c5d85f2b0ff8318d2877eec2f63b931bd47417a81a538327af927da3e', 'length': 0}, 'protocol': 'tcp'}

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 10 months ago
Appeared in 10 threat reports