IPMediumSignal 62/100
221.194.168.2
Location
Shijiazhuang, JX
ASN
AS4837
China Unicom
First Seen
Apr 15, 2026
Last Seen
Apr 24, 2026
Found in 6 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
62%
Signal Score
62 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Network Information
Country
China
RegionShijiazhuang, JX
ASNAS4837
OrganizationChina Unicom
Feed Intelligence Summary
6 reports62% confidence
6
Source reports
62%
Confidence score
Category tags
active scanactive scanningaptasiabrute forcebrute force attackchinacredential accesscredential stuffingexploitation activityidentity & access exploitationindicatornetworkpassword attacksreconnaissanceresearchedscannerssh attackt1110.001t1110.002t1110.003t1110.004t1595.001t1595.002t1595.003threat actortor node
Activity Timeline
Apr 24Apr 24
Threat Activity Heatmap
· Peak: 2026-04-24LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreMedium Risk
62
SIGNAL
Signal Score
62%
Confidence
6
Reports
First seenApr 15, 2026
Last seenApr 24, 2026
GeolocationCN
CountryChina
LocationShijiazhuang, JX
ASNAS4837
OrgChina Unicom
Coords25.8443, 114.9290
VirusTotal
Not checked
WHOIS
- description
- The following is the full list of names given to Vye32GsS2g38eKhmaKrLdDjgrnf2YBT4/FGx8SNCa4txePA
- raw
- inetnum: 221.194.128.0 - 221.194.191.255 netname: CNC-LF country: cn descr: company LangFang City,Hebei province. admin-c: JL2284-AP tech-c: JL2284-AP status: ASSIGNED NON-PORTABLE mnt-by: MAINT-CNCGROUP-HE last-modified: 2009-04-10T03:35:29Z source: APNIC person: jinyuan lu nic-hdl: JL2284-AP e-mail: [email protected] address: hebei province shijiazhuang phone: +86-311-86685210 fax-no: +86-311-86051214 country: CN mnt-by: MAINT-CNCGROUP-HE last-modified: 2008-09-04T07:29:40Z source: APNIC route: 221.194.0.0/16 origin: AS4837 descr: China Unicom B811&A1218, China Unicom No.21, Jin-Rong Street mnt-by: MAINT-CNCGROUP-RR last-modified: 2023-06-08T06:24:12Z source: APNIC
- references
- https://malware-filter.gitlab.io/malware-filter/botnet-filter.txt
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 1 month ago · Last seen 1 month ago
Appeared in 6 threat reports