IOC Radar
IPMediumSignal 100/100

45.160.125.255

Location
BrazilBrazil
Fortaleza, Ceará
ASN
AS264293
Smart Solucoes em Telecomunicacoes
First Seen
Jun 12, 2024
Last Seen
Mar 30, 2026
Jun 12
First Seen
732d ago
Mar 30
Last Seen
76d ago
18
Reports
source reports
99%
Confidence
medium
Found in 18 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
99%
Signal Score
100 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

52 techniques

Network Information

CountryBRBrazil
RegionFortaleza, Ceará
ASNAS264293
OrganizationSmart Solucoes em Telecomunicacoes

Feed Intelligence Summary

18 reports99% confidence
18
Source reports
99%
Confidence score
Category tags
abuseaccessaccess controlactive scanactive scanningapiattackauto-generated securitybad reputationbad web botbotnetbotnet activitybrbrazilbrute forcebrute force attackbrute force attemptc2cisco devicecommand & controlcommand and controlcommentcommunication protocolcompromised hostcowrie honeypotcredential accesscredential harvestingcredential stuffingctadata exfiltrationdata store exposureddosddos attackddos attacksddos preparationdecoy systemdevice managementdionaea honeypotdistributed attacksenterprise networkingexecutable fileexploitexploitation activityfattgroupshackinghoneytrap honeypothunteridentity & access exploitationindicatorinfected systeminfrastructure acquisitionreconnaissanceinitial accessinjection activityinternet of thingsintrusion detectioniociot botnetiot securityiot/ics attackkfsensor honeypotlamplateral movementloginmailoney honeypotmalicious activitymalicious ipmalicious network activitymalicious payloadmalicious softwaremalwaremalware behaviourmalware capturemanualmedia & entertainmentmiraimirai botnetnetworknetwork attacksnetwork infrastructurenetwork intrusionnetwork probingnetwork scanningnetwork securitynetwork service scanningnetwork traffic analysisnorth americap0fpassword attacksphishingphishing attackphishing trappngprocess injectionprotocol exploitationransomwarereconnaissanceremote accessremote service exploitationremote service interactionremote servicesresearchedresource developmentresource hijackingscanscannerscriptsecurity policysensor-taggedsentrypeer botnetserverservice scansftp attackslugsocial engineeringsocradar honeypotsouth americassh attackssh monitoringsurface webt1005t1016.001t1018t1021t1021.001t1021.002t1021.004t1040t1041t1046t1055t1056.001t1059t1059.001t1059.004t1068t1071t1071.001t1076t1078t1078.004t1110t1110.001t1110.002t1110.003t1110.004t1133t1189t1190t1195.002t1203t1486t1496t1497t1499.001t1499.002t1499.003t1563t1565t1566t1566.001t1566.002t1566.003t1566.004t1573t1573.001t1587.001t1590.001t1595t1595.001t1595.002t1595.003tannertcptcp protocoltcp/23telecommunicationstelnettelnet threatthreatthreat actorthreat detectionthreat intelligencethreat preventiontor nodetpotunauthorized accessunited statesvalid accountsvalidatorvoip attackvulnerabilityvulnerability scan

Activity Timeline

1 total obs
Mar 30Mar 30

Threat Activity Heatmap

· Peak: 2026-03-30
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreHigh Risk
100
SIGNAL
Signal Score
99%
Confidence
18
Reports
First seenJun 12, 2024
Last seenMar 30, 2026
GeolocationBR
CountryBrazil
LocationFortaleza, Ceará
ASNAS264293
OrgSmart Solucoes em Telecomunicacoes
Coords-3.7145, -38.5419

VirusTotal

Not checked

WHOIS

description
2025-05-02T10:08:34.945Z Honeypot : Cowrie : Source: 45.160.125.255 Data: New connection: 45.160.125.255:48776 (172.29.0.2:23) [session: 6de59e237ca3]
raw
Socket not responding: [Errno 111] Connection refused
references
https://malware-filter.gitlab.io/malware-filter/botnet-filter.txt, https://github.com/telekom-security/tpotce

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 2 years ago · Last seen 2 months ago
Appeared in 18 threat reports