IPMediumSignal 46/100
210.212.162.140
Location
Pune, MH
ASN
AS9829
National Internet Backbone
First Seen
Jun 24, 2021
Last Seen
May 23, 2026
Found in 10 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
46%
Signal Score
46 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Network Information
Country
India
RegionPune, MH
ASNAS9829
OrganizationNational Internet Backbone
Feed Intelligence Summary
10 reports46% confidence
10
Source reports
46%
Confidence score
Category tags
abuseaccess controlactive scanactive scanningasiaattackaustraliaauto-generated securitybad reputationblacklist candidatebotnetbotnet activitybrute forcebrute force attackbrute-forcecommand and controlcommunication protocolcowrie honeypotcredential accesscredential stuffingdata encryptiondata exfiltrationdata store exposuredatabase attackddosddos attacksdecoy systemdenial of servicedionaea honeypotdistributed attacksencryptionexploitexploitationexploitation activityexploited hostfattftpftp brute forcehackinghoneytrap honeypothttphttp brute forcehttp scanneridentity & access exploitationimageinindiaindicatorinitial accessinjection activityinternet of thingsintrusion detectioniociot botnetiot securityiot/ics attackkazakhstankaznetlateral movementmailoney honeypotmalicious activitymalicious ipmalicious softwaremalwaremalware behaviourmalware capturemirai botnetmssqlnetworknetwork attacksnetwork intrusion attemptsnetwork probingnetwork protocolnetwork scannetwork scanningnetwork securitynetwork traffic analysisoceaniap0fpassword attacksphishingphishing attackphishing trappossible botnet activitypossible reconnaissance activityprocess injectionprotocol exploitationrangereconnaissanceremote accessremote servicesresearchedresource hijackingscanscannerscanning activitysecurity policysensor-taggedsentrypeer botnetslugsmtpsmtp brute forcessh attackssh monitoringsurface websystem accesst-pott1018t1021t1021.001t1021.002t1040t1046t1053t1055t1059t1059.004t1068t1071.001t1076t1077t1078t1083t1105t1110t1110.001t1110.002t1110.003t1110.004t1133t1190t1210t1486t1496t1499.001t1499.002t1499.003t1550.003t1563t1565t1566t1583t1583.001t1583.002t1595t1595.001t1595.002t1595.003tannertargeting databasetcptcp protocoltelecommunicationstelnet threatthreat actorthreat detectionthreat intelligencethreat preventiontor nodetpotunauthorized access attemptvoipvoip attackvulnerability scanweb exploitweb traffic
Activity Timeline
May 23May 23
Threat Activity Heatmap
· Peak: 2026-05-23LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Intelligence SummaryAI Generated
This Indicator of Compromise (IOC), an IPv4 address, signals a significant and persistent threat requiring immediate attention due to its established association with malicious activities. With a threat score of 46.47, this IP address is strongly linked to various offensive security techniques, including brute-forcing, network scanning, exploitation of remote services, and potentially even ransomware-related activities. Its presence in organizational logs could indicate ongoing reconnaissance, a…
Threat ScoreMedium Risk
46
SIGNAL
Signal Score
46%
Confidence
10
Reports
First seenJun 24, 2021
Last seenMay 23, 2026
GeolocationIN
CountryIndia
LocationPune, MH
ASNAS9829
OrgNational Internet Backbone
Coords19.0748, 72.8856
VirusTotal
Not checked
WHOIS
- description
- HTTP range in small image. The goal is to consume server resources. The same IP address may appear more than once a day. S3#
- references
- https://threats.kz
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 5 years ago · Last seen 19 days ago
Appeared in 10 threat reports