IPMediumSignal 0/100
52.5.18.208
Location
Ashburn, Virginia
ASN
AS14618
AWS EC2 (us-east-1)
First Seen
Jan 12, 2026
Last Seen
Jan 14, 2026
Found in 1 report. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
0%
Signal Score
0 / 100
IDS Rule
No
Threat Context
Tags
Network Information
Country
United States
RegionAshburn, Virginia
ASNAS14618
OrganizationAWS EC2 (us-east-1)
Feed Intelligence Summary
1 report0% confidence
1
Source reports
0%
Confidence score
Category tags
indicatornetworkresearched
Activity Timeline
Jan 14Jan 14
Threat Activity Heatmap
· Peak: 2026-01-14LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Intelligence SummaryAI Generated
This indicator of compromise (IOC), an IPv4 address identified as `52.5.18.208`, has been explicitly whitelisted and assigned a risk score of 0.0, indicating it is currently considered benign and poses no immediate threat to organizational security. Its initial inclusion in threat intelligence feeds, specifically Abuse.ch-ThreatFox-C&Cs, which typically flags Command and Control (C2) infrastructure, was subsequently superseded by its whitelisted status from the Appealer Whitelist Service. This c…
Threat ScoreLow Risk
0
SIGNAL
Signal Score
0%
Confidence
1
Reports
First seenJan 12, 2026
Last seenJan 14, 2026
GeolocationUS
CountryUnited States
LocationAshburn, Virginia
ASNAS14618
OrgAWS EC2 (us-east-1)
Coords39.0438, -77.4874
VirusTotal
Not checked
WHOIS
- description
- ip:port combination that is used for botnet Command&control (C&C)
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 4 months ago · Last seen 4 months ago
Appeared in 1 threat report