IOC Radar
IPMediumSignal 100/100

38.54.88.203

Location
JapanJapan
Tokyo, Tokyo
ASN
AS138915
LightNode-JP
First Seen
Nov 12, 2025
Last Seen
Apr 9, 2026
Nov 12
First Seen
213d ago
Apr 9
Last Seen
64d ago
6
Reports
source reports
99%
Confidence
medium
9/91
VirusTotal
detections
Found in 6 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
99%
Signal Score
100 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

32 techniques

Network Information

CountryJPJapan
RegionTokyo, Tokyo
ASNAS138915
OrganizationLightNode-JP

IP Category

Proxy
Proxy server

Feed Intelligence Summary

6 reports99% confidence
6
Source reports
99%
Confidence score
Category tags
account hijackingactive scanaptarctic wolfashen lepusasiaattackauthenticationauthentication bypassbrute forcebrute force attackcertcompanycredential accesscredential harvestingcredential stuffingcvedata encryptiondata exfiltrationdata store exposureencryptioneurope/asiaexfiltrationexploitexploitation activityextortionforticloud ssofortiosfortiproxyhosting provider ipsidentity & access exploitationindicatorinfostealerinjection activityjapankaopu cloudluca stealermakop ransomwaremalicious activitymalicious softwaremalwaremobile threatnamenetworknorth americapassword attackspassword sprayingphishingphishing attackprocess injectionproxypython malwareransomwareremote accessremote code executionresearchedsamlsecurity operationssocial engineeringssosystem disruptiont1003t1055t1059.006t1068t1071.001t1078t1082t1110t1110.001t1110.002t1110.003t1110.004t1133t1190t1199t1204.002t1212t1486t1490t1539t1550t1550.003t1550.004t1552.001t1553t1555t1555.005t1565t1566t1566.001t1566.002t1566.003threat actorthreat intelligencetor nodeturkeyunited statesvulnerability scanwolfyara

Activity Timeline

1 total obs
Apr 9Apr 9

Threat Activity Heatmap

· Peak: 2026-04-09
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreHigh Risk
100
SIGNAL
Signal Score
99%
Confidence
6
Reports
First seenNov 12, 2025
Last seenApr 9, 2026
GeolocationJP
CountryJapan
LocationTokyo, Tokyo
ASNAS138915
OrgLightNode-JP
Coords35.6893, 139.6899
Proxy

VirusTotal

9/ 91vendors flagged
10% detection rateJun 13, 2026

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 7 months ago · Last seen 2 months ago
Appeared in 6 threat reports