IOC Radar
IPMediumSignal 100/100

47.212.206.136

Location
United StatesUnited States
Flagstaff, AZ
ASN
AS19108
Optimum
First Seen
Jan 9, 2025
Last Seen
Feb 12, 2026
Jan 9
First Seen
520d ago
Feb 12
Last Seen
120d ago
18
Reports
source reports
99%
Confidence
medium
Found in 18 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
99%
Signal Score
100 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

44 techniques

Network Information

CountryUSUnited States
RegionFlagstaff, AZ
ASNAS19108
OrganizationOptimum

Feed Intelligence Summary

18 reports99% confidence
18
Source reports
99%
Confidence score
Category tags
abuseaccess controlactive scanningaptarmattackbotnetbrute forcebrute force attackbrute force attemptc&cc2command and controlcommunication protocolcommunication technologiescompromised devicecompromised hostcompromised systemcowrie honeypotcredential accesscredential harvestingcredential stuffingctadata exfiltrationddosddos attacksdecoy systemdenial of servicedistributed attackselfexploit attemptsftp brute forcehackinghttp brute forceindicatorinfrastructure acquisitionreconnaissanceinternet of thingsintrusion detectioniociot botnetiot/ics attacklateral movementloginmalicious activitymalicious softwaremalwaremalware propagationmalware scanningmanualmirai botnetmobile carriersmobile networksmozinetworknetwork attacksnetwork intrusionnetwork probingnetwork scanningnetwork securitynetwork service scanningnetwork trafficnorth americapassword attacksphishing attackprocess injectionprotocol exploitationreconnaissanceremote accessremote servicesresearchedscanscannersecurity policysftp attacksmtp brute forcesocial engineeringsocradar honeypotsql injection attemptsssh attackssh monitoringt1003t1021t1021.001t1021.002t1040t1041t1046t1055t1059t1071t1071.001t1076t1078t1105t1110t1110.001t1110.002t1110.003t1110.004t1133t1187t1190t1199t1203t1210t1486t1496t1497t1499.001t1499.002t1499.003t1563t1565t1566t1566.001t1566.002t1566.003t1587.001t1588t1590.001t1595t1595.001t1595.002t1595.003tcp protocoltcp/23telecom servicestelecommunicationstelnet threatthreat actorthreat intelligencethreat preventionunauthorized accessunited statesunited states of americausweb application attackweb exploitation

Activity Timeline

1 total obs
Feb 12Feb 12

Threat Activity Heatmap

· Peak: 2026-02-12
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Threat ScoreHigh Risk
100
SIGNAL
Signal Score
99%
Confidence
18
Reports
First seenJan 9, 2025
Last seenFeb 12, 2026
GeolocationUS
CountryUnited States
LocationFlagstaff, AZ
ASNAS19108
OrgOptimum
Coords35.1872, -111.6596

VirusTotal

Not checked

WHOIS

raw
NetRange: 47.208.0.0 - 47.223.255.255 CIDR: 47.208.0.0/12 NetName: SUDDE NetHandle: NET-47-208-0-0-1 Parent: NET47 (NET-47-0-0-0-0) NetType: Direct Allocation OriginAS: Organization: Optimum (SUDDE) RegDate: 2015-09-08 Updated: 2015-09-08 Ref: https://rdap.arin.net/registry/ip/47.208.0.0 OrgName: Optimum OrgId: SUDDE Address: 311 NNW Loop 323 City: Tyler StateProv: TX PostalCode: 75701 Country: US RegDate: 2006-05-25 Updated: 2023-12-05 Ref: https://rdap.arin.net/registry/entity/SUDDE OrgAbuseHandle: ABUSE6997-ARIN OrgAbuseName: Abuse Suddenlink OrgAbusePhone: +1-903-266-4800 OrgAbuseEmail: [email protected] OrgAbuseRef: https://rdap.arin.net/registry/entity/ABUSE6997-ARIN OrgNOCHandle: NOCSU37-ARIN OrgNOCName: NOC Suddenlink OrgNOCPhone: +1-866-232-5455 OrgNOCEmail: [email protected] OrgNOCRef: https://rdap.arin.net/registry/entity/NOCSU37-ARIN OrgTechHandle: AUIO-ARIN OrgTechName: Altice USA Internet Operations OrgTechPhone: +1-516-803-2300 OrgTechEmail: [email protected] OrgTechRef: https://rdap.arin.net/registry/entity/AUIO-ARIN
references
https://malware-filter.gitlab.io/malware-filter/botnet-filter.txt, https://github.com/telekom-security/tpotce, https://raw.githubusercontent.com/ahamed-rizvan/IOCs/refs/heads/main/Malicous%20IP%20Address.txt

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 4 months ago
Appeared in 18 threat reports