IOC Radar
IPMediumSignal 48/100

37.99.32.185

Location
KazakhstanKazakhstan
Almaty, Almaty
ASN
AS21299
TNSPLUS-FTTB
First Seen
Apr 15, 2026
Last Seen
Apr 24, 2026
Apr 15
First Seen
58d ago
Apr 24
Last Seen
50d ago
7
Reports
source reports
48%
Confidence
medium
Found in 7 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
48%
Signal Score
48 / 100
IDS Rule
No
Threat Context
Tags

Network Information

CountryKZKazakhstan
RegionAlmaty, Almaty
ASNAS21299
OrganizationTNSPLUS-FTTB

Feed Intelligence Summary

7 reports48% confidence
7
Source reports
48%
Confidence score
Category tags
aptasiaexploitation activityimapimap attackindicatorkazakhstannetworkresearchedsmtpsmtp attackerthreat actortor node

Activity Timeline

1 total obs
Apr 24Apr 24

Threat Activity Heatmap

· Peak: 2026-04-24
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreMedium Risk
48
SIGNAL
Signal Score
48%
Confidence
7
Reports
First seenApr 15, 2026
Last seenApr 24, 2026
GeolocationKZ
CountryKazakhstan
LocationAlmaty, Almaty
ASNAS21299
OrgTNSPLUS-FTTB
Coords43.2525, 76.9115

VirusTotal

Not checked

WHOIS

description
The following is the full list of names given to Vye32GsS2g38eKhmaKrLdDjgrnf2YBT4/FGx8SNCa4txePA
raw
inetnum: 37.99.32.0 - 37.99.47.255 netname: KZ-TNSPLUS-FTTB descr: FTTB_Almaty country: KZ admin-c: DG5853-RIPE tech-c: DG5853-RIPE status: ASSIGNED PA mnt-by: TNSPLUS-MNT created: 2012-02-20T10:19:04Z last-modified: 2012-05-03T12:57:47Z source: RIPE person: Dmitriy Gromov address: 38 Dostik str., Almaty, Kazakhstan phone: +7 727 2599 000 nic-hdl: DG5853-RIPE mnt-by: TNSPLUS-MNT created: 2011-10-28T04:40:19Z last-modified: 2017-11-06T20:48:03Z source: RIPE route: 37.99.32.0/24 origin: AS21299 mnt-by: ORBITA-PLUS-MNT mnt-by: TNSPLUS-MNT mnt-by: SATELCOM-MNT mnt-by: kz-ipnet-kar-tel-1-mnt created: 2018-10-01T06:35:33Z last-modified: 2018-10-01T06:35:33Z source: RIPE

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 month ago · Last seen 1 month ago
Appeared in 7 threat reports