IPMediumSignal 48/100
195.20.18.85
Location
Chisinau, Chișinău Municipality
ASN
AS48753
Alexhost SRL
First Seen
Jun 30, 2025
Last Seen
Jul 18, 2025
Found in 15 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
48%
Signal Score
48 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Network Information
Country
Finland
RegionChisinau, Chișinău Municipality
ASNAS48753
OrganizationAlexhost SRL
Feed Intelligence Summary
15 reports48% confidence
15
Source reports
48%
Confidence score
Category tags
abuseaccess controlactive scanningattackauthenticationauthentication attackbotnetbrute forcebrute force attackbrute force attemptcommand and controlcommunication protocolcompromised hostcredential accesscredential stuffingdata exfiltrationdistributed attackseuropeexfiltrationfinlandindicatorioclateral movementlogin attacklogin brute-forcemalicious activitymalicious softwaremalwaremoldova, republic ofnetworknetwork attacksnetwork intrusionnetwork service scanningnetwork traffic analysispassword attackpassword attacksprocess injectionreconnaissanceremote accessresearchedscannersecurity policyssh attackt1021.004t1040t1055t1071t1071.001t1078t1078.004t1105t1110t1110.001t1110.002t1110.003t1110.004t1133t1486t1496t1497t1499.002t1499.003t1565t1573t1588t1588.004t1589t1595t1595.001t1595.002t1595.003tcp protocolthreat actorthreat prevention
Activity Timeline
Jul 18Jul 18
Threat Activity Heatmap
· Peak: 2025-07-18LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Threat ScoreMedium Risk
48
SIGNAL
Signal Score
48%
Confidence
15
Reports
First seenJun 30, 2025
Last seenJul 18, 2025
GeolocationFI
CountryFinland
LocationChisinau, Chișinău Municipality
ASNAS48753
OrgAlexhost SRL
Coords60.1717, 24.9349
VirusTotal
Not checked
WHOIS
- description
- SSH brute force IOCs collected mainly from hosts located in Finland
- raw
- inetnum: 195.20.18.0 - 195.20.18.127 org: ORG-AS895-RIPE netname: AlexHost country: MD admin-c: SZ3268-RIPE tech-c: SZ3268-RIPE status: ASSIGNED PA mnt-by: IPSMAIN created: 2023-02-22T10:47:24Z last-modified: 2023-02-22T10:47:24Z source: RIPE mnt-domains: IPSMAIN mnt-domains: CLOUDATAMD-MNT mnt-lower: CLOUDATAMD-MNT mnt-routes: CLOUDATAMD-MNT mnt-routes: IPSMAIN organisation: ORG-AS895-RIPE org-name: ALEXHOST SRL org-type: OTHER address: str. C. Brancusi nr. 3, Chisinau, Moldova abuse-c: AR18916-RIPE mnt-ref: MNT-GLBTX mnt-ref: FREENET-MNT mnt-ref: IPSMAIN mnt-by: IPSMAIN created: 2021-02-08T19:58:24Z last-modified: 2022-03-09T16:27:19Z source: RIPE # Filtered person: AlexHost SRL address: str. Constantin Brancusi nr. 3, Chisinau, Moldova phone: +37379600002 nic-hdl: SZ3268-RIPE mnt-by: CLOUDATAMD-MNT created: 2014-03-21T14:17:01Z last-modified: 2023-03-03T08:12:53Z source: RIPE # Filtered route: 195.20.18.0/24 origin: AS48753 mnt-by: VPLAB-MNT created: 2024-03-01T10:23:09Z last-modified: 2024-03-01T10:23:09Z source: RIPE
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 11 months ago · Last seen 11 months ago
Appeared in 15 threat reports