IOC Radar
IPMediumSignal 54/100

188.252.191.62

Location
CroatiaCroatia
Zagreb, Zagreb
ASN
AS31012
XNET
First Seen
Nov 2, 2025
Last Seen
Apr 16, 2026
Nov 2
First Seen
223d ago
Apr 16
Last Seen
58d ago
7
Reports
source reports
54%
Confidence
medium
Found in 7 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
54%
Signal Score
54 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

2 techniques

Network Information

CountryHRCroatia
RegionZagreb, Zagreb
ASNAS31012
OrganizationXNET

Feed Intelligence Summary

7 reports54% confidence
7
Source reports
54%
Confidence score
Category tags
abuseactive scanaptbad reputationbitcoinblockchaincommodity contracts intermediationcrypto exchangecrypto miningcrypto walletcryptocurrencycryptocurrency threatscryptojackingdecentralized financedigital currencyfinanceindicatornetworkransomwareresearchedresource hijackingscannert1486t1496threat actortor node

Activity Timeline

1 total obs
Apr 16Apr 16

Threat Activity Heatmap

· Peak: 2026-04-16
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreMedium Risk
54
SIGNAL
Signal Score
54%
Confidence
7
Reports
First seenNov 2, 2025
Last seenApr 16, 2026
GeolocationHR
CountryCroatia
LocationZagreb, Zagreb
ASNAS31012
OrgXNET
Coords45.8144, 15.9780

VirusTotal

Not checked

WHOIS

raw
inetnum: 188.252.128.0 - 188.252.191.255 netname: XNET-CABLE descr: B.net Hrvatska d.o.o. descr: HR-1000 Zagreb descr: INFRA-AW country: HR admin-c: VIP7-RIPE tech-c: VIP7-RIPE status: ASSIGNED PA mnt-by: AS12810-MNT created: 2011-02-10T08:54:28Z last-modified: 2013-07-22T12:49:43Z source: RIPE # Filtered role: A1 Hrvatska contacts address: A1 Hrvatska address: Vrtni put 1 address: 10000 Zagreb address: Croatia (Hrvatska) abuse-mailbox: [email protected] remarks: ************************************ remarks: In case of abuse, remarks: please be advised to contact remarks: [email protected] remarks: ************************************* admin-c: MK8781-RIPE tech-c: VH342-RIPE tech-c: VR727-RIPE tech-c: TM2641-RIPE tech-c: SM6081-RIPE tech-c: MJ3039-RIPE tech-c: MK8781-RIPE nic-hdl: VIP7-RIPE mnt-by: AS12810-MNT created: 2003-08-28T08:01:09Z last-modified: 2025-05-16T09:49:57Z source: RIPE # Filtered route: 188.252.128.0/17 descr: XNET origin: AS31012 mnt-by: AS12810-MNT created: 2011-02-09T15:53:25Z last-modified: 2013-07-22T13:12:14Z source: RIPE

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 7 months ago · Last seen 1 month ago
Appeared in 7 threat reports