IOC Radar
IPMediumSignal 50/100

181.131.216.206

Location
ColombiaColombia
Valledupar, Cesar
ASN
AS13489
EPM Telecomunicaciones S.A. E.S.P
First Seen
Jan 17, 2025
Last Seen
Jun 13, 2026
Jan 17
First Seen
526d ago
Jun 13
Last Seen
14d ago
11
Reports
source reports
50%
Confidence
medium
Found in 11 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
50%
Signal Score
50 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

65 techniques

Network Information

CountryCOColombia
RegionValledupar, Cesar
ASNAS13489
OrganizationEPM Telecomunicaciones S.A. E.S.P

Feed Intelligence Summary

11 reports50% confidence
11
Source reports
50%
Confidence score
Category tags
academic institutionsactive scanactive scanningaerospace & defenseaptasyncratattackautomotive manufacturingbankingbanksbitratblind eagleblind eagle aptbotnetbotnet activitybrute forcebrute_forcec2c2 activitycivil servicesclustercocommand & controlcommand and controlcommand executioncommercial bankingcompromised hostcompromised hostsconsumer goodscredential accesscredential brute forcingcredential harvestingcredential stuffingcredential theftcredential_accesscredit card servicescyber threatsdata encryptiondata exfiltrationdata store exposuredcratddosddos preparationdefensedefense contractingdefense logisticsdefense systemsdefense technologydenial of servicediscorddistributed attackseducationeducational resourceseducational serviceseducational technologyelectronic health recordselectronics manufacturingencryptionenergyenergy distributionexploitexploitationexploitation activityfigurefinancefinance and insurancefinancial institutionfinancial servicesfinancial technologyfleet managementfreight servicesftpftp brute forcefuturegovernment targetinggovernment technologyhealth care and social assistancehealth information technologyhealthcare information systemshigher educationhospital managementidentity & access exploitationindicatorindustrial automationindustrial iotindustrial productioninfrastructure acquisitionreconnaissanceinfrastructure targetinginjection activityinsiktinsikt groupiot securityk-12 educationlateral movementlimeratmalicious activitymalicious domainmalicious linksmalicious powershell activitymalicious softwaremalwaremalware deliverymalware filtermanualmanufacturing technologymaritime transportmedical servicesmilitary operationsnation-state activitynational securitynetworknetwork intrusionnetwork protocolnetwork reconnaissancenetwork scanningnetwork securitynetwork_reconnaissancenjratnuncaoiloil & gaspanamapassenger transportationpatient carepayment processingphishingphishing attackphishing attackspossible infectionpower generationpower systemspowershellprevious insiktprocess injectionprocess manufacturingprotocol exploitationpublic administrationpublic infrastructurepublic policypurecrypterquality controlquasarquasarratrail transportransomwareratratsreconnaissancered akodonregulatory agenciesremcosremcos ratremcos trojanremote accessremote access toolremote access trojanremote servicesrenewable energyresearchedretail tradescanning activityscripting attackssocial engineeringsouth americaspearphishingssh attackstealcsupply chain attacksupply chain managementt1003t1003.001t1005t1012t1018t1021t1021.001t1021.002t1027t1040t1041t1046t1053t1055t1056t1059t1059.001t1059.003t1065t1068t1071t1071.001t1071.002t1076t1077t1078t1082t1086t1090t1102t1105t1110t1110.001t1110.002t1112t1140t1190t1204t1204.001t1204.002t1213t1486t1496t1497t1499.001t1499.002t1499.003t1555t1563t1565t1566t1566.001t1566.002t1566.003t1568t1573t1583t1584t1587.001t1589t1590.001t1595t1595.001t1595.002t1595.003tag-144telnet threatthreat actortor nodetransportation and warehousingtransportation infrastructuretransportation technologywealth managementweb securityxworm

Activity Timeline

1 total obs
Jun 13Jun 13

Threat Activity Heatmap

· Peak: 2026-06-13
Less
More
Mon
Wed
Fri
Jun
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Threat ScoreMedium Risk
50
SIGNAL
Signal Score
50%
Confidence
11
Reports
First seenJan 17, 2025
Last seenJun 13, 2026
GeolocationCO
CountryColombia
LocationValledupar, Cesar
ASNAS13489
OrgEPM Telecomunicaciones S.A. E.S.P
Coords10.4653, -73.2498

VirusTotal

Not checked

WHOIS

description
CC=CO ASN=AS13489 epm telecomunicaciones s.a. e.s.p.
raw
Socket not responding: [Errno 111] Connection refused
references
https://www.recordedfuture.com/research/tag-144s-persistent-grip-on-south-american-organizations, https://malware-filter.gitlab.io/malware-filter/botnet-filter.txt, https://threatfox.abuse.ch/export/csv/recent/

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 14 days ago
Appeared in 11 threat reports