IOC Radar
IPMediumSignal 57/100

45.138.74.238

Location
FinlandFinland
Helsinki, Uusimaa
ASN
AS204339
First Server Limited
First Seen
Sep 18, 2022
Last Seen
Jun 3, 2026
Sep 18
First Seen
1360d ago
Jun 3
Last Seen
7d ago
9
Reports
source reports
57%
Confidence
medium
Found in 9 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
57%
Signal Score
57 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

76 techniques

Network Information

CountryFIFinland
RegionHelsinki, Uusimaa
ASNAS204339
OrganizationFirst Server Limited

Feed Intelligence Summary

9 reports57% confidence
9
Source reports
57%
Confidence score
Category tags
abuseaccount compromiseacr stealeraddressaerospace & defenseaitm serverakira ransomwareamos steakeramos stealeranna paulaanydesk moduleaptapt-k-47apt36apt43archive fileastral stealerasyncrat reloadedatomic httpsatomic stealeraustriaautoitautoit malwareavast-anti-root-kitbabbleloaderbackdoorbadpilot campaignbanshee infostealerbcttbeaconing behaviorbha006bitter aptblockboinc c2bootkitty iocsbotnetbotnet communicationbrazanbamboo c2brazenbamboobugsleep malwarebumblebee malwareburnsratburnsrat cc2c2 addressc2 domainc2 httpc2 httpsc2 ipc2 ip addressc2 serverc2 serverscertcheat enginechristmas-themed lnk fileschrome extensions hijackedcivil servicesclickfix-tacticclinical researchcloudcloud atlascloud computingcloud migrationcloud securitycloud servicescloud storagecloudscout_evasive pandacnc servercobalt strikecode executioncode injectioncode issuescode snippetscometlogger-0.1command and controlcommand executioncommunication protocolcompiled autoit malwarecompromise notecompromised hostcontagious interviewcorporate lawcredential accesscredential harvestingcredential theftcrowdstrike outage exploitcrypto cybercthulhu stealercyber threatcyber threatscyberespionage campaigndamndarkgatedarkracedatadata encryptiondata exfiltrationdatabase securitydecoy systemdefanged filedefencedefensedefense contractingdefense logisticsdefense systemsdefense technologydemodex rootkitdetailsdigital signaturedistributed attacksdlldonexdownload urldownloaderdropperdrug developmentdrug manufacturingduoyieagerbee backdooreldoradoeldorado ransomwareelfenergyenergy distributionespionage campaigneuropeeurope/asiaevasive pandaexploitextortionfake captchafake chromefake discount sitesfake game sitesfatalratferret malwarefifilefilesfinaldraft elffinaldraft malwarefinancefinancial servicesfindfingerprintfinlandfirefoxfirstfirst seenfirst stagefooterfreelance developer scamfrom emailgamacopy aptgamaredongh0stratghostgambitghostsocksgithubgithub usersglove-stealergmergoogle ads heistgoogle meetgovernment technologyguidloaderhasheshashes payloadhawkeye malwareheadershealthcare innovationhelldown linuxhelldown ransomwarehidden rootkithornshorns-hooveshtahta filehta md5hta scripthtmlhtml payloadhttp attackhttp scannericonindicatorindicatortypeinformation stealersinformation technologyinfrastructure acquisitionreconnaissanceingress tool transferinitial accessinjection attacksintellectual property lawinvisibleferret malwareiociocsiocs filesiocs hashiocs helldowniocs maliciousiocs zipips httpsipv4ipv4 addressit infrastructurejs downloadl fileslandinglatin americalaw practicelegal consultinglegal researchlegal serviceslegal technologylegionloader malwarelinkslinuxlnklnk fileloaderlockbitlockbit ransomwarelockbit3lumma