IOC Radar
IPMediumSignal 77/100

45.119.55.66

Location
Hong KongHong Kong
Sha Tin Wai, Hong Kong
ASN
AS55933
YISUHUTONG Network Technology Co., Ltd.
First Seen
Mar 19, 2026
Last Seen
May 22, 2026
Mar 19
First Seen
86d ago
May 22
Last Seen
22d ago
6
Reports
source reports
77%
Confidence
medium
Found in 6 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
77%
Signal Score
77 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

33 techniques

Network Information

CountryHKHong Kong
RegionSha Tin Wai, Hong Kong
ASNAS55933
OrganizationYISUHUTONG Network Technology Co., Ltd.

Feed Intelligence Summary

6 reports77% confidence
6
Source reports
77%
Confidence score
Category tags
academic institutionsagentand ipaddressaptarchiveasiabrute forcecertchainchinacivil servicescloudcookiecredential harvestingcredential stuffingcritical_infrastructurecyber threatsdata exfiltrationdata store exposuredestdigital mediaeducational resourceseducational serviceseducational technologyenergyentertainment technologyeurope/asiaexploitation activityfinancefinancial servicesfirstgh0stgh0st ratgovernment technologyhigher educationhkhong konghuntidentity & access exploitationindiaindicatorindonesiainfectinfostealerinjection activityk-12 educationmalaysiamalicious softwaremalwaremedia & entertainmentmedia distributionmultimedia productionnetworknextnot nullphishingphishing attackportpowershellprocess injectionpublic administrationpublic infrastructurepublic policypythonpython stealerransomwareregulatory agenciesresearchedrmm toolsilver foxsocial engineeringsocradarsouth asiastreaming servicest1014t1016t1027t1036t1041t1055t1056.001t1059t1071t1071.001t1078t1082t1095t1105t1112t1113t1197t1204t1204.001t1204.002t1211t1218t1219t1486t1499.001t1543t1548t1564t1565t1566t1566.001t1566.002t1566.003taiwanthreat actortor nodetridentturkeyvalleyratwindows servicewinos

Activity Timeline

1 total obs
May 22May 22

Threat Activity Heatmap

· Peak: 2026-05-22
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Threat ScoreHigh Risk
77
SIGNAL
Signal Score
77%
Confidence
6
Reports
First seenMar 19, 2026
Last seenMay 22, 2026
GeolocationHK
CountryHong Kong
LocationSha Tin Wai, Hong Kong
ASNAS55933
OrgYISUHUTONG Network Technology Co., Ltd.
Coords22.2855, 114.1577

VirusTotal

Not checked

WHOIS

description
CC=CN ASN=AS55933 cloudie limited
raw
inetnum: 45.119.54.0 - 45.119.55.255 netname: CLOUD-YISUHUTONG descr: YISUHUTONG Network Technology Co., Ltd. country: HK admin-c: YNTC1-AP tech-c: YNTC1-AP abuse-c: AC2809-AP status: ALLOCATED NON-PORTABLE mnt-by: MAINT-CLOUD-YISUHUTONG mnt-irt: IRT-CLOUD-YISUHUTONG last-modified: 2024-08-03T00:30:52Z source: APNIC irt: IRT-CLOUD-YISUHUTONG address: Sha Tin Data Center e-mail: [email protected] abuse-mailbox: [email protected] admin-c: YNTC1-AP tech-c: YNTC1-AP auth: # Filtered remarks: [email protected] was validated on 2025-06-25 mnt-by: MAINT-CLOUD-YISUHUTONG last-modified: 2025-11-18T00:37:52Z source: APNIC role: ABUSE CLOUDYISUHUTONG country: ZZ address: Sha Tin Data Center phone: +000000000 e-mail: [email protected] admin-c: YNTC1-AP tech-c: YNTC1-AP nic-hdl: AC2809-AP remarks: Generated from irt object IRT-CLOUD-YISUHUTONG remarks: [email protected] was validated on 2025-06-25 abuse-mailbox: [email protected] mnt-by: APNIC-ABUSE last-modified: 2025-06-25T13:17:32Z source: APNIC role: YISUHUTONG Network Technology Co Ltd address: Sha Tin Data Center country: HK phone: +8653286635030 e-mail: [email protected] admin-c: QYSH1-AP tech-c: QYSH1-AP nic-hdl: YNTC1-AP mnt-by: MAINT-QYSHTNTCL-CN last-modified: 2024-08-23T11:28:34Z source: APNIC
references
IOCs.2026.pdf, https://blog.sekoia.io/silver-fox-the-only-tax-audit-where-the-fine-print-installs-malware/

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 2 months ago · Last seen 22 days ago
Appeared in 6 threat reports