IPLowSignal 100/100
23.94.213.233
Location
Los Angeles, CA
ASN
AS36352
HostPapa
First Seen
Oct 21, 2023
Last Seen
Feb 15, 2026
Oct 21
First Seen
967d ago
Feb 15
Last Seen
119d ago
16
Reports
source reports
99%
Confidence
low
0/91
VirusTotal
detections
Found in 16 reports. Confidence: low. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
99%
Signal Score
100 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Network Information
Country
United States
RegionLos Angeles, CA
ASNAS36352
OrganizationHostPapa
Feed Intelligence Summary
16 reports99% confidence
16
Source reports
99%
Confidence score
Category tags
abuseaccess attemptactive scanningattackauthentication abuseauthentication attackauthentication failurebotnetbrute forcebrute force attackcommand and controlcommunication protocolcowrie honeypotcredential accesscredential stuffingctadata exfiltrationdecoy systemdistributed attackseuropeexploit attemptfailed login attemptsftp brute forcelogin failuremalicious activitymalicious softwaremalwarenetworknetwork probingnetwork securitynorth americapassword attacksprocess injectionproxyreconnaissanceresearchedscanscannersecurity operationsservice scanningsftp attacksocradar honeypotssh attackssh monitoringt1021t1021.001t1021.004t1040t1041t1055t1059t1071.001t1078t1110t1110.001t1110.002t1110.003t1110.004t1190t1486t1496t1499.002t1499.003t1565t1595t1595.001t1595.002t1595.003telecommunicationsthreat actorthreat intelligenceunauthorized accessunited kingdomunited statesunited states of americausvoip
Activity Timeline
Feb 15Feb 15
Threat Activity Heatmap
· Peak: 2026-02-15LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Threat ScoreHigh Risk
100
SIGNAL
Signal Score
99%
Confidence
16
Reports
First seenOct 21, 2023
Last seenFeb 15, 2026
GeolocationUS
CountryUnited States
LocationLos Angeles, CA
ASNAS36352
OrgHostPapa
Coords34.0544, -118.2440
WHOIS
- description
- Banned by Fail2Ban [sshd]
- raw
- NetRange: 23.94.0.0 - 23.95.255.255 CIDR: 23.94.0.0/15 NetName: CC-16 NetHandle: NET-23-94-0-0-1 Parent: NET23 (NET-23-0-0-0-0) NetType: Direct Allocation OriginAS: AS36352 Organization: HostPapa (HOSTP-7) RegDate: 2013-08-16 Updated: 2024-02-02 Comment: Geofeed https://geofeeds.oniaas.io/geofeeds.csv Ref: https://rdap.arin.net/registry/ip/23.94.0.0 OrgName: HostPapa OrgId: HOSTP-7 Address: 325 Delaware Avenue Address: Suite 300 City: Buffalo StateProv: NY PostalCode: 14202 Country: US RegDate: 2016-06-06 Updated: 2024-04-26 Ref: https://rdap.arin.net/registry/entity/HOSTP-7 OrgAbuseHandle: NETAB23-ARIN OrgAbuseName: NETABUSE OrgAbusePhone: +1-905-315-3455 OrgAbuseEmail: [email protected] OrgAbuseRef: https://rdap.arin.net/registry/entity/NETAB23-ARIN OrgTechHandle: NETTE9-ARIN OrgTechName: NETTECH OrgTechPhone: +1-905-315-3455 OrgTechEmail: [email protected] OrgTechRef: https://rdap.arin.net/registry/entity/NETTE9-ARIN RTechHandle: NETTE11-ARIN RTechName: NETTECH-COLOCROSSING RTechPhone: +1-800-518-9716 RTechEmail: [email protected] RTechRef: https://rdap.arin.net/registry/entity/NETTE11-ARIN RAbuseHandle: NETAB27-ARIN RAbuseName: NETABUSE-COLOCROSSING RAbusePhone: +1-800-518-9716 RAbuseEmail: [email protected] RAbuseRef: https://rdap.arin.net/registry/entity/NETAB27-ARIN
- references
- https://redpiranha.net, https://raw.githubusercontent.com/ahamed-rizvan/IOCs/refs/heads/main/Malicous%20IP%20Address.txt, https://github.com/telekom-security/tpotce
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
lowFirst detected 2 years ago · Last seen 3 months ago
Appeared in 16 threat reports