IOC Radar
IPMediumSignal 56/100

208.131.130.87

Location
United StatesUnited States
Farragut, Tennessee
ASN
AS13213
WestHost, Inc.
First Seen
Oct 31, 2024
Last Seen
Apr 9, 2026
Oct 31
First Seen
591d ago
Apr 9
Last Seen
65d ago
6
Reports
source reports
56%
Confidence
medium
Found in 6 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
56%
Signal Score
56 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

25 techniques

Network Information

CountryUSUnited States
RegionFarragut, Tennessee
ASNAS13213
OrganizationWestHost, Inc.

IP Category

VPN
VPN exit node

Feed Intelligence Summary

6 reports56% confidence
6
Source reports
56%
Confidence score
Category tags
accessaccess controlaccount discoveryaccount profilingaccount takeoveractive scanactive scanningauthenticationautomated attackbotnetbotnet activitybrute forcebrute force attackbrute force attemptsbruteforcecommand and controlcredential accesscredential stuffingdata exfiltrationdata store exposureddosdenial of servicedistributed attacksencryptionexploitation activityfortiosgroupshackingidentity & access exploitationindicatorinformation technologyinjection activityipv4it infrastructuremalicious softwaremalwaremobile threatnetworknetwork securitynorth americapassword attackpassword attacksprocess injectionreconnaissanceremote accessremote servicesresearchedscannerscriptsecurity operationsslugsoftware developmentssl vpnsurface webt1021.001t1055t1071.001t1078t1078.001t1110t1110.001t1110.002t1110.003t1110.004t1133t1190t1203t1486t1496t1499.001t1499.002t1499.003t1555t1555.003t1565t1567t1595.001t1595.002t1595.003threat actorthreat intelligencetor nodeunauthorized accessunited statesusvpnvpn ipweb application attackweb exploitation

Activity Timeline

1 total obs
Apr 9Apr 9

Threat Activity Heatmap

· Peak: 2026-04-09
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreMedium Risk
56
SIGNAL
Signal Score
56%
Confidence
6
Reports
First seenOct 31, 2024
Last seenApr 9, 2026
GeolocationUS
CountryUnited States
LocationFarragut, Tennessee
ASNAS13213
OrgWestHost, Inc.
Coords37.7510, -97.8220
VPN

VirusTotal

Not checked

WHOIS

raw
NetRange: 208.131.128.0 - 208.131.159.255 CIDR: 208.131.128.0/19 NetName: WH-NET-208-131-128-0-1 NetHandle: NET-208-131-128-0-1 Parent: NET208 (NET-208-0-0-0-0) NetType: Direct Allocation OriginAS: AS29854 Organization: WestHost, Inc. (WESTHO) RegDate: 2005-12-13 Updated: 2014-01-02 Ref: https://rdap.arin.net/registry/ip/208.131.128.0 OrgName: WestHost, Inc. OrgId: WESTHO Address: 115 Broadway, 5th Floor City: New York StateProv: NY PostalCode: 10006 Country: US RegDate: 2000-03-13 Updated: 2024-11-25 Comment: Please report abuse issues to [email protected] Ref: https://rdap.arin.net/registry/entity/WESTHO OrgAbuseHandle: WESTH2-ARIN OrgAbuseName: WestHost Abuse OrgAbusePhone: +1-435-755-3433 OrgAbuseEmail: [email protected] OrgAbuseRef: https://rdap.arin.net/registry/entity/WESTH2-ARIN OrgTechHandle: WESTH1-ARIN OrgTechName: WestHost Inc OrgTechPhone: +1-435-755-3433 OrgTechEmail: [email protected] OrgTechRef: https://rdap.arin.net/registry/entity/WESTH1-ARIN RAbuseHandle: WESTH2-ARIN RAbuseName: WestHost Abuse RAbusePhone: +1-435-755-3433 RAbuseEmail: [email protected] RAbuseRef: https://rdap.arin.net/registry/entity/WESTH2-ARIN RTechHandle: WESTH1-ARIN RTechName: WestHost Inc RTechPhone: +1-435-755-3433 RTechEmail: [email protected] RTechRef: https://rdap.arin.net/registry/entity/WESTH1-ARIN RNOCHandle: WESTH1-ARIN RNOCName: WestHost Inc RNOCPhone: +1-435-755-3433 RNOCEmail: [email protected] RNOCRef: https://rdap.arin.net/registry/entity/WESTH1-ARIN

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 2 months ago
Appeared in 6 threat reports