IOC Radar
IPMediumSignal 81/100

195.177.94.44

Location
FranceFrance
Marseille, Provence-Alpes-Côte d'Azur
ASN
AS214961
Pitline Ltd
First Seen
Apr 14, 2026
Last Seen
Apr 23, 2026
Apr 14
First Seen
61d ago
Apr 23
Last Seen
52d ago
7
Reports
source reports
81%
Confidence
medium
Found in 7 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
81%
Signal Score
81 / 100
IDS Rule
No
Threat Context
Tags

Network Information

CountryFRFrance
RegionMarseille, Provence-Alpes-Côte d'Azur
ASNAS214961
OrganizationPitline Ltd

Feed Intelligence Summary

7 reports81% confidence
7
Source reports
81%
Confidence score
Category tags
aptc2-infrastructurecertcobalt-strikecommand & controleuropefranceindicatormalwarenetworkosint-volleyransomwareresearchedself-signedthreat actortor nodeukraineunknown-malwarexworm

Activity Timeline

1 total obs
Apr 23Apr 23

Threat Activity Heatmap

· Peak: 2026-04-23
Less
More
Mon
Wed
Fri
Jun
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreHigh Risk
81
SIGNAL
Signal Score
81%
Confidence
7
Reports
First seenApr 14, 2026
Last seenApr 23, 2026
GeolocationFR
CountryFrance
LocationMarseille, Provence-Alpes-Côte d'Azur
ASNAS214961
OrgPitline Ltd
Coords50.4522, 30.5287

VirusTotal

Not checked

WHOIS

raw
inetnum: 195.177.92.0 - 195.177.95.255 netname: GBTCloud country: CH org: ORG-LA684-RIPE admin-c: VD2666-RIPE tech-c: VD2666-RIPE status: ASSIGNED PI mnt-by: RIPE-NCC-END-MNT abuse-c: PTLN-RIPE geofeed: https://pitline.net/geofeed.csv mnt-by: PITLINE-MNT created: 2002-10-22T14:08:36Z last-modified: 2026-03-09T08:33:14Z source: RIPE organisation: ORG-LA684-RIPE org-name: Pitline Ltd country: UA org-type: LIR address: Donets-Zakharzhevskogo, 6/8, 309 address: 61057 address: Kharkiv address: UKRAINE phone: +380675746805 abuse-c: PTLN-RIPE mnt-ref: RIPE-NCC-HM-MNT mnt-ref: PITLINE-MNT mnt-by: RIPE-NCC-HM-MNT mnt-by: PITLINE-MNT created: 2013-12-20T14:28:05Z last-modified: 2020-12-16T13:01:48Z source: RIPE # Filtered person: Vyacheslav Danik address: Ukraine, Kharkiv phone: +380800339850 nic-hdl: VD2666-RIPE mnt-by: PITLINE-MNT created: 2013-12-20T14:58:58Z last-modified: 2024-03-28T10:41:29Z source: RIPE # Filtered route: 195.177.94.0/24 origin: AS214961 mnt-by: PITLINE-MNT created: 2025-01-24T13:20:12Z last-modified: 2025-01-24T13:20:12Z source: RIPE
references
https://malware-filter.gitlab.io/malware-filter/botnet-filter.txt, https://analytics.dugganusa.com/api/v1/stix-feed/v2, https://threatfox.abuse.ch

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 2 months ago · Last seen 1 month ago
Appeared in 7 threat reports