IOC Radar
IPMediumSignal 71/100

195.93.190.16

Location
UkraineUkraine
Burlacha Balka, 51
ASN
AS15713
LLC Global-City
First Seen
Apr 15, 2026
Last Seen
Apr 23, 2026
Apr 15
First Seen
60d ago
Apr 23
Last Seen
52d ago
7
Reports
source reports
71%
Confidence
medium
Found in 7 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
71%
Signal Score
71 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

1 techniques

Network Information

CountryUAUkraine
RegionBurlacha Balka, 51
ASNAS15713
OrganizationLLC Global-City

Feed Intelligence Summary

7 reports71% confidence
7
Source reports
71%
Confidence score
Category tags
aptbrute forcecredential accesscredential stuffingeuropeexploitation activityidentity & access exploitationindicatornetworkresearchedssh attackt1110.002threat actortor nodeukraine

Activity Timeline

1 total obs
Apr 23Apr 23

Threat Activity Heatmap

· Peak: 2026-04-23
Less
More
Mon
Wed
Fri
Jun
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Intelligence SummaryAI Generated

This Indicator of Compromise (IOC), an IPv4 address, represents a significant and immediate threat to organizational security. With a high score of 71.34, it is explicitly identified by multiple reputable threat intelligence feeds as being involved in potential attacks, specifically brute-force attempts targeting VNC credentials and SSH services. If left unaddressed, this malicious activity could lead to unauthorized access to critical systems, compromise of sensitive data, and potential lateral…

Threat ScoreHigh Risk
71
SIGNAL
Signal Score
71%
Confidence
7
Reports
First seenApr 15, 2026
Last seenApr 23, 2026
GeolocationUA
CountryUkraine
LocationBurlacha Balka, 51
ASNAS15713
OrgLLC Global-City
Coords46.2967, 30.6663

VirusTotal

Not checked

WHOIS

description
The following is the full list of names given to Vye32GsS2g38eKhmaKrLdDjgrnf2YBT4/FGx8SNCa4txePA
raw
inetnum: 195.93.190.0 - 195.93.191.255 netname: GCN-UA-NET country: UA org: ORG-GCN2-RIPE admin-c: OA3870-RIPE tech-c: OA3870-RIPE status: ASSIGNED PI mnt-by: RIPE-NCC-END-MNT mnt-by: ar4i-mnt mnt-by: MNT-GCN mnt-by: biba-mnt mnt-routes: MNT-GCN mnt-domains: MNT-GCN created: 2007-12-21T13:25:52Z last-modified: 2026-03-02T09:28:41Z source: RIPE sponsoring-org: ORG-RA159-RIPE organisation: ORG-GCN2-RIPE org-name: LLC Global-City-Net country: UA org-type: OTHER address: Chornomorsk, Odesa region, Danchenko str. 3B tech-c: OA3870-RIPE abuse-c: AR21664-RIPE mnt-ref: MNT-GCN mnt-by: biba-mnt mnt-by: ar4i-mnt created: 2007-02-20T11:30:35Z last-modified: 2026-03-02T09:21:26Z source: RIPE # Filtered person: Oleksandr Artemenko address: Ukraine, Odesa region, Odesa district, Malodolynske village, 9 Serhiy Bitner lane, 68093 phone: +380676560385 nic-hdl: OA3870-RIPE mnt-by: ar4i-mnt created: 2025-07-03T07:56:36Z last-modified: 2025-07-03T07:56:36Z source: RIPE # Filtered route: 195.93.190.0/24 descr: GCN-UA origin: AS15713 mnt-by: biba-mnt mnt-by: MNT-GCN mnt-by: ar4i-mnt created: 2007-12-21T14:35:57Z last-modified: 2026-03-02T09:29:25Z source: RIPE # Filtered
references
https://malware-filter.gitlab.io/malware-filter/botnet-filter.txt

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 2 months ago · Last seen 1 month ago
Appeared in 7 threat reports