IOC Radar
IPMediumSignal 67/100

192.71.244.244

Location
SloveniaSlovenia
Ljubljana, 061
ASN
AS48894
EDIS GmbH
First Seen
Jan 23, 2025
Last Seen
Apr 23, 2026
Jan 23
First Seen
503d ago
Apr 23
Last Seen
49d ago
7
Reports
source reports
67%
Confidence
medium
Found in 7 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
67%
Signal Score
67 / 100
IDS Rule
No
Threat Context
Tags

Network Information

CountrySISlovenia
RegionLjubljana, 061
ASNAS48894
OrganizationEDIS GmbH

IP Category

VPN
VPN exit node

Feed Intelligence Summary

7 reports67% confidence
7
Source reports
67%
Confidence score
Category tags
active scanbrute forcebrute force attackernetworkportscanproxyresearchedscannersservice scansloveniavpnvultr

Activity Timeline

1 total obs
Apr 23Apr 23

Threat Activity Heatmap

· Peak: 2026-04-23
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreMedium Risk
67
SIGNAL
Signal Score
67%
Confidence
7
Reports
First seenJan 23, 2025
Last seenApr 23, 2026
GeolocationSI
CountrySlovenia
LocationLjubljana, 061
ASNAS48894
OrgEDIS GmbH
Coords46.0517, 14.5133
VPN

VirusTotal

Not checked

WHOIS

description
IPv4 hosts detected port scanning Vultr Tokyo (Japan) honeypot
raw
inetnum: 192.71.244.0 - 192.71.244.255 netname: EDIS-SLO-NET descr: EDIS Infrastructure in Slovenia status: LEGACY remarks: Ljubljana, Slovenia org: ORG-ABUS1224-RIPE country: SI geoloc: 46.0569 14.5058 geofeed: https://www.edis.at/geofeed.txt language: SL admin-c: EDIS-AT tech-c: EDIS-AT mnt-by: RESILANS-MNT mnt-routes: EDIS-MNT created: 2013-02-22T14:21:27Z last-modified: 2023-01-11T16:18:18Z source: RIPE # Filtered organisation: ORG-ABUS1224-RIPE org-name: EDIS GmbH org-type: OTHER address: Hauptplatz 3/3 address: 8010 GRAZ address: Austria abuse-c: ABUS2725-RIPE mnt-ref: RESILANS-MNT mnt-by: RESILANS-MNT created: 2013-03-14T13:51:04Z last-modified: 2016-08-12T11:02:57Z source: RIPE # Filtered role: EDIS GmbH - Noc Engineer address: EDIS GmbH, Hauptplatz 3/3, 8010, GRAZ, Austria address: http://www.edis.at phone: +43 316 827500300 admin-c: EDIS-RIPE admin-c: GK2 admin-c: ISAT tech-c: EDIS-RIPE tech-c: ISAT abuse-mailbox: [email protected] nic-hdl: EDIS-AT mnt-by: EDIS-MNT created: 2011-08-12T07:29:38Z last-modified: 2016-04-08T06:50:42Z source: RIPE # Filtered route: 192.71.244.0/24 origin: AS48894 mnt-by: EDIS-MNT created: 2016-08-25T09:30:14Z last-modified: 2016-08-25T09:30:14Z source: RIPE
references
https://jamesbrine.com.au/vultrtokyo-portscan-bruteforce-ip-list-2026-04-15/, https://jamesbrine.com.au

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 1 month ago
Appeared in 7 threat reports