IOC Radar
IPMediumSignal 39/100

194.180.48.127

Location
GermanyGermany
Berngau, VA
ASN
AS201814
HostSlick
First Seen
Dec 5, 2022
Last Seen
May 3, 2026
Dec 5
First Seen
1291d ago
May 3
Last Seen
47d ago
9
Reports
source reports
39%
Confidence
medium
Found in 9 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
39%
Signal Score
39 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

10 techniques

Network Information

CountryDEGermany
RegionBerngau, VA
ASNAS201814
OrganizationHostSlick

Feed Intelligence Summary

9 reports39% confidence
9
Source reports
39%
Confidence score
Category tags
abuseaccess controlactive scanactive scanningasiabad reputationbankingbrute forcebrute force attackchinacredential accesscredential stuffingcredit card servicesddosdedenial of serviceeuropeexploitation activityfinancefinancial servicesfinancial technologygermanyhackingidentity & access exploitationindiaindicatorindonesiairankoreanetherlandsnetworknetwork probingnorth americapassword attackspayment processingpolandreconnaissanceresearchedscannerscanning activitysecurity policyt1110.001t1110.002t1110.003t1110.004t1190t1203t1499.001t1595.001t1595.002t1595.003thailandthreat preventionunitedunited stateswealth managementweb application attackweb exploitationweb scanner

Activity Timeline

1 total obs
May 3May 3

Threat Activity Heatmap

· Peak: 2026-05-03
Less
More
Mon
Wed
Fri
Jun
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreLow Risk
39
SIGNAL
Signal Score
39%
Confidence
9
Reports
First seenDec 5, 2022
Last seenMay 3, 2026
GeolocationDE
CountryGermany
LocationBerngau, VA
ASNAS201814
OrgHostSlick
Coords39.0814, -77.6443

VirusTotal

Not checked

WHOIS

raw
inetnum: 194.180.48.0 - 194.180.48.255 netname: Dedicated_Servers_IP_Range descr: Dedicated Servers IP Range org: ORG-RA1050-RIPE country: DE admin-c: LW2980-RIPE tech-c: LW2980-RIPE mnt-routes: mnt-de-maximilian-1 mnt-routes: MNT-NETERRA mnt-domains: mnt-de-maximilian-1 status: ASSIGNED PA mnt-by: MNT-NETERRA created: 2023-12-05T06:11:52Z last-modified: 2024-12-17T06:25:34Z source: RIPE organisation: ORG-RA1050-RIPE org-name: RAZI Network org-type: OTHER address: Hauptstrasse 31 92361 Berngau, DE admin-c: LW2980-RIPE tech-c: LW2980-RIPE abuse-c: ACRO59441-RIPE mnt-ref: AZERONLINE-MNT mnt-ref: voldeta-mnt mnt-ref: mnt-de-maximilian-1 mnt-ref: MNT-NETERRA mnt-by: mnt-de-maximilian-1 created: 2022-07-26T19:20:40Z last-modified: 2025-05-14T10:59:47Z source: RIPE # Filtered person: Razi Network address: 5605 SW Orleans St Seattle WA 98116 phone: +4917661200655 org: ORG-RA1050-RIPE nic-hdl: LW2980-RIPE mnt-by: mnt-de-maximilian-1 created: 2022-07-26T19:16:27Z last-modified: 2025-05-13T15:24:37Z source: RIPE # Filtered route: 194.180.48.0/24 origin: AS201814 mnt-by: MNT-NETERRA created: 2024-12-17T06:25:46Z last-modified: 2024-12-17T06:25:46Z source: RIPE
references
https://www.linkedin.com/posts/starlightintel_cybersecurity-cyberattack-rce-activity-7006655704950341632-Is8L?utm_source=share&utm_medium=member_desktop

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 3 years ago · Last seen 1 month ago
Appeared in 9 threat reports