payloadlumma stealermacma malwaremalicious linksmalicious powershell activitymalicious softwaremallox ransomwaremalspam emailmalwaremalware c2malware callbackmalware deliverymalware hashmalware signingmalware trafficmd5medical researchmekotio bankingmekotio banking trojanmgbot malwaremicrosoft advertisers phishedmilitary operationsmintsloadermintsloader c2mintsloader_stealcmirrorface campaignmirrorface campainmlpeamoneromonitormsimsi filemulti-cloud managementmut-1244-githubna majesticna starknational securityneshtanetsupport ratnetworknetwork intrusionnetwork ipnoneuclid ratnoopdoor malwarenoopldr type1noopldr type2oil & gasoperating systemopswat oesisottercookie contagious interviewottercookie malwarepanelpathloaderpayloadpayload hostpayload urlpharmaceutical and medicine manufacturingpharmaceutical supply chainphishingphishing attackphishing urlsphobosphobos ransomwarephpsertphpsert variantplay ransomwarepluginplugxplugx c2plugx malwareportspower generationpower systemspowershower c2privilege-escalationprocess injectionpscppsexecpublicpublic administrationpublic infrastructurepublic policypullpumakitpurecrypterpxa stealerpypi-aiocpapythonpython malwarepython nodestealerpython-based backdoorqilin ransomwarequite solsjoasquocransomransomhubransomwareransomware-lockbit3-iocs.csvratrat racercerdpwrapper abusereddelta c2redditref5961ref5961 groupregistry keysregulatory agenciesregulatory complianceremcos trojanremote accessremote code executionremote servicesrenewable energyresearchedreverse shell activityrhadamanthys c2rockstar-phishingromcomromcom backdoorromcom exploitsromcom-exploitsrspackrspack_compromised_packagesrussiarussian aptrustystealersalt typhoonsample sha256samplessandbox-escapescripting attackssearchseashell blizzardsectopratseenseo abuseserver httpserversservice dllsftp attackshadowroot ransomwareshell commandssilent lynx aptsilent skimmersimilar sha256sitesitessliver implantsmokeloadersnailresin attacksnake keyloggersneaky 2fasocial engineeringsoftware developmentsoftware exploitationsoftware integritysolana-backdoorsolo airfieldssh accessstarstar blizzardstar blizzard spear-phishingstealcstealc c2stealc payloadstealerstealerssteelfox trojanstrike loadersstrongstudio codesystem disruptionsystembcsystembc ratt1001t1001.001t1003t1003.001t1005t1021.001t1021.004t1027t1027.002t1041t1053t1053.005t1055t1059t1059.001t1059.003t1059.005t1068t1069.001t1070t1070.001t1070.004t1071t1071.001t1071.004t1078t1078.002t1082t1083t1086t1095t1105t1110.002t1114t1114.001t1133t1140t1176t1189t1190t1195t1195.002t1199t1203t1204t1204.001t1204.002t1213t1213.003t1486t1490t1496t1499.001t1499.002t1499.003t1547t1547.001t1554.001t1554.003t1555t1555.003t1565t1566t1566.001t1566.002t1566.003t1566.004t1568t1568.002t1569.002t1573t1573.001t1587.001t1590.001t1598t1598.003tag-100tailscale abusethreat intelligencetimetls certificatetokentrojan malwaretrojanizedtrojanspytsecturkeytype nameu.s. organization targeteduac-0185uac-0194urlsurls httpurls httpsv4 removalvalleyrat malwarevantvbshower c2versionversion bversion cversion dversion evgod ransomwareviewvisual studiovisual studio codevssadmin deletevulnerabilityweaponized softwareweb securityweb trafficwebflow abusewezrat malwarewindows payloadwinos4.0 ratwinrarwolfsbane backdoorymir ransomwarezebo-0.1.0zero-day vulnerability exploitationzip archivezipmsi

