IOC Radar
IPMediumSignal 93/100

185.82.73.171

Location
NetherlandsNetherlands
Amsterdam, North Holland
ASN
AS214036
Ultahost, Inc
First Seen
Apr 8, 2026
Last Seen
Jun 1, 2026
Apr 8
First Seen
69d ago
Jun 1
Last Seen
15d ago
6
Reports
source reports
93%
Confidence
medium
Found in 6 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
93%
Signal Score
93 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

5 techniques

Network Information

CountryNLNetherlands
RegionAmsterdam, North Holland
ASNAS214036
OrganizationUltahost, Inc

Feed Intelligence Summary

6 reports93% confidence
6
Source reports
93%
Confidence score
Category tags
brute forcecertcisacommandcredential harvestingcredential stuffingeuropeeurope/asiaidentity & access exploitationindicatoriot securityiranianlogix designernetherlandsnetworknlphishingphishing attackplcsresearchedscadasocial engineeringstored datat1219t1565t1566.001t1566.002t1566.003tablethreat actortitle idturkeyuse commonly

Activity Timeline

1 total obs
Jun 1Jun 1

Threat Activity Heatmap

· Peak: 2026-06-01
Less
More
Mon
Wed
Fri
Jun
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Threat ScoreHigh Risk
93
SIGNAL
Signal Score
93%
Confidence
6
Reports
First seenApr 8, 2026
Last seenJun 1, 2026
GeolocationNL
CountryNetherlands
LocationAmsterdam, North Holland
ASNAS214036
OrgUltahost, Inc
Coords52.3676, 4.9041

VirusTotal

Not checked

WHOIS

description
CC=NL ASN=AS15020 bandito networks inc
raw
inetnum: 185.82.73.0 - 185.82.73.255 netname: LSW-CUST-ULTAHOST country: NL org: ORG-UI46-RIPE admin-c: UI48103-RIPE tech-c: UI48103-RIPE abuse-c: UI48103-RIPE status: ASSIGNED PA mnt-by: LAYERSWITCH-MNT created: 2024-09-25T20:36:07Z last-modified: 2024-10-14T14:46:27Z source: RIPE organisation: ORG-UI46-RIPE org-name: Ultahost, Inc. country: US org-type: OTHER address: 651 N Broad St. Suite 206. Middletown/Delaware abuse-c: UI48103-RIPE mnt-ref: NETROUTING-MNT mnt-by: NETROUTING-MNT created: 2024-10-11T16:52:16Z last-modified: 2025-01-14T10:13:57Z source: RIPE # Filtered role: Ultahost, Inc. address: 651 N Broad St. Suite 206. Middletown/Delaware, USA abuse-mailbox: [email protected] nic-hdl: UI48103-RIPE mnt-by: NETROUTING-MNT created: 2024-09-25T20:33:28Z last-modified: 2024-09-25T20:33:50Z source: RIPE # Filtered route: 185.82.73.0/24 origin: as214036 mnt-by: LAYERSWITCH-MNT created: 2024-11-14T16:32:31Z last-modified: 2024-11-14T16:32:31Z source: RIPE route: 185.82.73.0/24 origin: as49127 descr: LSW-CUST-ULTAHOST mnt-by: LAYERSWITCH-MNT created: 2024-09-17T19:30:36Z last-modified: 2024-09-17T19:30:36Z source: RIPE
references
https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 2 months ago · Last seen 15 days ago
Appeared in 6 threat reports