IOC Radar
IPMediumSignal 92/100

27.220.54.138

Location
ChinaChina
Jinan, BJ
ASN
AS4837
China Unicom Shandong Province Network
First Seen
May 14, 2025
Last Seen
Feb 15, 2026
May 14
First Seen
401d ago
Feb 15
Last Seen
124d ago
13
Reports
source reports
92%
Confidence
medium
3/91
VirusTotal
detections
Found in 13 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
92%
Signal Score
92 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

32 techniques

Network Information

CountryCNChina
RegionJinan, BJ
ASNAS4837
OrganizationChina Unicom Shandong Province Network

Feed Intelligence Summary

13 reports92% confidence
13
Source reports
92%
Confidence score
Category tags
abuseactive scanningarmasiaattackbotnetbrute forcebrute force attackc2 serverchinacommand and controlcommunication technologiescompromised hostscredential accesscredential stuffingdata exfiltrationdata theftddosddos attacksdenial of servicedistributed attackselfexploit attemptsftp brute forcehackinghttp brute forceindicatorinternet of thingsiociot botnetiot/ics attacklateral movementmalicious activitymalicious softwaremalwaremalware distributionmalware propagationmalware scanningmirai botnetmobile carriersmobile networksmozinetworknetwork probingnetwork scanningnetwork traffic analysispassword attacksprocess injectionreconnaissanceremote accessremote servicesresearchedscannersmtp brute forcesocradar honeypotspamsql injection attemptsssh attackt1021t1021.001t1046t1055t1059t1071t1071.001t1076t1078t1105t1110t1110.001t1110.002t1110.003t1110.004t1133t1187t1190t1199t1210t1486t1496t1499.002t1499.003t1563t1565t1573t1588t1595t1595.001t1595.002t1595.003telecom servicestelecommunicationsthreat actor

Activity Timeline

1 total obs
Feb 15Feb 15

Threat Activity Heatmap

· Peak: 2026-02-15
Less
More
Mon
Wed
Fri
Jun
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Threat ScoreHigh Risk
92
SIGNAL
Signal Score
92%
Confidence
13
Reports
First seenMay 14, 2025
Last seenFeb 15, 2026
GeolocationCN
CountryChina
LocationJinan, BJ
ASNAS4837
OrgChina Unicom Shandong Province Network
Coords39.9285, 116.3850

VirusTotal

3/ 91vendors flagged
3% detection rateJun 8, 2026

WHOIS

raw
inetnum: 27.192.0.0 - 27.223.255.255 netname: UNICOM-SD descr: China Unicom Shandong province network descr: China Unicom country: CN admin-c: CH1302-AP tech-c: XZ14-AP abuse-c: AC1718-AP status: ALLOCATED PORTABLE remarks: -------------------------------------------------------- remarks: To report network abuse, please contact mnt-irt remarks: For troubleshooting, please contact tech-c and admin-c remarks: Report invalid contact via www.apnic.net/invalidcontact remarks: -------------------------------------------------------- mnt-by: APNIC-HM mnt-lower: MAINT-CNCGROUP mnt-lower: MAINT-CNCGROUP-SD mnt-routes: MAINT-CNCGROUP-RR mnt-irt: IRT-CU-CN last-modified: 2025-01-22T13:11:14Z source: APNIC irt: IRT-CU-CN address: No.21,Financial Street address: Beijing,100033 address: P.R.China e-mail: [email protected] abuse-mailbox: [email protected] admin-c: CH1302-AP tech-c: CH1302-AP auth: # Filtered remarks: [email protected] was validated on 2025-02-24 mnt-by: MAINT-CNCGROUP last-modified: 2025-02-24T06:16:57Z source: APNIC role: ABUSE CUCN country: ZZ address: No.21,Financial Street address: Beijing,100033 address: P.R.China phone: +000000000 e-mail: [email protected] admin-c: CH1302-AP tech-c: CH1302-AP nic-hdl: AC1718-AP remarks: Generated from irt object IRT-CU-CN remarks: [email protected] was validated on 2025-02-24 abuse-mailbox: [email protected] mnt-by: APNIC-ABUSE last-modified: 2025-02-24T06:17:45Z source: APNIC person: ChinaUnicom Hostmaster nic-hdl: CH1302-AP e-mail: [email protected] address: No.21,Jin-Rong Street address: Beijing,100033 address: P.R.China phone: +86-10-66259764 fax-no: +86-10-66259764 country: CN mnt-by: MAINT-CNCGROUP last-modified: 2017-08-17T06:13:16Z source: APNIC person: XIAOFENG ZHANG nic-hdl: XZ14-AP e-mail: [email protected] address: Jinan,Shandong P.R China phone: +86-531-6666666 fax-no: +86-531-6666666 country: CN mnt-by: MAINT-ZXF last-modified: 2008-09-04T07:29:35Z source: APNIC route: 27.192.0.0/11 descr: China Unicom Shandong Province Network country: CN origin: AS4837 mnt-by: MAINT-CNCGROUP-RR last-modified: 2010-04-14T05:24:01Z source: APNIC
references
https://malware-filter.gitlab.io/malware-filter/botnet-filter.txt

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 4 months ago
Appeared in 13 threat reports