IOC Radar
IPMediumSignal 43/100

171.225.223.4

Location
VietnamVietnam
Haiphong, 25
ASN
AS7552
VIETEL
First Seen
Dec 29, 2025
Last Seen
May 14, 2026
Dec 29
First Seen
169d ago
May 14
Last Seen
32d ago
5
Reports
source reports
43%
Confidence
medium
Found in 5 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
43%
Signal Score
43 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

21 techniques

Network Information

CountryVNVietnam
RegionHaiphong, 25
ASNAS7552
OrganizationVIETEL

Feed Intelligence Summary

5 reports43% confidence
5
Source reports
43%
Confidence score
Category tags
active scanactive scanningasiabad web botbotnetbotnet activitybrute forcebrute force attackc2command & controlcommand and controlcompromised hostcowriecowrie honeypotcredential accesscredential stuffingddosddos attackdecoy systemdionaeadionaea honeypotdistributed attacksexploitation activityexploited hostfattftp brute forcehackinghoneytrap honeypothttp brute forceidentity & access exploitationindicatorinvalid loginlogin attemptmailoney honeypotmalicious activitymalwaremalware behaviourmalware capturemalware distributionnetworknetwork scanningnetwork securitynetwork traffic analysisopenctip0fpassword attacksphishingphishing attackphishing trapprotocol exploitationreconnaissanceremote accessremote servicesresearchedresource hijackingscannersecurity operationssensor-taggedsentrypeer botnetssh attackssh monitoringt1021t1021.001t1040t1059t1076t1078t1110t1110.001t1110.002t1110.003t1110.004t1190t1496t1499.001t1499.002t1499.003t1563t1573t1595.001t1595.002t1595.003tannertelnet threatthreat actorthreat detectionthreat intelligencetor nodetpotviet namvietnamvnvoip attackvulnerability scan

Activity Timeline

1 total obs
May 14May 14

Threat Activity Heatmap

· Peak: 2026-05-14
Less
More
Mon
Wed
Fri
Jun
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreMedium Risk
43
SIGNAL
Signal Score
43%
Confidence
5
Reports
First seenDec 29, 2025
Last seenMay 14, 2026
GeolocationVN
CountryVietnam
LocationHaiphong, 25
ASNAS7552
OrgVIETEL
Coords16.6168, 106.7293

VirusTotal

Not checked

WHOIS

raw
inetnum: 171.224.0.0 - 171.255.255.255 netname: VIETTEL-VN descr: Viettel Group descr: No 1, Tran Huu Duc street, My Dinh 2 ward, Nam Tu Liem district, Ha Noi City country: VN admin-c: TVT8-AP tech-c: NDT9-AP status: ALLOCATED PORTABLE mnt-irt: IRT-VNNIC-AP mnt-by: MAINT-VN-VNNIC last-modified: 2017-11-11T09:43:21Z source: APNIC irt: IRT-VNNIC-AP address: Ha Noi, VietNam phone: +84-24-35564944 fax-no: +84-24-37821462 e-mail: [email protected] abuse-mailbox: [email protected] admin-c: NTTT1-AP tech-c: NTTT1-AP auth: # Filtered mnt-by: MAINT-VN-VNNIC last-modified: 2025-11-17T23:08:34Z source: APNIC person: Nguyen Dang Tiep address: Viettel Network Corporation address: No 1, Tran Huu Duc street, My Dinh 2 ward, Nam Tu Liem district, Ha Noi City country: VN phone: +84-24-62989898 e-mail: [email protected] nic-hdl: NDT9-AP mnt-by: MAINT-VN-VIETEL last-modified: 2017-11-11T09:40:35Z source: APNIC person: Tran Van Thanh address: Viettel Network Corporation address: No 1, Tran Huu Duc street, My Dinh 2 ward, Nam Tu Liem district, Ha Noi City country: VN phone: +84-24-62989898 e-mail: [email protected] nic-hdl: TVT8-AP mnt-by: MAINT-VN-VIETEL last-modified: 2018-08-21T09:57:13Z source: APNIC route: 171.224.0.0/11 descr: VIETTEL-VN origin: AS24086 mnt-by: MAINT-VN-VNNIC last-modified: 2025-08-14T17:12:04Z source: APNIC route: 171.224.0.0/11 descr: VIETTEL-VN origin: AS38731 mnt-by: MAINT-VN-VNNIC last-modified: 2025-08-14T17:12:09Z source: APNIC route: 171.224.0.0/11 descr: VIETTEL-VN origin: AS7552 mnt-by: MAINT-VN-VNNIC last-modified: 2025-08-14T17:11:59Z source: APNIC
references
https://malware-filter.gitlab.io/malware-filter/botnet-filter.txt

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 5 months ago · Last seen 1 month ago
Appeared in 5 threat reports