IOC Radar
IPHighVerifiedSignal 69/100

216.106.185.40

Location
United StatesUnited States
Santa Clara, California
ASN
AS63023
GTHost
First Seen
Apr 17, 2026
Last Seen
Apr 28, 2026
Apr 17
First Seen
58d ago
Apr 28
Last Seen
47d ago
5
Reports
source reports
69%
Confidence
high
Found in 5 reports. Confidence: high. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
69%
Signal Score
69 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

3 techniques

Network Information

CountryUSUnited States
RegionSanta Clara, California
ASNAS63023
OrganizationGTHost

Feed Intelligence Summary

5 reports69% confidence
5
Source reports
69%
Confidence score
Category tags
active scanafricaargentinaasiaaustraliaaustriaauto-blockedbad reputationbangladeshbelgiumbrazilbrute forcebrute-forcecanadachinaencryptioneuropeeurope/asiafinlandfrancegermanyhong kongindiaindicatorirelanditalyjapankenyakorea, republic ofkyrgyzstanlithuaniamexicomorocconetherlandsnetworknew zealandnorth americanorwayoceaniapolandresearchedromaniarussiascannerserbiasingaporesouth africasouth americassl-enrichmentswedent1071.001t1105t1573.002taiwanthreat-intelukraineunited kingdomunited statesusvenezuela, bolivarian republic of

Activity Timeline

1 total obs
Apr 28Apr 28

Threat Activity Heatmap

· Peak: 2026-04-28
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreMedium Risk
69
SIGNAL
Signal Score
69%
Confidence
5
Reports
First seenApr 17, 2026
Last seenApr 28, 2026
Verified IOC
GeolocationUS
CountryUnited States
LocationSanta Clara, California
ASNAS63023
OrgGTHost
Coords37.7510, -97.8220

VirusTotal

Not checked

WHOIS

description
AbuseIPDB 100% | US | GTHost
raw
NetRange: 216.106.176.0 - 216.106.191.255 CIDR: 216.106.176.0/20 NetName: GTHOST NetHandle: NET-216-106-176-0-1 Parent: NET216 (NET-216-0-0-0-0) NetType: Direct Allocation OriginAS: Organization: GTHost (GC-852) RegDate: 2025-10-14 Updated: 2025-11-18 Comment: Geofeed https://lg-tor.gthost.com/geo-feed.csv Ref: https://rdap.arin.net/registry/ip/216.106.176.0 OrgName: GTHost OrgId: GC-852 Address: 427 S La Salle St, Suite 405 City: Chicago StateProv: IL PostalCode: 60605 Country: US RegDate: 2017-12-22 Updated: 2025-12-24 Ref: https://rdap.arin.net/registry/entity/GC-852 OrgNOCHandle: ADMIN6532-ARIN OrgNOCName: Admin OrgNOCPhone: +1-855-550-1010 OrgNOCEmail: [email protected] OrgNOCRef: https://rdap.arin.net/registry/entity/ADMIN6532-ARIN OrgTechHandle: ADMIN6532-ARIN OrgTechName: Admin OrgTechPhone: +1-855-550-1010 OrgTechEmail: [email protected] OrgTechRef: https://rdap.arin.net/registry/entity/ADMIN6532-ARIN OrgAbuseHandle: ABUSE9420-ARIN OrgAbuseName: Abuse OrgAbusePhone: +1-855-550-1010 OrgAbuseEmail: [email protected] OrgAbuseRef: https://rdap.arin.net/registry/entity/ABUSE9420-ARIN
references
https://analytics.dugganusa.com/api/v1/stix-feed/v2, https://www.abuseipdb.com

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

high
First detected 1 month ago · Last seen 1 month ago
Appeared in 5 threat reports