IOC Radar
IPMediumSignal 100/100

209.159.214.143

Location
United StatesUnited States
Box Elder, South Dakota
ASN
AS20412
Clarity Telecom LLC
First Seen
Jan 6, 2025
Last Seen
Mar 18, 2026
Jan 6
First Seen
537d ago
Mar 18
Last Seen
101d ago
14
Reports
source reports
99%
Confidence
medium
Found in 14 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
99%
Signal Score
100 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

31 techniques

Network Information

CountryUSUnited States
RegionBox Elder, South Dakota
ASNAS20412
OrganizationClarity Telecom LLC

Feed Intelligence Summary

14 reports99% confidence
14
Source reports
99%
Confidence score
Category tags
abuseaccess controlactive scanningattackbotnetbrute forcebrute force attackbrute force attemptcommand and controlcommunication protocolcowrie honeypotcredential accesscredential harvestingcredential stuffingctadata exfiltrationddos attacksdecoy systemdistributed attackshoneytrap honeypotindicatorinfrastructure acquisitionreconnaissanceinternet of thingsintrusion detectioniociot botnetiot/ics attacklampmalicious activitymalicious network activitymalicious softwaremalwaremanualmirai botnetnetworknetwork attacksnetwork intrusionnetwork probingnetwork scanningnetwork securitynetwork service scanningnorth americapassword attacksphishing attackprocess injectionprotocol exploitationreconnaissanceresearchedscanscannersecurity policyself-signedsftp attacksocial engineeringssh attackssh monitoringt1021.002t1040t1041t1046t1055t1056.001t1059.001t1071.001t1078t1110t1110.001t1110.002t1110.003t1110.004t1133t1190t1486t1496t1499.001t1499.002t1499.003t1565t1566.001t1566.002t1566.003t1587.001t1590.001t1595t1595.001t1595.002t1595.003tcp protocoltelecommunicationstelnet threatthreat actorthreat detectionthreat intelligencethreat preventionunited statesunited states of americaus

Activity Timeline

1 total obs
Mar 18Mar 18

Threat Activity Heatmap

· Peak: 2026-03-18
Less
More
Mon
Wed
Fri
Jun
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Threat ScoreHigh Risk
100
SIGNAL
Signal Score
99%
Confidence
14
Reports
First seenJan 6, 2025
Last seenMar 18, 2026
GeolocationUS
CountryUnited States
LocationBox Elder, South Dakota
ASNAS20412
OrgClarity Telecom LLC
Coords44.1225, -103.0592

VirusTotal

Not checked

WHOIS

description
Scans hitting the server at TCP port 23 Telnet. Same IP should not appear more than once in 96 hours in our lists S3#.
references
https://github.com/telekom-security/tpotce

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 3 months ago
Appeared in 14 threat reports