IOC Radar
IPMediumSignal 49/100

38.55.131.228

Location
United StatesUnited States
Santa Clara, California
ASN
AS402169
PEG TECH INC
First Seen
Nov 12, 2025
Last Seen
Jun 2, 2026
Nov 12
First Seen
229d ago
Jun 2
Last Seen
27d ago
10
Reports
source reports
49%
Confidence
medium
Found in 10 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
49%
Signal Score
49 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

23 techniques

Network Information

CountryUSUnited States
RegionSanta Clara, California
ASNAS402169
OrganizationPEG TECH INC

Feed Intelligence Summary

10 reports49% confidence
10
Source reports
49%
Confidence score
Category tags
abuseactive scanactive scanningadbhoney honeypotaptattackaustraliabad reputationbotnetbotnet activitybrute forcebrute force attackbrute force attacksciscocisco devicecommand and controlcommunication protocolcowriecowrie honeypotcredential accesscredential stuffingdata exfiltrationdata store exposuredatabase attackddosddos attackdecoy systemdenial of servicedevice managementdionaeadionaea honeypotenterprise networkingexploitexploitation activityexploitation of vulnerabilityexploited hostfattfileftp attacksftp brute forcehackinghoneytrap honeypothttp brute forcehttp scanningidentity & access exploitationintrusion detectionioclamplamp stack attacklateral movementmailoney honeypotmalicious activitymalicious file uploadsmalwaremalware behaviourmalware capturenetworknetwork infrastructurenetwork intrusion attemptsnetwork scanningnetwork securitynorth americaoceaniaopenctip0fpassword attacksphishingphishing attackphishing trappossible mirai variantprotocol exploitationproxyreconnaissanceremote access attemptsresearchedresource hijackingscannerscripting attackssensor-taggedsentrypeer botnetservice scansftpsftp activitysftp attacksipsip attackssmtp brute forcespamsshssh attackssh monitoringt1021t1021.004t1040t1041t1059t1059.004t1059.007t1071.001t1078t1110t1110.001t1110.002t1110.003t1110.004t1190t1203t1204.002t1496t1499.001t1595t1595.001t1595.002t1595.003tannertargeting databasetelecommunicationstelnet threatthreat actorthreat detectionthreat intelligencetor nodetpotudp port scanunited statesusvoipvoip attackvulnerability scanweb application attackweb application attacksweb attackweb exploitationweb spam

Activity Timeline

1 total obs
Jun 2Jun 2

Threat Activity Heatmap

· Peak: 2026-06-02
Less
More
Mon
Wed
Fri
Jun
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
·
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Threat ScoreMedium Risk
49
SIGNAL
Signal Score
49%
Confidence
10
Reports
First seenNov 12, 2025
Last seenJun 2, 2026
GeolocationUS
CountryUnited States
LocationSanta Clara, California
ASNAS402169
OrgPEG TECH INC
Coords37.7510, -97.8220

VirusTotal

Not checked

WHOIS

raw
Cogent Communications, LLC COGENT-A (NET-38-0-0-0-1) 38.0.0.0 - 38.255.255.255 PEG TECH INC PEG-TECH-CGNT-NET-3 (NET-38-55-128-0-1) 38.55.128.0 - 38.55.255.255
references
https://github.com/telekom-security/tpotce, https://malware-filter.gitlab.io/malware-filter/botnet-filter.txt

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 7 months ago · Last seen 27 days ago
Appeared in 10 threat reports