IOC Radar
IPMediumSignal 73/100

209.38.17.122

Location
United StatesUnited States
Sydney, New South Wales
ASN
AS14061
DigitalOcean, LLC
First Seen
Mar 21, 2025
Last Seen
Feb 18, 2026
Mar 21
First Seen
461d ago
Feb 18
Last Seen
127d ago
16
Reports
source reports
73%
Confidence
medium
Found in 16 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
73%
Signal Score
73 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

29 techniques

Network Information

CountryUSUnited States
RegionSydney, New South Wales
ASNAS14061
OrganizationDigitalOcean, LLC

IP Category

VPN
VPN exit node

Feed Intelligence Summary

16 reports73% confidence
16
Source reports
73%
Confidence score
Category tags
abuseaccess controlactive scanningattackaustraliaauthentication attacksauthentication failureautomated attackbotnetbrute forcebrute force attackcommand and controlcommunication protocolcredential accesscredential stuffingdata exfiltrationdenial of servicedistributed attackseuropefail2ban alertfailed loginftp brute forcehttp brute forceindicatoripv4login attacklogin attemptsmalicious activitymalicious softwaremalwarenetworknetwork attacksnetwork intrusionnetwork protocolnetwork reconnaissancenetwork scanningnetwork securitynorth americaoceaniapassword attackspossible brute forceprocess injectionreconnaissanceresearchedscanscannerscanning activitysecurity operationssecurity policyservice enumerationssh attackt1018t1021t1021.001t1021.002t1021.006t1040t1046t1055t1059t1071.001t1078t1110t1110.001t1110.002t1110.003t1110.004t1133t1190t1486t1496t1499.002t1499.003t1565t1588t1588.002t1595t1595.001t1595.002t1595.003tcp scanningtelecommunicationsthreat actorthreat intelligencethreat preventionunauthorized accessunauthorized access attemptsunited kingdomunited statesunknown threat actorvoipvpn

Activity Timeline

1 total obs
Feb 18Feb 18

Threat Activity Heatmap

· Peak: 2026-02-18
Less
More
Mon
Wed
Fri
Jun
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Threat ScoreHigh Risk
73
SIGNAL
Signal Score
73%
Confidence
16
Reports
First seenMar 21, 2025
Last seenFeb 18, 2026
GeolocationUS
CountryUnited States
LocationSydney, New South Wales
ASNAS14061
OrgDigitalOcean, LLC
Coords37.7510, -97.8220
VPN

VirusTotal

Not checked

WHOIS

description
Banned by Fail2Ban [sshd]
raw
inetnum: 209.0.0.0 - 209.255.255.255 netname: ARIN-CIDR-BLOCK descr: Not allocated by APNIC remarks: ------------------------------------------------------ remarks: remarks: Important: remarks: remarks: Details of networks in this range are not registered remarks: in the APNIC Whois Database. remarks: remarks: Please search the ARIN Whois, which contains remarks: details of IP addresses allocated in North America, remarks: parts of the Caribbean, and sub-equatorial Africa: remarks: remarks: website: https://ws.arin.net/whois remarks: command line: whois.arin.net remarks: remarks: ------------------------------------------------------ country: AU admin-c: IANA1-AP tech-c: IANA1-AP mnt-by: MAINT-APNIC-AP mnt-lower: MAINT-APNIC-AP status: ALLOCATED PORTABLE last-modified: 2009-05-01T03:52:53Z source: APNIC role: Internet Assigned Numbers Authority address: see http://www.iana.org. admin-c: IANA1-AP tech-c: IANA1-AP nic-hdl: IANA1-AP remarks: For more information on IANA services remarks: go to IANA web site at http://www.iana.org. mnt-by: MAINT-APNIC-AP last-modified: 2018-06-22T22:34:30Z source: APNIC
references
https://redpiranha.net

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 4 months ago
Appeared in 16 threat reports