IOC Radar
IPMediumSignal 67/100

219.157.66.236

Location
ChinaChina
Zhengzhou, HA
ASN
AS4837
CNC Group CHINA169 Henan Province Network
First Seen
Aug 28, 2021
Last Seen
Jun 3, 2026
Aug 28
First Seen
1757d ago
Jun 3
Last Seen
16d ago
12
Reports
source reports
67%
Confidence
medium
Found in 12 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
67%
Signal Score
67 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

14 techniques

Network Information

CountryCNChina
RegionZhengzhou, HA
ASNAS4837
OrganizationCNC Group CHINA169 Henan Province Network

Feed Intelligence Summary

12 reports67% confidence
12
Source reports
67%
Confidence score
Category tags
abuseabusech-urlhaus-c2cactive scanactive scanningadbapeapkaptarmasciiasiaasyncratautogenerated-phishingbad reputationbaseloaderbatblamonbotnetbotnet activitybrute forcebrute force attackbyobc2chinacmdcncobaltstrikecoinminercommand & controlcommand and controlcredential accesscredential stuffingcryptocurrencycryptojackerdarkgatedata exfiltrationdata store exposuredbatloaderddosdiscorddistributed attacksdlldocdownloaderdropped-by-amadeydropped-by-privateloaderdropped-by-smokeloaderelfencodedexeexecutable fileexploitation activityexploited hostgafgytgh0stratgithubguloaderhackinghajimehtaidentity & access exploitationindicatorinfostealerinjection activityjava-bytecodekajikryptiklnklog4jlog4shelllokim68kmacsyncmalicious softwaremalwaremamontmartemetasploitmeterpretermipsmiraimobile threatmozimp4msinetcatnetworknpmorcusorcusratousabanpassword attacksphishingpowedonpowerpcpowershellpowershelldropperprocess injectionps1purelogstealerquasarratransomwareratreconnaissanceremcosremcosratresearchedscams & fraudscannerscrscriptshshellscriptstealcsuperht1055t1071.001t1110.001t1110.002t1110.003t1110.004t1486t1496t1499.002t1499.003t1565t1595.001t1595.002t1595.003tag:farflithreat actortrojanua-wgetunited statesvbsvbs-droppervenomratx86x86-64xwormzbotzipzusy

Activity Timeline

1 total obs
Jun 3Jun 3

Threat Activity Heatmap

· Peak: 2026-06-03
Less
More
Mon
Wed
Fri
Jun
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Threat ScoreMedium Risk
67
SIGNAL
Signal Score
67%
Confidence
12
Reports
First seenAug 28, 2021
Last seenJun 3, 2026
GeolocationCN
CountryChina
LocationZhengzhou, HA
ASNAS4837
OrgCNC Group CHINA169 Henan Province Network
Coords34.6808, 112.4531

VirusTotal

Not checked

WHOIS

raw
inetnum: 219.154.0.0 - 219.157.255.255 netname: UNICOM-CN descr: China Unicom IP network descr: China Unicom country: CN admin-c: CH1302-AP tech-c: CH1302-AP abuse-c: AC1718-AP status: ALLOCATED PORTABLE remarks: service provider remarks: -------------------------------------------------------- remarks: To report network abuse, please contact mnt-irt remarks: For troubleshooting, please contact tech-c and admin-c remarks: Report invalid contact via www.apnic.net/invalidcontact remarks: -------------------------------------------------------- mnt-by: APNIC-HM mnt-lower: MAINT-CN-CUCGROUP mnt-routes: MAINT-CNCGROUP-RR mnt-irt: IRT-CU-CN last-modified: 2025-01-22T13:12:21Z source: APNIC irt: IRT-CU-CN address: No.21,Financial Street address: Beijing,100033 address: P.R.China e-mail: [email protected] abuse-mailbox: [email protected] admin-c: CH1302-AP tech-c: CH1302-AP auth: # Filtered remarks: [email protected] was validated on 2026-05-08 mnt-by: MAINT-CNCGROUP last-modified: 2026-05-09T04:50:16Z source: APNIC role: ABUSE CUCN country: ZZ address: No.21,Financial Street address: Beijing,100033 address: P.R.China phone: +000000000 e-mail: [email protected] admin-c: CH1302-AP tech-c: CH1302-AP nic-hdl: AC1718-AP remarks: Generated from irt object IRT-CU-CN remarks: [email protected] was validated on 2026-05-08 abuse-mailbox: [email protected] mnt-by: APNIC-ABUSE last-modified: 2026-05-08T01:31:32Z source: APNIC person: ChinaUnicom Hostmaster nic-hdl: CH1302-AP e-mail: [email protected] address: No.21,Jin-Rong Street address: Beijing,100033 address: P.R.China phone: +86-10-66259764 fax-no: +86-10-66259764 country: CN mnt-by: MAINT-CNCGROUP last-modified: 2017-08-17T06:13:16Z source: APNIC route: 219.156.0.0/15 descr: CNC Group CHINA169 Henan Province Network country: CN origin: AS4837 mnt-by: MAINT-CNCGROUP-RR last-modified: 2008-09-04T07:54:44Z source: APNIC
references
https://urlhaus.abuse.ch/browse/

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 4 years ago · Last seen 16 days ago
Appeared in 12 threat reports