Activity Timeline

1 total obs
Jun 3Jun 3

Threat Activity Heatmap

· Peak: 2026-06-03
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Threat ScoreMedium Risk
57
SIGNAL
Signal Score
57%
Confidence
9
Reports
First seenSep 18, 2022
Last seenJun 3, 2026
GeolocationFI
CountryFinland
LocationHelsinki, Uusimaa
ASNAS204339
OrgFirst Server Limited
Coords60.1699, 24.9384

VirusTotal

Not checked

WHOIS

description
CC=RU ASN=ASNone
raw
Socket not responding: timed out
references
https://www.welivesecurity.com/en/eset-research/romcom-exploits-firefox-and-windows-zero-days-in-the-wild/, Bootkitty, Glove-Stealer, Fake Discount Sites Exploit Black Friday, Helldown Ransomware, HawkEye Malware, PXA Stealer, Iranian Hackers Use GitHub and Phishing to Evade Detection in SnailResin Attack, BrazenBamboo, SpyGlace, RustyStealer and New Ymir Ransomware, PyPI-AIOCPA, Python NodeStealer, romcom-exploits-firefox-and-windows, Rockstar-Phishing, Silent Skimmer Gets Loud (Again), SteelFox Trojan, WezRat Malware, Avast-Anti-Root-KIt, Winos4.0 RAT, APT36, WolfsBane Backdoor, APT-K-47, Remcos RAT, babbleloader, Bitter APT, UAC-0194’s Exploitation of CVE-2024-43451 in Ukraine for Phishing, CloudScout_ Evasive Panda scouting cloud services, clickfix-tactic, Akira Ransomware, Bumblebee Malware, ELDORADO RANSOMWARE, Evasive Panda Uses MACMA and MgBot Malware to Target US and Taiwan, Demodex rootkit, BugSleep Malware, HotPage.exe (malware), Qilin Ransomware, NOOPDOOR Malware, Shadowroot Ransomware, play ransomware, MALLOX RANSOMWARE, New Malware Campaign Abusing RDPWrapper and Tailscale to Target Cryptocurrency Users, ACR Stealer, Suspicious Domains Exploiting the Recent CrowdStrike Outage!, Gh0stGambit, MEKOTIO BANKING TROJAN, TAG-100, Fake game sites lead to information stealers, Chrome Extensions Hijacked, 2.6 Million Users Impacted, macOS Users Targeted by the New Variant of Banshee Infostealer, Hundreds of fake Reddit sites push Lumma Stealer malware, GamaCopy APT Group Mimicking GamaRedon, InvisibleFerret Malware Leveraging Python for Targeted Attacks, Fake CAPTCHA Campaign That Spreads LUMMA Info Stealer, REF5961 Group Deploys EAGERBEE Backdoor Against Critical Sectors, Phishing Campaigns Fuel Compiled AutoIt Malware Distribution, The great Google Ads heist_ criminals ransack advertiser accounts via fake Google ads, New Star Blizzard spear-phishing campaign targets WhatsApp accounts, RansomHub Affiliate leverages Python-based backdoor, Sliver Implant Targets German Entities with DLL Sideloading and Proxying Techniques, Advanced Evasion Techniques Used by NonEuclid RAT, The Return of PlugX Malware with Fresh Tricks, The Growing Risk of Sneaky 2FA for Microsoft and Gmail Accounts, Weaponized Software Targeting Chinese Organizations, Threat Surge as Lumma Stealer Expands Its Reach, Chinese State-Sponsored RedDelta Targeted Taiwan, Mongolia, and Southeast Asia with Adapted PlugX Infection Chain, MintsLoader_Stealc, North Korean APT43 Uses PowerShell and Dropbox in Targeted South Korea Cyberattacks, North Korean Hackers Target Freelance Developers in Job Scam to Deploy Malware, Rat Race_ ValleyRAT Malware Targets Organizations with New Delivery Techniques, Salt Typhoon Target U.S. Telecom Networks, SecTopRAT, Stealers on the Rise, Snake Keylogger, AsyncRAT Reloaded, The BadPilot campaign_ Seashell Blizzard subgroup conducts multiyear global access operation, FatalRAT, SystemBC RAT Poses New Risks to Linux System, Unveiling Silent Lynx APT Targeting Entities Across Kyrgyzstan & Neighbouring Nations, FERRET Malware Targets macOS in Sophisticated North Korean Attacks, Espionage Campaign Targeting South Asian Entities, Astral Stealer Strikes Again Stealing More Than Just Your Cookies, The New Ransomware Menace Vgod Gains Momentum, Microsoft Advertisers Phished via Malicious Google Ads, LegionLoader Malware Expands Global Reach, NEW.txt, From Stealers to Ransomware PureCrypter Delivers It All, New Phishing Campaign Abuses Webflow, SEO, and Fake CAPTCHAs, FINALDRAFT Malware Exploits Microsoft Graph API for Espionage on Windows and Linux, LockBit Ransomware Attack Leveraging Cobalt Strike, Rspack_Compromised_Packages, SmokeLoader, Sock5Systemz-PROXY-AM, solana-backdoor, U.S. Organization in China Targeted by Attackers, UAC-0185 attacks warned by CERT-UA, BellaCpp, bootkitty(logofail), Visual Studio Code Remote tunnels, Cloud Atlas seen using a new tool in its attacks, Christmas-Themed LNK Files Used for Malware Delivery, DarkGate, MirrorFace Campain, horns-hooves, Developers Targeted by New ‘OtterCookie’ Malware with Fake Job Offers, NetSupport RAT and BurnsRAT, Cybercriminals Leverage Fake CAPTCHAs for Malware Delivery, MUT-1244-GitHub, Phobos ransomware, Python Malware in Zebo-0.1.0 and Cometlogger-0.1 Found Stealing User Data, PUMAKIT, OtterCookie used by Contagious Interview, Ransomware-Lockbit3-IOCs.csv, 2021-09-21-Curriculo-IOCs.txt

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 3 years ago · Last seen 7 days ago
Appeared in 9 threat reports