IOC Radar
IPMediumSignal 57/100

41.123.1.104

Location
South AfricaSouth Africa
Johannesburg, Gauteng
ASN
AS12091
MTNSA
First Seen
Apr 16, 2026
Last Seen
Apr 22, 2026
Apr 16
First Seen
71d ago
Apr 22
Last Seen
65d ago
6
Reports
source reports
57%
Confidence
medium
Found in 6 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
57%
Signal Score
57 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

1 techniques

Network Information

CountryZASouth Africa
RegionJohannesburg, Gauteng
ASNAS12091
OrganizationMTNSA

Feed Intelligence Summary

6 reports57% confidence
6
Source reports
57%
Confidence score
Category tags
abuseactive scanafricaaustraliabad reputationindicatornetworkoceaniaresearchedscanscannersipsouth africassht1595

Activity Timeline

1 total obs
Apr 22Apr 22

Threat Activity Heatmap

· Peak: 2026-04-22
Less
More
Mon
Wed
Fri
Jun
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreMedium Risk
57
SIGNAL
Signal Score
57%
Confidence
6
Reports
First seenApr 16, 2026
Last seenApr 22, 2026
GeolocationZA
CountrySouth Africa
LocationJohannesburg, Gauteng
ASNAS12091
OrgMTNSA
Coords-29.0000, 24.0000

VirusTotal

Not checked

WHOIS

description
IPV4 hosts detected performing scans on production environment located in Australia.
raw
inetnum: 41.123.0.0 - 41.123.127.255 netname: MTNSA-41-123-0-0-17 descr: Mobile Broadband Internet - Pretoria country: ZA admin-c: MBIP-AFRINIC tech-c: MBIP-AFRINIC status: ASSIGNED PA remarks: report abuse to [email protected] mnt-by: MTNBUSINESS-MNT source: AFRINIC # Filtered parent: 41.112.0.0 - 41.127.255.255 role: MTN Business IP Maintainer address: MTN Business address: Heron Place address: c/o Century Boulevard and Heron Crescent address: Stand no 6465 address: Century City address: Cape Town address: South Africa admin-c: AT32-AFRINIC tech-c: AT32-AFRINIC nic-hdl: MBIP-AFRINIC mnt-by: MTNBUSINESS-MNT source: AFRINIC # Filtered
references
https://redpiranha.net

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 2 months ago · Last seen 2 months ago
Appeared in 6 threat reports