IOC Radar
IPMediumSignal 0/100

51.15.59.15

Location
NetherlandsNetherlands
Haarlem, NH
ASN
AS12876
Online SAS NL
First Seen
Sep 7, 2020
Last Seen
Jun 12, 2026
Sep 7
First Seen
2104d ago
Jun 12
Last Seen
today
2
Reports
source reports
0%
Confidence
medium
Found in 2 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
0%
Signal Score
0 / 100
IDS Rule
No
Threat Context
Tags

Network Information

CountryNLNetherlands
RegionHaarlem, NH
ASNAS12876
OrganizationOnline SAS NL

Feed Intelligence Summary

2 reports0% confidence
2
Source reports
0%
Confidence score
Category tags
networkproxyresearched

Activity Timeline

1 total obs
Jun 12Jun 12

Threat Activity Heatmap

Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
1
Minimal
30d
1
Minimal
3mo
1
Minimal
Threat ScoreLow Risk
0
SIGNAL
Signal Score
0%
Confidence
2
Reports
First seenSep 7, 2020
Last seenJun 12, 2026
GeolocationNL
CountryNetherlands
LocationHaarlem, NH
ASNAS12876
OrgOnline SAS NL
Coords52.3803, 4.6422

VirusTotal

Not checked

WHOIS

description
Anonymization_Network indicators. Date: Apr 8, 2026. Part 1/5. For more threat intelligence visit https://ltna.com.au/cyber
raw
inetnum: 51.15.0.0 - 51.15.63.255 org: ORG-ONLI2-RIPE netname: ONLINE_NET_DEDICATED_SERVERS_NL country: NL admin-c: MM42047-RIPE tech-c: MM42047-RIPE status: LEGACY mnt-by: ONLINESAS-MNT created: 2016-10-28T11:18:17Z last-modified: 2016-10-28T11:19:00Z source: RIPE organisation: ORG-ONLI2-RIPE org-name: ONLINE SAS NL org-type: OTHER address: ONLINE SAS NL, EvoSwitch AMS1, J.W. Lucasweg 35 2031 BE Haarlem abuse-c: AR32851-RIPE mnt-ref: ONLINESAS-MNT mnt-by: ONLINESAS-MNT created: 2016-05-13T10:41:40Z last-modified: 2016-05-13T10:41:40Z source: RIPE # Filtered person: Mickael Marchand address: 8 rue de la ville l'eveque 75008 PARIS phone: +33173502000 nic-hdl: MM42047-RIPE mnt-by: MMA-MNT created: 2015-07-10T15:02:32Z last-modified: 2016-02-23T12:43:25Z source: RIPE # Filtered route: 51.15.0.0/17 descr: SCALEWAY descr: Amsterdam, Netherlands origin: AS12876 mnt-by: MNT-TISCALIFR mnt-by: ONLINE-NET-MNT created: 2019-10-03T15:11:06Z last-modified: 2022-05-03T10:05:58Z source: RIPE
references
https://github.com/telekom-security/tpotce, https://raw.githubusercontent.com/platformbuilds/Tor-IP-Addresses/refs/heads/master/tor-exit-nodes.lst, https://check.torproject.org/torbulkexitlist, https://github.com/borestad/blocklist-abuseipdb/blob/main/abuseipdb-s100-3d.ipv4, https://www.bleepingcomputer.com/news/security/cisco-warns-of-large-scale-brute-force-attacks-against-vpn-services/, https://raw.githubusercontent.com/Cisco-Talos/IOCs/main/2024/04/coralraider-targets-socialmedia-accounts.txt, https://raw.githubusercontent.com/Cisco-Talos/IOCs/main/2024/04/large-scale-brute-force-activity-targeting-vpns-ssh-services-with-commonly-used-login-credentials.txt, https://raw.githubusercontent.com/Cisco-Talos/IOCs/main/2024/04/offlrouter-virus-causes-upload-confidential-documents-to-virustotal.txt, https://raw.githubusercontent.com/Cisco-Talos/IOCs/main/2024/04/starry-addax.txt

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 5 years ago · Last seen today
Appeared in 2 threat reports