IPMediumSignal 25/100
51.254.199.77
Location
Roubaix, Hauts-de-France
ASN
AS16276
OVH
First Seen
Jun 6, 2025
Last Seen
Jun 21, 2026
Found in 14 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
25%
Signal Score
25 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Network Information
Country
France
RegionRoubaix, Hauts-de-France
ASNAS16276
OrganizationOVH
Feed Intelligence Summary
14 reports25% confidence
14
Source reports
25%
Confidence score
Category tags
abuseaccess controlaccount brute forceactive scanactive scanningantispamapacheapache attackerapplication layer attackapplication layer protocolattackauthenticationauthentication attackbad reputationbad web botblog spambotnetbotnet activitybotnet activity detectionbrute forcebrute force attackbrute force attemptbrute force attemptsc2 communicationcisco attackcisco devicecisco device targetingcommand & controlcommand and controlcommunication protocolcompromised hostcowrie activitycowrie honeypotcredential accesscredential stuffingdata exfiltrationdata store exposuredatabase attackddosddos attackdecoy systemdenial of servicedevice managementdionaea capturedionaea honeypotdistributed attacksenterprise networkingeuropeexploitation activityexploited hostfinlandfrancehackingheralding behaviorhoneytrap honeypothttp brute forcehttp scanneridentity & access exploitationindicatorinformation technologyinjection activityiocircit infrastructurelamplamp attacklamp stack targetinglog4jloginlogin attacklogin pagemalicious activitymalicious network activitymalicious softwaremalwaremalware behaviourmalware capturemalware distributionnetworknetwork attacksnetwork infrastructurenetwork intrusionnetwork protocolnetwork scanningnetwork securitypassword attackpassword attacksphp brute forceprocess injectionreconnaissanceresearchedresource hijackingscannerscripting attacksscripting languagesecurity operationssecurity policysentrypeer botnetsentrypeer detectionsftp activitysftp attacksip brute forcesip scanningsoftware developmentspamssh attackssh monitoringt1021t1040t1041t1055t1059t1059.007t1071t1071.001t1078t1105t1110t1110.001t1110.002t1110.003t1110.004t1185t1190t1203t1204.002t1486t1496t1499.001t1499.002t1499.003t1565t1573t1588.004t1589t1595t1595.001t1595.002t1595.003targeting databasetcp protocoltelecommunicationsthreat actorthreat detectionthreat intelligencethreat preventiontor nodetpotcevoipvoip attackweb applicationweb application attackweb application exploitationweb attackweb developmentweb exploitationweb serverweb service attackweb spamweb traffic
Activity Timeline
Jun 21Jun 21
Threat Activity Heatmap
LessMore
Mon
Wed
Fri
24h
1
Minimal
7d
1
Minimal
30d
1
Minimal
3mo
1
Minimal
Threat ScoreLow Risk
25
SIGNAL
Signal Score
25%
Confidence
14
Reports
First seenJun 6, 2025
Last seenJun 21, 2026
GeolocationFR
CountryFrance
LocationRoubaix, Hauts-de-France
ASNAS16276
OrgOVH
Coords50.6924, 3.2011
VirusTotal
Not checked
WHOIS
- description
- Web related brute force IOCs collected mainly from hosts located in Finland
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 1 year ago · Last seen today
Appeared in 14 threat reports