IOC Radar
IPMediumSignal 25/100

51.254.199.77

Location
FranceFrance
Roubaix, Hauts-de-France
ASN
AS16276
OVH
First Seen
Jun 6, 2025
Last Seen
Jun 21, 2026
Jun 6
First Seen
379d ago
Jun 21
Last Seen
today
14
Reports
source reports
25%
Confidence
medium
Found in 14 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
25%
Signal Score
25 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

32 techniques

Network Information

CountryFRFrance
RegionRoubaix, Hauts-de-France
ASNAS16276
OrganizationOVH

Feed Intelligence Summary

14 reports25% confidence
14
Source reports
25%
Confidence score
Category tags
abuseaccess controlaccount brute forceactive scanactive scanningantispamapacheapache attackerapplication layer attackapplication layer protocolattackauthenticationauthentication attackbad reputationbad web botblog spambotnetbotnet activitybotnet activity detectionbrute forcebrute force attackbrute force attemptbrute force attemptsc2 communicationcisco attackcisco devicecisco device targetingcommand & controlcommand and controlcommunication protocolcompromised hostcowrie activitycowrie honeypotcredential accesscredential stuffingdata exfiltrationdata store exposuredatabase attackddosddos attackdecoy systemdenial of servicedevice managementdionaea capturedionaea honeypotdistributed attacksenterprise networkingeuropeexploitation activityexploited hostfinlandfrancehackingheralding behaviorhoneytrap honeypothttp brute forcehttp scanneridentity & access exploitationindicatorinformation technologyinjection activityiocircit infrastructurelamplamp attacklamp stack targetinglog4jloginlogin attacklogin pagemalicious activitymalicious network activitymalicious softwaremalwaremalware behaviourmalware capturemalware distributionnetworknetwork attacksnetwork infrastructurenetwork intrusionnetwork protocolnetwork scanningnetwork securitypassword attackpassword attacksphp brute forceprocess injectionreconnaissanceresearchedresource hijackingscannerscripting attacksscripting languagesecurity operationssecurity policysentrypeer botnetsentrypeer detectionsftp activitysftp attacksip brute forcesip scanningsoftware developmentspamssh attackssh monitoringt1021t1040t1041t1055t1059t1059.007t1071t1071.001t1078t1105t1110t1110.001t1110.002t1110.003t1110.004t1185t1190t1203t1204.002t1486t1496t1499.001t1499.002t1499.003t1565t1573t1588.004t1589t1595t1595.001t1595.002t1595.003targeting databasetcp protocoltelecommunicationsthreat actorthreat detectionthreat intelligencethreat preventiontor nodetpotcevoipvoip attackweb applicationweb application attackweb application exploitationweb attackweb developmentweb exploitationweb serverweb service attackweb spamweb traffic

Activity Timeline

1 total obs
Jun 21Jun 21

Threat Activity Heatmap

Less
More
Mon
Wed
Fri
Jun
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
24h
1
Minimal
7d
1
Minimal
30d
1
Minimal
3mo
1
Minimal
Threat ScoreLow Risk
25
SIGNAL
Signal Score
25%
Confidence
14
Reports
First seenJun 6, 2025
Last seenJun 21, 2026
GeolocationFR
CountryFrance
LocationRoubaix, Hauts-de-France
ASNAS16276
OrgOVH
Coords50.6924, 3.2011

VirusTotal

Not checked

WHOIS

description
Web related brute force IOCs collected mainly from hosts located in Finland

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen today
Appeared in 14 threat reports