IOC Radar
IPHighVerifiedSignal 86/100

176.65.139.126

Location
NetherlandsNetherlands
Eygelshoven, England
ASN
AS214472
Storm Industries
First Seen
Jan 30, 2026
Last Seen
Jun 9, 2026
Jan 30
First Seen
132d ago
Jun 9
Last Seen
3d ago
44
Reports
source reports
95%
Confidence
high
Found in 44 reports. Confidence: high. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
95%
Signal Score
86 / 100
IDS Rule
Yes
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

1 techniques

Network Information

CountryNLNetherlands
RegionEygelshoven, England
ASNAS214472
OrganizationStorm Industries

Feed Intelligence Summary

44 reports95% confidence
AT
Abuse.ch ThreatFox
3d ago
3793 IOCs in report
AT
Abuse.ch ThreatFox
3d ago
3771 IOCs in report
AT
Abuse.ch ThreatFox
3d ago
3697 IOCs in report
AT
Abuse.ch ThreatFox
3d ago
3695 IOCs in report
AT
Abuse.ch ThreatFox
3d ago
3693 IOCs in report
AT
Abuse.ch ThreatFox
3d ago
3686 IOCs in report
AT
Abuse.ch ThreatFox
3d ago
3688 IOCs in report
AT
Abuse.ch ThreatFox
3d ago
3687 IOCs in report
AT
Abuse.ch ThreatFox
3d ago
3682 IOCs in report
AT
Abuse.ch ThreatFox
3d ago
3679 IOCs in report

Activity Timeline

37 total obs
Jun 9Jun 8

Threat Activity Heatmap

Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
37
Critical
30d
37
Critical
3mo
37
Critical
Threat ScoreHigh Risk
86
SIGNAL
Signal Score
95%
Confidence
44
Reports
First seenJan 30, 2026
Last seenJun 9, 2026
Verified IOC
GeolocationNL
CountryNetherlands
LocationEygelshoven, England
ASNAS214472
OrgStorm Industries
Coords49.9148, -6.3111

VirusTotal

Not checked

WHOIS

description
Scans hitting the server at TCP port 8080 HTTP and PROXY. The same IP address may appear more than once a day. S3#
raw
inetnum: 176.65.139.0 - 176.65.139.255 netname: PFCLOUD-NET org: ORG-SI335-RIPE country: NL admin-c: SNO38-RIPE tech-c: SNO38-RIPE status: ASSIGNED PA created: 2026-01-28T13:14:37Z last-modified: 2026-02-23T13:52:04Z source: RIPE mnt-by: MNT-ZEXOTEK organisation: ORG-SI335-RIPE org-name: Storm Industries org-type: OTHER address: United Kingdom, Aberdare mnt-ref: MNT-ZEXOTEK abuse-c: ACRO63650-RIPE mnt-ref: STORMINDUSTRIES-MNT created: 2026-02-21T21:08:51Z last-modified: 2026-02-22T13:44:07Z source: RIPE # Filtered mnt-by: STORMINDUSTRIES-MNT role: StormCloud Network Operations address: United Kingdoms, Aberdare abuse-mailbox: [email protected] nic-hdl: SNO38-RIPE mnt-by: STORMCLOUD-MNT created: 2026-02-21T21:02:21Z last-modified: 2026-02-22T01:23:53Z source: RIPE # Filtered route: 176.65.139.0/24 origin: AS214472 created: 2026-03-18T17:56:01Z last-modified: 2026-03-18T17:56:01Z source: RIPE mnt-by: MNT-ZEXOTEK route: 176.65.139.0/24 origin: AS51396 created: 2026-01-28T13:15:05Z last-modified: 2026-01-28T13:15:05Z source: RIPE mnt-by: MNT-ZEXOTEK

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

high
First detected 4 months ago · Last seen 3 days ago
Appeared in 44 threat reports from 10 sources
Associated with: Kimsuky, Hive, Play, Turla
Used by malware: Dridex, NetWire, Nanocore, Stealc, Rhadamanthys, Lumma, Mirai, Vidar, NjRAT, Pegasus, SocGholish, XMRig, Remcos, Rhysida, Bumblebee, META Stealer, Hive, Play, Havoc, Sliver, Cobalt Strike, XWorm, AsyncRAT