IOC Radar
IPMediumSignal 71/100

193.150.247.219

Location
SwedenSweden
Helsingborg, U
ASN
AS1257
Tele2 KO
First Seen
Mar 25, 2026
Last Seen
Jun 5, 2026
Mar 25
First Seen
73d ago
Jun 5
Last Seen
2d ago
10
Reports
source reports
71%
Confidence
medium
Found in 10 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
71%
Signal Score
71 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

13 techniques

Network Information

CountrySESweden
RegionHelsingborg, U
ASNAS1257
OrganizationTele2 KO

Feed Intelligence Summary

10 reports71% confidence
10
Source reports
71%
Confidence score
Category tags
abuseactive scanactive scanningbad reputationbrute forcebrute force attackbrute force attackerbrute-forcebruteforcecowriecredential accesscredential harvestingcredential stuffingddosdenial of servicedionaeaeuropeexploitexploitation activityexploited hostfatthackingidentity & access exploitationindicatoriot securityiot targetednetworkp0fpassword attacksphishingphishing attackportscanransomwarereconnaissanceresearchedscannerscannerssesensor-taggedservice scansocial engineeringsocradar honeypotspamsshssh attackswedent1110.001t1110.002t1110.003t1110.004t1190t1203t1499.001t1566.001t1566.002t1566.003t1595.001t1595.002t1595.003tannertelnettpotvulnerability scanvulnerability-exploitationvultrweb app attackweb application attackweb exploitationweb spam

Activity Timeline

1 total obs
Jun 5Jun 5

Threat Activity Heatmap

Less
More
Mon
Wed
Fri
Jun
·
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
24h
0
Dormant
7d
1
Minimal
30d
1
Minimal
3mo
1
Minimal
Threat ScoreHigh Risk
71
SIGNAL
Signal Score
71%
Confidence
10
Reports
First seenMar 25, 2026
Last seenJun 5, 2026
GeolocationSE
CountrySweden
LocationHelsingborg, U
ASNAS1257
OrgTele2 KO
Coords59.6146, 16.5528

VirusTotal

Not checked

WHOIS

description
IPv4 hosts detected attempting to brute force TELNET on Vultr Paris (France) honeypot
raw
inetnum: 193.150.240.0 - 193.150.247.255 netname: SE-TELE2-KO-CUSTOMER country: SE admin-c: SWIP-RIPE tech-c: SWIP-RIPE status: ASSIGNED PA mnt-by: COMHEM-MNT created: 2018-09-03T11:09:09Z last-modified: 2021-04-27T05:26:14Z source: RIPE role: Swipnet Staff address: Tele2 AB/Swedish IP Network address: IP Registry address: Torshamnsgatan 17 164 40 Kista SWEDEN fax-no: +46 8 5626 42 10 abuse-mailbox: [email protected] remarks: The database object describes the staff of SWIPNET LIR. admin-c: ROSI3-RIPE admin-c: TH6544-RIPE tech-c: ROSI3-RIPE tech-c: TH6544-RIPE nic-hdl: SWIP-RIPE mnt-by: SWIPNET-LIR-MNT created: 2002-03-21T14:25:04Z last-modified: 2022-11-23T10:36:53Z source: RIPE # Filtered route: 193.150.192.0/18 origin: AS1257 mnt-by: AS1257-MNT created: 2021-07-13T10:14:08Z last-modified: 2021-07-13T10:14:08Z source: RIPE route: 193.150.192.0/18 descr: Com Hem AB origin: AS39651 mnt-by: COMHEM-MNT created: 2006-10-25T11:55:24Z last-modified: 2015-01-27T07:19:31Z source: RIPE
references
https://jamesbrine.com.au/vultrparis-portscan-bruteforce-ip-list-2026-04-16/, https://jamesbrine.com.au, https://jamesbrine.com.au/vultrparis-telnet-bruteforce-ip-list-2026-04-16/

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 2 months ago · Last seen 2 days ago
Appeared in 10 threat reports