IOC Radar
IPHighVerifiedSignal 88/100

206.188.196.221

Location
NetherlandsNetherlands
Amsterdam, North Holland
ASN
AS399629
BL Networks
First Seen
Jun 2, 2026
Last Seen
Jun 4, 2026
Jun 2
First Seen
3d ago
Jun 4
Last Seen
yesterday
43
Reports
source reports
95%
Confidence
high
10/91
VirusTotal
detections
Found in 43 reports. Confidence: high. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
95%
Signal Score
88 / 100
IDS Rule
Yes

Network Information

CountryNLNetherlands
RegionAmsterdam, North Holland
ASNAS399629
OrganizationBL Networks

Feed Intelligence Summary

43 reports95% confidence
AT
Abuse.ch ThreatFox
Yesterday
2925 IOCs in report
AT
Abuse.ch ThreatFox
Yesterday
2948 IOCs in report
AT
Abuse.ch ThreatFox
Yesterday
2938 IOCs in report
AT
Abuse.ch ThreatFox
Yesterday
2903 IOCs in report
AT
Abuse.ch ThreatFox
Yesterday
2897 IOCs in report
AT
Abuse.ch ThreatFox
Yesterday
2895 IOCs in report
AT
Abuse.ch ThreatFox
Yesterday
2868 IOCs in report
AT
Abuse.ch ThreatFox
Yesterday
2917 IOCs in report
AT
Abuse.ch ThreatFox
Yesterday
2903 IOCs in report
AT
Abuse.ch ThreatFox
Yesterday
2894 IOCs in report

Activity Timeline

43 total obs
Jun 4Jun 2

Threat Activity Heatmap

Less
More
Mon
Wed
Fri
Jun
·
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
24h
0
Dormant
7d
43
Critical
30d
43
Critical
3mo
43
Critical
Threat ScoreHigh Risk
88
SIGNAL
Signal Score
95%
Confidence
43
Reports
First seenJun 2, 2026
Last seenJun 4, 2026
Verified IOC
GeolocationNL
CountryNetherlands
LocationAmsterdam, North Holland
ASNAS399629
OrgBL Networks
Coords52.3759, 4.8975

VirusTotal

10/ 91vendors flagged
11% detection rateJun 4, 2026

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

high
First detected 3 days ago · Last seen 1 day ago
Appeared in 43 threat reports from 10 sources
Associated with: Sandworm
Used by malware: Nanocore, Stealc, Mirai, Vidar, Pegasus, Lumma, NetWire, SocGholish, Remcos, Rhysida, XMRig, XorDDoS, XWorm, Havoc, AsyncRAT, Metasploit, Sliver