IOC Radar
IPMediumSignal 48/100

190.250.42.247

Location
ColombiaColombia
Medellín, Antioquia
ASN
AS13489
EPM Telecomunicaciones S.A. E.S.P
First Seen
Apr 8, 2026
Last Seen
Apr 10, 2026
Apr 8
First Seen
67d ago
Apr 10
Last Seen
65d ago
6
Reports
source reports
48%
Confidence
medium
Found in 6 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
48%
Signal Score
48 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

7 techniques

Network Information

CountryCOColombia
RegionMedellín, Antioquia
ASNAS13489
OrganizationEPM Telecomunicaciones S.A. E.S.P

Feed Intelligence Summary

6 reports48% confidence
6
Source reports
48%
Confidence score
Category tags
active scanactive scanningbrute forcebrute force attackcredential accesscredential stuffingexploitation activityidentity & access exploitationimapimap attackindicatornetworkpassword attacksreconnaissanceresearchedscannersmtpsmtp attackersouth americassh attackt1110.001t1110.002t1110.003t1110.004t1595.001t1595.002t1595.003

Activity Timeline

1 total obs
Apr 10Apr 10

Threat Activity Heatmap

· Peak: 2026-04-10
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreMedium Risk
48
SIGNAL
Signal Score
48%
Confidence
6
Reports
First seenApr 8, 2026
Last seenApr 10, 2026
GeolocationCO
CountryColombia
LocationMedellín, Antioquia
ASNAS13489
OrgEPM Telecomunicaciones S.A. E.S.P
Coords6.1551, -75.3737

VirusTotal

Not checked

WHOIS

raw
inetnum: 190.250.0.0/15 status: allocated aut-num: AS13489 owner: UNE EPM TELECOMUNICACIONES S.A. ownerid: CO-EPME1-LACNIC responsible: Administrador EPMNET address: Carrera 48 número 20 - 45, ., Rivana Business Park address: 050022 - Medellin - CO country: CO phone: +57 43251505 [0000] owner-c: JDM29 tech-c: YGO2 abuse-c: ABI13 inetrev: 190.250.0.0/15 nserver: LAUTA.UNE.NET.CO nsstat: 20260405 AA nslastaa: 20260405 nserver: BIRLOCHA.UNE.NET.CO nsstat: 20260405 AA nslastaa: 20260405 nserver: NSBOG01.UNE.NET.CO nsstat: 20260405 AA nslastaa: 20260405 created: 20100614 changed: 20240611 nic-hdl: JDM29 person: ADM INTERNET e-mail: [email protected] address: Carrera 16, 11, INTERIOR 108 address: 050022 - MEDELLIN - ANTIOQUIA country: CO phone: +57 3017890000 [0000] created: 20190530 changed: 20250710 nic-hdl: YGO2 person: AdmInternet Tigo Col e-mail: [email protected] address: Cra. 16 Nro. 11A Sur 100, 100, -- address: NA - Medellin - An country: CO phone: +57 45150505 [0] created: 20030120 changed: 20250531 nic-hdl: ABI13 person: Abuso Internet e-mail: [email protected] address: Rivana, 100, address: 00 - MEDELLIN - ANTIOQUIA country: CO phone: +57 3001231234 created: 20240611 changed: 20240611

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 2 months ago · Last seen 2 months ago
Appeared in 6 threat reports