IPMediumSignal 28/100
185.243.5.17
Location
Newark, CA
ASN
AS23470
Dedires LLC
First Seen
Jan 31, 2025
Last Seen
Apr 5, 2026
Found in 11 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
28%
Signal Score
28 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Network Information
Country
United States
RegionNewark, CA
ASNAS23470
OrganizationDedires LLC
Feed Intelligence Summary
11 reports28% confidence
11
Source reports
28%
Confidence score
Category tags
abuseactive scanactive scanningamerican expressasiaattackaustraliabad reputationbotnetbotnet activitybrute forcebrute force attackbrute force attackscommand and controlcommunication protocolcowriecowrie honeypotcredential accesscredential harvestingcredential stuffingdata exfiltrationdata store exposureddosdecoy systemdionaea honeypotdistributed attacksemailexploitation activityfattfraud voipftpftp brute forcegithubhkhoneytrap honeypothong konghttp scannerhuaweiidentity & access exploitationindicatorinformation technologyinjection activitylamplamp server targetlamp stack targetingmailoney honeypotmalicious activitymalicious sftp activitymalicious sip activitymalicious softwaremalicious ssh activitymalwaremalware behaviourmalware capturenation-state activitynetworknetwork enumerationnetwork intrusion attemptsnetwork scanningnetwork securitynorth americaoceaniap0fpassword attacksphishingphishing attackphishing trappotential credential compromiseprocess injectionprotocol exploitationpythonreconnaissanceremote accessremote servicesresearchedresource hijackingscams & fraudscannersensor-taggedsentrypeer botnetsftpsftp attacksipsip brute forcesip scanningslugsmtpsocial engineeringsshssh attackssh monitoringsurface webt1021t1021.001t1040t1041t1055t1059t1059.004t1071.001t1076t1078t1110t1110.001t1110.002t1110.003t1110.004t1190t1486t1496t1499.001t1499.002t1499.003t1563t1565t1566.001t1566.002t1566.003t1566.004t1595t1595.001t1595.002t1595.003tannertcp scantelecommunicationtelecommunicationstelnet threatthreat actorthreat detectionthreat intelligencetor nodetpotudp scanunauthorized network activityunited statesusvoipvoip attackweb trafficwestpac new zealand
Activity Timeline
Apr 5Apr 5
Threat Activity Heatmap
· Peak: 2026-04-05LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreLow Risk
28
SIGNAL
Signal Score
28%
Confidence
11
Reports
First seenJan 31, 2025
Last seenApr 5, 2026
GeolocationUS
CountryUnited States
LocationNewark, CA
ASNAS23470
OrgDedires LLC
Coords34.0544, -118.2440
VirusTotal
Not checked
WHOIS
- description
- 2025-02-25T00:41:19.949Z Honeypot : Sentrypeer : Source: 185.243.5.17 Port: 5060 Data: INVITE sip:[email protected] SIP/2.0 Via: SIP/2.0/UDP 185.243.5.17:0;branch=z9hG4bK-2116346257;rport From: "FreeSWITCH" <sip:[email protected]>;tag=3633313231613132313363340131383138343937373436 To: "FreeSWITCH" <sip:[email protected]> Call-ID: 870466230525167725025544 CSeq: 1 INVITE Contact: <sip:[email protected]:0> Accept: application/sdp User-agent: PBX Max-forwards: 70 Content-Length: 0
- raw
- inetnum: 185.0.0.0 - 185.255.255.255 netname: IANA-NETBLOCK-185 descr: This network range is not allocated to APNIC. descr: descr: If your whois search has returned this message, then you have descr: searched the APNIC whois database for an address that is descr: allocated by another Regional Internet Registry (RIR). descr: descr: Please search the other RIRs at whois.arin.net or whois.ripe.net descr: for more information about that range. country: AU admin-c: IANA1-AP tech-c: IANA1-AP remarks: For general info on spam complaints email [email protected]. remarks: For general info on hacking & abuse complaints email [email protected]. mnt-by: MAINT-APNIC-AP mnt-lower: MAINT-APNIC-AP status: ALLOCATED PORTABLE last-modified: 2008-09-04T06:51:29Z source: APNIC role: Internet Assigned Numbers Authority address: see http://www.iana.org. admin-c: IANA1-AP tech-c: IANA1-AP nic-hdl: IANA1-AP remarks: For more information on IANA services remarks: go to IANA web site at http://www.iana.org. mnt-by: MAINT-APNIC-AP last-modified: 2018-06-22T22:34:30Z source: APNIC
- references
- https://raw.githubusercontent.com/ahamed-rizvan/IOCs/refs/heads/main/Malicous%20IP%20Address.txt, https://github.com/telekom-security/tpotce
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 1 year ago · Last seen 2 months ago
Appeared in 11 threat reports