IOC Radar
IPMediumSignal 30/100

178.242.81.39

Location
TurkeyTurkey
Istanbul, 06
ASN
AS16135
Turkcell Internet
First Seen
May 30, 2025
Last Seen
Mar 28, 2026
May 30
First Seen
376d ago
Mar 28
Last Seen
74d ago
6
Reports
source reports
30%
Confidence
medium
Found in 6 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
30%
Signal Score
30 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

29 techniques

Network Information

CountryTRTurkey
RegionIstanbul, 06
ASNAS16135
OrganizationTurkcell Internet

Feed Intelligence Summary

6 reports30% confidence
6
Source reports
30%
Confidence score
Category tags
abuseactive scanactive scanningbad reputationbotnetbotnet activitybrute forcebrute force attackcommand and controlcredential accesscredential stuffingdata exfiltrationdata store exposureddosdenial of servicedistributed attackseurope/asiaexploit attemptsexploitation activityftp brute forcehttp brute forceidentity & access exploitationindicatorinjection activitylateral movementmalicious softwaremalwaremalware propagationmalware scanningnetworknetwork probingnetwork scanningpassword attacksprocess injectionreconnaissanceremote accessremote servicesresearchedsmtp brute forcesql injection attemptsssh attackt1021t1021.001t1046t1055t1059t1071.001t1076t1078t1110t1110.001t1110.002t1110.003t1110.004t1133t1187t1190t1199t1210t1486t1496t1499.002t1499.003t1563t1565t1588t1595t1595.001t1595.002t1595.003targeting databaseturkey

Activity Timeline

1 total obs
Mar 28Mar 28

Threat Activity Heatmap

· Peak: 2026-03-28
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreLow Risk
30
SIGNAL
Signal Score
30%
Confidence
6
Reports
First seenMay 30, 2025
Last seenMar 28, 2026
GeolocationTR
CountryTurkey
LocationIstanbul, 06
ASNAS16135
OrgTurkcell Internet
Coords39.9205, 32.8372

VirusTotal

Not checked

WHOIS

raw
NetRange: 178.0.0.0 - 178.255.255.255 CIDR: 178.0.0.0/8 NetName: 178-RIPE NetHandle: NET-178-0-0-0-1 Parent: () NetType: Allocated to RIPE NCC OriginAS: Organization: RIPE Network Coordination Centre (RIPE) RegDate: 2009-01-30 Updated: 2009-05-18 Comment: These addresses have been further assigned to users in Comment: the RIPE NCC region. Contact information can be found in Comment: the RIPE database at http://www.ripe.net/whois Ref: https://rdap.arin.net/registry/ip/178.0.0.0 ResourceLink: https://apps.db.ripe.net/search/query.html ResourceLink: whois.ripe.net OrgName: RIPE Network Coordination Centre OrgId: RIPE Address: P.O. Box 10096 City: Amsterdam StateProv: PostalCode: 1001EB Country: NL RegDate: Updated: 2013-07-29 Ref: https://rdap.arin.net/registry/entity/RIPE ReferralServer: whois://whois.ripe.net ResourceLink: https://apps.db.ripe.net/search/query.html OrgAbuseHandle: ABUSE3850-ARIN OrgAbuseName: Abuse Contact OrgAbusePhone: +31205354444 OrgAbuseEmail: [email protected] OrgAbuseRef: https://rdap.arin.net/registry/entity/ABUSE3850-ARIN OrgTechHandle: RNO29-ARIN OrgTechName: RIPE NCC Operations OrgTechPhone: +31 20 535 4444 OrgTechEmail: [email protected] OrgTechRef: https://rdap.arin.net/registry/entity/RNO29-ARIN inetnum: 178.240.0.0 - 178.243.255.255 netname: TR-TURKCELL-INTERNET descr: TURKCELL INTERNET country: TR admin-c: TIM96-RIPE tech-c: TIM96-RIPE status: ASSIGNED PA mnt-by: TR-TURKCELL created: 2012-04-30T05:53:37Z last-modified: 2012-04-30T05:53:37Z source: RIPE person: Turkcell IP Manager address: Turkcell Kartal Plaza address: Topselvi Mahallesi Dipcik Sokak No:31 address: Kartal ISTANBUL phone: +90 216 458 10 00 fax-no: +90 216 427 50 60 nic-hdl: TIM96-RIPE mnt-by: tr-turkcell created: 2006-04-17T07:04:48Z last-modified: 2011-07-17T21:19:30Z source: RIPE # Filtered route: 178.242.64.0/18 descr: Diyarbakir internet origin: AS16135 mnt-by: tr-turkcell created: 2013-05-22T10:39:48Z last-modified: 2013-05-22T10:39:48Z source: RIPE

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 2 months ago
Appeared in 6 threat reports