IOC Radar
IPMediumSignal 11/100

188.241.241.116

Location
RomaniaRomania
Frankfurt am Main, Hesse
ASN
AS57403
HFM S.R.L
First Seen
Mar 29, 2025
Last Seen
Aug 27, 2025
Mar 29
First Seen
449d ago
Aug 27
Last Seen
298d ago
3
Reports
source reports
11%
Confidence
medium
Found in 3 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
11%
Signal Score
11 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

20 techniques

Network Information

CountryRORomania
RegionFrankfurt am Main, Hesse
ASNAS57403
OrganizationHFM S.R.L

Feed Intelligence Summary

3 reports11% confidence
3
Source reports
11%
Confidence score
Category tags
australiaauthentication abusebotnetbrute forcebrute force attackbrute force attemptscommand and controlcredential accesscredential stuffingdata exfiltrationdistributed attackseuropegermanylogin attackmalicious softwaremalwarenetworknetwork accessoceaniapassword attackpassword attacksprocess injectionproxyremote accessresearchedromaniasecurity operationsssh attackt1055t1071.001t1078t1078.002t1078.004t1110t1110.001t1110.002t1110.003t1110.004t1486t1496t1499.002t1499.003t1555t1565t1588t1588.002t1595t1595.001threat intelligence

Activity Timeline

1 total obs
Aug 27Aug 27

Threat Activity Heatmap

· Peak: 2025-08-27
Less
More
Mon
Wed
Fri
Jun
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Threat ScoreLow Risk
11
SIGNAL
Signal Score
11%
Confidence
3
Reports
First seenMar 29, 2025
Last seenAug 27, 2025
GeolocationRO
CountryRomania
LocationFrankfurt am Main, Hesse
ASNAS57403
OrgHFM S.R.L
Coords45.9968, 24.9970

VirusTotal

Not checked

WHOIS

description
Host bruteforcing SSH
references
https://redpiranha.net

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 9 months ago
Appeared in 3 threat reports