IPMediumSignal 0/100
184.105.247.244
Location
Pleasanton, MT
ASN
AS6939
The Shadow Server Foundation
First Seen
Aug 26, 2020
Last Seen
Jun 19, 2026
Found in 1 report. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
0%
Signal Score
0 / 100
IDS Rule
No
Threat Context
Tags
Network Information
Country
United States
RegionPleasanton, MT
ASNAS6939
OrganizationThe Shadow Server Foundation
Feed Intelligence Summary
1 report0% confidence
1
Source reports
0%
Confidence score
Category tags
indicatornetworkresearched
Activity Timeline
Jun 19Jun 19
Threat Activity Heatmap
· Peak: 2026-06-19LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Intelligence SummaryAI Generated
This indicator, an IPv4 address, is currently identified as whitelisted with a negligible threat score of 0.0. Its inclusion in threat intelligence feeds, specifically SANS Wide Scanners, primarily suggests its role in widespread network scanning activities rather than targeted malicious operations. At present, there is no corroborating evidence to indicate hostile behavior associated with this IP address within the organization's environment. Consequently, this IOC should be regarded as low-ris…
Threat ScoreLow Risk
0
SIGNAL
Signal Score
0%
Confidence
1
Reports
First seenAug 26, 2020
Last seenJun 19, 2026
GeolocationUS
CountryUnited States
LocationPleasanton, MT
ASNAS6939
OrgThe Shadow Server Foundation
Coords46.2433, -114.1678
VirusTotal
Not checked
WHOIS
- description
- IPv4 hosts detected port scanning Vultr Melbourne (Australia) honeypot
- raw
- Hurricane Electric LLC HURRICANE-11 (NET-184-104-0-0-1) 184.104.0.0 - 184.105.255.255 The Shadowserver Foundation, Inc. HURRICANE-CE2897-2AAEDEA4 (NET-184-105-247-192-1) 184.105.247.192 - 184.105.247.255
- references
- https://github.com/telekom-security/tpotce, https://feeds.dshield.org/feeds/topips.txt, https://feeds.dshield.org/feeds/top10.txt, https://feeds.dshield.org/feeds/block.txt, https://list.rtbh.com.tr/output.txt, https://raw.githubusercontent.com/ahamed-rizvan/IOCs/refs/heads/main/Malicous%20IP%20Address.txt, C_C March-2025-04-03 13_46_36.669.csv
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 5 years ago · Last seen 8 days ago
Appeared in 1 threat report