IOC Radar
IPMediumSignal 75/100

164.92.154.59

Location
NetherlandsNetherlands
Amsterdam, North Holland
ASN
AS14061
DigitalOcean, LLC
First Seen
Jan 7, 2026
Last Seen
Apr 23, 2026
Jan 7
First Seen
158d ago
Apr 23
Last Seen
52d ago
15
Reports
source reports
75%
Confidence
medium
Found in 15 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
75%
Signal Score
75 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

10 techniques

Network Information

CountryNLNetherlands
RegionAmsterdam, North Holland
ASNAS14061
OrganizationDigitalOcean, LLC

Feed Intelligence Summary

15 reports75% confidence
15
Source reports
75%
Confidence score
Category tags
abuseactive scanactive scanningapacheapache attackeraptattackbad reputationbad web botbotnet activitybrute forcebrute force attackcredential accesscredential stuffingddosddos attackdenial of serviceeuropeexploitation activityhackingidentity & access exploitationindicatormalicious activitymalwarenetherlandsnetworkpassword attacksping of deathportscanreconnaissanceresearchedscannerscannersservice scansshssh attackt1110.001t1110.002t1110.003t1110.004t1190t1203t1499.001t1595.001t1595.002t1595.003threat actortor nodevultrweb application attackweb exploitation

Activity Timeline

1 total obs
Apr 23Apr 23

Threat Activity Heatmap

· Peak: 2026-04-23
Less
More
Mon
Wed
Fri
Jun
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreHigh Risk
75
SIGNAL
Signal Score
75%
Confidence
15
Reports
First seenJan 7, 2026
Last seenApr 23, 2026
GeolocationNL
CountryNetherlands
LocationAmsterdam, North Holland
ASNAS14061
OrgDigitalOcean, LLC
Coords52.3563, 4.9571

VirusTotal

Not checked

WHOIS

description
IPv4 hosts detected port scanning Vultr Tokyo (Japan) honeypot
raw
NetRange: 164.92.64.0 - 164.92.255.255 CIDR: 164.92.128.0/17, 164.92.64.0/18 NetName: DO-13 NetHandle: NET-164-92-64-0-1 Parent: NET164 (NET-164-0-0-0-0) NetType: Direct Allocation OriginAS: Organization: DigitalOcean, LLC (DO-13) RegDate: 2020-05-04 Updated: 2020-05-04 Ref: https://rdap.arin.net/registry/ip/164.92.64.0 OrgName: DigitalOcean, LLC OrgId: DO-13 Address: 105 Edgeview Drive, Suite 425 City: Broomfield StateProv: CO PostalCode: 80021 Country: US RegDate: 2012-05-14 Updated: 2025-04-11 Ref: https://rdap.arin.net/registry/entity/DO-13 OrgNOCHandle: NOC32014-ARIN OrgNOCName: Network Operations Center OrgNOCPhone: +1-646-827-4366 OrgNOCEmail: [email protected] OrgNOCRef: https://rdap.arin.net/registry/entity/NOC32014-ARIN OrgAbuseHandle: DIGIT19-ARIN OrgAbuseName: DigitalOcean Abuse OrgAbusePhone: +1-646-827-4366 OrgAbuseEmail: [email protected] OrgAbuseRef: https://rdap.arin.net/registry/entity/DIGIT19-ARIN OrgTechHandle: NOC32014-ARIN OrgTechName: Network Operations Center OrgTechPhone: +1-646-827-4366 OrgTechEmail: [email protected] OrgTechRef: https://rdap.arin.net/registry/entity/NOC32014-ARIN

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 5 months ago · Last seen 1 month ago
Appeared in 15 threat reports