IOC Radar
IPMediumSignal 26/100

31.25.140.10

Location
IraqIraq
Erbil, Erbil Governorate
ASN
AS197882
TarinNet-ISP
First Seen
Jun 5, 2024
Last Seen
Apr 2, 2026
Jun 5
First Seen
740d ago
Apr 2
Last Seen
74d ago
8
Reports
source reports
26%
Confidence
medium
1/91
VirusTotal
detections
Found in 8 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
26%
Signal Score
26 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

38 techniques

Network Information

CountryIQIraq
RegionErbil, Erbil Governorate
ASNAS197882
OrganizationTarinNet-ISP

Feed Intelligence Summary

8 reports26% confidence
8
Source reports
26%
Confidence score
Category tags
active scanactive scanningadbhoney attacksadbhoney honeypotantispamasiaattackauthentication attemptbotnetbotnet activitybrute forcebrute force attackcommand and controlcommunication protocolcowrie activitycowrie honeypotcowrie ssh attackscredential accesscredential harvestingcredential stuffingdata exfiltrationdata exfiltration attemptsdata store exposuredatabase securitydecoy systemdionaea honeypotdionaea malware collectiondistributed attackselasticpot honeypotelasticsearch monitoringexploitation activityftp brute forceheralding activityheralding projectidentity & access exploitationindicatorinjection activityiot securityiraqlog4jmailoney email attacksmailoney honeypotmalicious activitymalicious softwaremalwaremalware behaviourmalware capturenetworknetwork probenetwork scanningnetwork securitynetwork service scanningpassword attacksphishingphishing attackphishing trapprocess injectionreconnaissanceremote accessresearchedresource hijackingscanning activitysentrypeer botnetservice scansftp attacksocial engineeringspamssh attackssh monitoringt1018t1021t1021.002t1021.004t1040t1041t1046t1047t1055t1059t1059.004t1071.001t1078t1078.004t1110t1110.001t1110.002t1110.003t1110.004t1190t1195.001t1204.002t1486t1496t1499.001t1499.002t1499.003t1565t1566.001t1566.002t1566.003t1566.004t1583.001t1589.002t1595t1595.001t1595.002t1595.003tannertanner web attackstargeting databasetelecommunicationsthreat actorthreat intelligencetor nodeunauthorized login attemptsvoipvoip attack

Activity Timeline

1 total obs
Apr 2Apr 2

Threat Activity Heatmap

· Peak: 2026-04-02
Less
More
Mon
Wed
Fri
Jun
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreLow Risk
26
SIGNAL
Signal Score
26%
Confidence
8
Reports
First seenJun 5, 2024
Last seenApr 2, 2026
GeolocationIQ
CountryIraq
LocationErbil, Erbil Governorate
ASNAS197882
OrgTarinNet-ISP
Coords33.0000, 44.0000

VirusTotal

1/ 91vendors flagged
1% detection rateJun 12, 2026

WHOIS

description
2025-06-11T00:09:45.624Z Honeypot : Heralding : Source: 31.25.140.10 : Username/Password: ProxYUser/password Port: 1080 Message: 2025-06-11 00:09:45.624196,286cdcd7-fb1e-481d-ac9e-6bdb0ec9bb8a,6c47a03d-c97b-422d-b9ec-89ec44ac0624,31.25.140.10,50465,99.18.26.18,1080,socks5,ProxYUser,password,
raw
inetnum: 31.25.136.0 - 31.25.143.255 netname: IQ-TARINNET-20110307 country: IQ org: ORG-TGTa2-RIPE admin-c: dk3213-ripe abuse-c: AR73748-RIPE tech-c: dk3213-ripe status: ALLOCATED PA mnt-by: RIPE-NCC-HM-MNT mnt-by: Tarinnet-mnt mnt-routes: Tarinnet-mnt created: 2011-03-07T14:04:47Z last-modified: 2025-01-20T08:47:03Z source: RIPE organisation: ORG-TGTa2-RIPE org-name: Tarin General Trading and Setting Up Internet Device LTD country: IQ org-type: LIR address: Gulan Street - Behind Ster Tower address: 44001 address: Erbil address: IRAQ phone: +9647504270027 fax-no: +9647504183060 abuse-c: AR73748-RIPE mnt-ref: twana mnt-ref: Tarinnet-mnt mnt-ref: RIPE-NCC-HM-MNT mnt-by: RIPE-NCC-HM-MNT mnt-by: Tarinnet-mnt created: 2011-02-07T14:31:03Z last-modified: 2024-01-08T07:40:08Z source: RIPE # Filtered person: Ashraf Ibrahim address: Iraq-Erbil phone: +9647510538487 address: ster tower, 15th floor nic-hdl: DK3213-RIPE mnt-by: Tarinnet-mnt created: 2011-02-16T12:31:26Z last-modified: 2024-01-02T14:32:01Z source: RIPE # Filtered route: 31.25.140.0/24 origin: as197882 mnt-by: Tarinnet-mnt created: 2024-01-02T14:02:59Z last-modified: 2024-01-02T14:02:59Z source: RIPE
references
https://github.com/telekom-security/tpotce

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 2 years ago · Last seen 2 months ago
Appeared in 8 threat reports