IOC Radar
IPMediumSignal 50/100

164.92.245.26

Location
GermanyGermany
Frankfurt am Main, Hessen
ASN
AS14061
DigitalOcean, LLC
First Seen
Feb 16, 2025
Last Seen
May 12, 2026
Feb 16
First Seen
494d ago
May 12
Last Seen
44d ago
15
Reports
source reports
50%
Confidence
medium
Found in 15 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
50%
Signal Score
50 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

24 techniques

Network Information

CountryDEGermany
RegionFrankfurt am Main, Hessen
ASNAS14061
OrganizationDigitalOcean, LLC

Feed Intelligence Summary

15 reports50% confidence
15
Source reports
50%
Confidence score
Category tags
abuseactive scanactive scanningaptattackbad reputationbotnetbotnet activitybrute forcebrute force attackbrute-forcecommand and controlcowrie honeypotcowrie honeypot datacredential accesscredential harvestingcredential stuffingctadata exfiltrationdata store exposurededecoy systemdistributed attackseuropeexploitation activitygermanyhoneytrap honeypotidentity & access exploitationinjection activitylampmailoney honeypotmalicious activitymalicious softwaremalwarenetworknetwork probingnetwork scanningnetwork service scanningnorth americapassword attacksphishingphishing attackphishing trapprobingprocess injectionproxyransomwarereconnaissanceresearchedscannerservice scansftp attacksftp exploit attemptsocial engineeringsocradar honeypotssh attackssh monitoringt1021t1021.004t1041t1055t1071.001t1110t1110.001t1110.002t1110.003t1110.004t1190t1486t1496t1499.002t1499.003t1565t1566.001t1566.002t1566.003t1566.004t1595t1595.001t1595.002t1595.003telecommunicationsthreat actorthreat detectiontor nodeunauthorized access attemptunited statesweb scannerwebscanwebscanner

Activity Timeline

1 total obs
May 12May 12

Threat Activity Heatmap

· Peak: 2026-05-12
Less
More
Mon
Wed
Fri
Jun
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreMedium Risk
50
SIGNAL
Signal Score
50%
Confidence
15
Reports
First seenFeb 16, 2025
Last seenMay 12, 2026
GeolocationDE
CountryGermany
LocationFrankfurt am Main, Hessen
ASNAS14061
OrgDigitalOcean, LLC
Coords37.7510, -97.8220

VirusTotal

Not checked

WHOIS

description
2025-02-19T19:06:59.887Z Honeypot : Cowrie : Source: 164.92.245.26 Data: login attempt [GET /query?q=SHOW+DIAGNOSTICS HTTP/1.1/Host: 99.18.26.18:23] failed
raw
inetnum: 164.82.0.0 - 164.93.127.255 netname: NON-RIPE-NCC-MANAGED-ADDRESS-BLOCK descr: IPv4 address block not managed by the RIPE NCC remarks: ------------------------------------------------------ remarks: remarks: For registration information, remarks: you can consult the following sources: remarks: remarks: IANA remarks: http://www.iana.org/assignments/ipv4-address-space remarks: http://www.iana.org/assignments/iana-ipv4-special-registry remarks: http://www.iana.org/assignments/ipv4-recovered-address-space remarks: remarks: AFRINIC (Africa) remarks: http://www.afrinic.net/ whois.afrinic.net remarks: remarks: APNIC (Asia Pacific) remarks: http://www.apnic.net/ whois.apnic.net remarks: remarks: ARIN (Northern America) remarks: http://www.arin.net/ whois.arin.net remarks: remarks: LACNIC (Latin America and the Carribean) remarks: http://www.lacnic.net/ whois.lacnic.net remarks: remarks: ------------------------------------------------------ country: EU # Country is really world wide admin-c: IANA1-RIPE tech-c: IANA1-RIPE status: ALLOCATED UNSPECIFIED mnt-by: RIPE-NCC-HM-MNT created: 2019-01-07T10:49:17Z last-modified: 2019-01-07T10:49:17Z source: RIPE role: Internet Assigned Numbers Authority address: see http://www.iana.org. admin-c: IANA1-RIPE tech-c: IANA1-RIPE nic-hdl: IANA1-RIPE remarks: For more information on IANA services remarks: go to IANA web site at http://www.iana.org. mnt-by: RIPE-NCC-MNT created: 1970-01-01T00:00:00Z last-modified: 2001-09-22T09:31:27Z source: RIPE # Filtered
references
https://github.com/telekom-security/tpotce

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 1 month ago
Appeared in 15 threat reports