IOC Radar
IPMediumSignal 54/100

178.237.39.204

Location
NetherlandsNetherlands
Utrecht, North Holland
ASN
AS8455
Schuberg Philis B.V.
First Seen
Mar 20, 2025
Last Seen
May 10, 2026
Mar 20
First Seen
463d ago
May 10
Last Seen
46d ago
7
Reports
source reports
54%
Confidence
medium
Found in 7 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
54%
Signal Score
54 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

49 techniques

Network Information

CountryNLNetherlands
RegionUtrecht, North Holland
ASNAS8455
OrganizationSchuberg Philis B.V.

Feed Intelligence Summary

7 reports54% confidence
7
Source reports
54%
Confidence score
Category tags
acceptacrongl integactive scanaddress rangeadobe portableallocated paalphenappleasciiasiaattack networkbackbazaarbootkitbotnetcalls processcanadacertcidrciro pellegrinocitizen labcitycivicpluscivil servicescloseclustercnamecommand and controlcommand linecredential harvestingcrisiscus cnrapidsslcus oletdata exfiltrationdefense evasiondistributed attacksdns attackdocument formatdynamicloadere cityec oidencrypt cne8encryptionentityentity icone2europeexecutable fileexploitation activityextra infofederationfirstfrancefull pathgalaxygermanygovernment technologygraphite spywareguest systemhandlehoustonhouston addressiana registraricone2indicatorinfoinformation technologyinteliosiphoneissuerit infrastructureitalyjapanjsonkey algorithmkey identifierkey infoks postalcodelayer protocollinksloadsmalicious softwaremalwaremercenary spywaremetametadata analysismexicomitre attackmobilemobile securitymobile threatmsiemwdbnetherlandsnetworknetwork adminnetwork infonetwork namenextnorth americansonumberodigicert incontarioopenpgp secretoppoverview zenboxparagonparagon solutionsparagon spywareparent pidpathpayloadpdf documentperforms dnsphishingphishing attackpleasepoison carppolandpolicepostpredatorprocess injectionprocesses extraproliferatingpublic administrationpublic infrastructurepublic policyransomwareraxirrcmprdap databaseregulatory agenciesresearchedrijnripeserviceshell folderssigmaslashslovakiasmtpsocial engineeringsocial media securitysoftware developmentspawnsssdeepstatic analysisstatussubject publicsuite esuricata idssystem processt1003t1010t1012t1014t1018t1033t1036t1047t1055t1055 processt1056t1057t1064t1068t1070t1071t1071.001t1078t1082t1083t1095t1104t1105t1112t1125t1190t1203t1485t1486t1496t1497t1499.002t1499.003t1505t1518t1542t1543t1553t1562t1564t1565t1566t1566.001t1566.002t1566.003t1569t1571t1573t1574t1588.004threat actortiertngtofseetoggleturkeytwittertypeunitedurlsv3 serialvalue averdictwhois serverwindowwindows ntwindows sandboxwpaddetectedurlwpaddhcpwpaddnsx509v3 subjectyarazenbox androidzero-click exploit

Activity Timeline

1 total obs
May 10May 10

Threat Activity Heatmap

· Peak: 2026-05-10
Less
More
Mon
Wed
Fri
Jun
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreMedium Risk
54
SIGNAL
Signal Score
54%
Confidence
7
Reports
First seenMar 20, 2025
Last seenMay 10, 2026
GeolocationNL
CountryNetherlands
LocationUtrecht, North Holland
ASNAS8455
OrgSchuberg Philis B.V.
Coords52.3676, 4.9041

VirusTotal

Not checked

WHOIS

description
CC=NL ASN=AS8455 schuberg philis

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 1 month ago
Appeared in 7 threat reports