IOC Radar
IPMediumSignal 48/100

195.20.18.85

Location
FinlandFinland
Chisinau, Chișinău Municipality
ASN
AS48753
Alexhost SRL
First Seen
Jun 30, 2025
Last Seen
Jul 18, 2025
Jun 30
First Seen
350d ago
Jul 18
Last Seen
331d ago
15
Reports
source reports
48%
Confidence
medium
Found in 15 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
48%
Signal Score
48 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

28 techniques

Network Information

CountryFIFinland
RegionChisinau, Chișinău Municipality
ASNAS48753
OrganizationAlexhost SRL

Feed Intelligence Summary

15 reports48% confidence
15
Source reports
48%
Confidence score
Category tags
abuseaccess controlactive scanningattackauthenticationauthentication attackbotnetbrute forcebrute force attackbrute force attemptcommand and controlcommunication protocolcompromised hostcredential accesscredential stuffingdata exfiltrationdistributed attackseuropeexfiltrationfinlandindicatorioclateral movementlogin attacklogin brute-forcemalicious activitymalicious softwaremalwaremoldova, republic ofnetworknetwork attacksnetwork intrusionnetwork service scanningnetwork traffic analysispassword attackpassword attacksprocess injectionreconnaissanceremote accessresearchedscannersecurity policyssh attackt1021.004t1040t1055t1071t1071.001t1078t1078.004t1105t1110t1110.001t1110.002t1110.003t1110.004t1133t1486t1496t1497t1499.002t1499.003t1565t1573t1588t1588.004t1589t1595t1595.001t1595.002t1595.003tcp protocolthreat actorthreat prevention

Activity Timeline

1 total obs
Jul 18Jul 18

Threat Activity Heatmap

· Peak: 2025-07-18
Less
More
Mon
Wed
Fri
Jun
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Threat ScoreMedium Risk
48
SIGNAL
Signal Score
48%
Confidence
15
Reports
First seenJun 30, 2025
Last seenJul 18, 2025
GeolocationFI
CountryFinland
LocationChisinau, Chișinău Municipality
ASNAS48753
OrgAlexhost SRL
Coords60.1717, 24.9349

VirusTotal

Not checked

WHOIS

description
SSH brute force IOCs collected mainly from hosts located in Finland
raw
inetnum: 195.20.18.0 - 195.20.18.127 org: ORG-AS895-RIPE netname: AlexHost country: MD admin-c: SZ3268-RIPE tech-c: SZ3268-RIPE status: ASSIGNED PA mnt-by: IPSMAIN created: 2023-02-22T10:47:24Z last-modified: 2023-02-22T10:47:24Z source: RIPE mnt-domains: IPSMAIN mnt-domains: CLOUDATAMD-MNT mnt-lower: CLOUDATAMD-MNT mnt-routes: CLOUDATAMD-MNT mnt-routes: IPSMAIN organisation: ORG-AS895-RIPE org-name: ALEXHOST SRL org-type: OTHER address: str. C. Brancusi nr. 3, Chisinau, Moldova abuse-c: AR18916-RIPE mnt-ref: MNT-GLBTX mnt-ref: FREENET-MNT mnt-ref: IPSMAIN mnt-by: IPSMAIN created: 2021-02-08T19:58:24Z last-modified: 2022-03-09T16:27:19Z source: RIPE # Filtered person: AlexHost SRL address: str. Constantin Brancusi nr. 3, Chisinau, Moldova phone: +37379600002 nic-hdl: SZ3268-RIPE mnt-by: CLOUDATAMD-MNT created: 2014-03-21T14:17:01Z last-modified: 2023-03-03T08:12:53Z source: RIPE # Filtered route: 195.20.18.0/24 origin: AS48753 mnt-by: VPLAB-MNT created: 2024-03-01T10:23:09Z last-modified: 2024-03-01T10:23:09Z source: RIPE

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 11 months ago · Last seen 11 months ago
Appeared in 15 threat reports