IOC Radar
IPMediumSignal 69/100

192.210.186.199

Location
United StatesUnited States
Buffalo, New York
ASN
AS36352
HostPapa
First Seen
Sep 23, 2021
Last Seen
Jun 7, 2026
Sep 23
First Seen
1737d ago
Jun 7
Last Seen
19d ago
10
Reports
source reports
69%
Confidence
medium
Found in 10 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
69%
Signal Score
69 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

6 techniques

Network Information

CountryUSUnited States
RegionBuffalo, New York
ASNAS36352
OrganizationHostPapa

Feed Intelligence Summary

10 reports69% confidence
10
Source reports
69%
Confidence score
Category tags
abusech-urlhaus-c2cactive scanactive scanningarmasciibad reputationbad web botbotnet activityc2command & controlddosdenial of servicedropped-by-amadeyelfencodedexeexecutable fileexploitation activitygafgytguloaderindicatorinfostealerjsm68kmalwaremipsmiraimozimsinetworknorth americaopendirphantomgatephantomstealerphishingpowerpcpowershellps1pureratransomwareratreconnaissanceremcosratremusstealerresearchedrev-base64-loaderrustystealerscams & fraudscannerscriptself-signedshsparcstealcsuperht1190t1203t1499.001t1595.001t1595.002t1595.003ua-wgetunited statesusvbsvipkeyloggerweb application attackweb exploitationx86zip

Activity Timeline

1 total obs
Jun 7Jun 7

Threat Activity Heatmap

· Peak: 2026-06-07
Less
More
Mon
Wed
Fri
Jun
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Threat ScoreMedium Risk
69
SIGNAL
Signal Score
69%
Confidence
10
Reports
First seenSep 23, 2021
Last seenJun 7, 2026
GeolocationUS
CountryUnited States
LocationBuffalo, New York
ASNAS36352
OrgHostPapa
Coords42.8864, -78.8784

VirusTotal

Not checked

WHOIS

raw
NetRange: 192.210.128.0 - 192.210.255.255 CIDR: 192.210.128.0/17 NetName: CC-11 NetHandle: NET-192-210-128-0-1 Parent: NET192 (NET-192-0-0-0-0) NetType: Direct Allocation OriginAS: Organization: HostPapa (HOSTP-7) RegDate: 2012-12-11 Updated: 2024-02-02 Comment: Geofeed https://geofeeds.oniaas.io/geofeeds.csv Ref: https://rdap.arin.net/registry/ip/192.210.128.0 OrgName: HostPapa OrgId: HOSTP-7 Address: 325 Delaware Avenue Address: Suite 300 City: Buffalo StateProv: NY PostalCode: 14202 Country: US RegDate: 2016-06-06 Updated: 2025-10-05 Ref: https://rdap.arin.net/registry/entity/HOSTP-7 OrgAbuseHandle: NETAB23-ARIN OrgAbuseName: NETABUSE OrgAbusePhone: +1-905-315-3455 OrgAbuseEmail: [email protected] OrgAbuseRef: https://rdap.arin.net/registry/entity/NETAB23-ARIN OrgTechHandle: NETTE9-ARIN OrgTechName: NETTECH OrgTechPhone: +1-905-315-3455 OrgTechEmail: [email protected] OrgTechRef: https://rdap.arin.net/registry/entity/NETTE9-ARIN RAbuseHandle: NETAB27-ARIN RAbuseName: NETABUSE-COLOCROSSING RAbusePhone: +1-800-518-9716 RAbuseEmail: [email protected] RAbuseRef: https://rdap.arin.net/registry/entity/NETAB27-ARIN RTechHandle: NETTE11-ARIN RTechName: NETTECH-COLOCROSSING RTechPhone: +1-800-518-9716 RTechEmail: [email protected] RTechRef: https://rdap.arin.net/registry/entity/NETTE11-ARIN

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 4 years ago · Last seen 19 days ago
Appeared in 10 threat reports