IOC Radar
IPMediumSignal 0/100

52.5.18.208

Location
United StatesUnited States
Ashburn, Virginia
ASN
AS14618
AWS EC2 (us-east-1)
First Seen
Jan 12, 2026
Last Seen
Jan 14, 2026
Jan 12
First Seen
149d ago
Jan 14
Last Seen
147d ago
1
Reports
source reports
0%
Confidence
medium
Found in 1 report. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
0%
Signal Score
0 / 100
IDS Rule
No
Threat Context
Tags

Network Information

CountryUSUnited States
RegionAshburn, Virginia
ASNAS14618
OrganizationAWS EC2 (us-east-1)

Feed Intelligence Summary

1 report0% confidence
1
Source reports
0%
Confidence score
Category tags
indicatornetworkresearched

Activity Timeline

1 total obs
Jan 14Jan 14

Threat Activity Heatmap

· Peak: 2026-01-14
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Intelligence SummaryAI Generated

This indicator of compromise (IOC), an IPv4 address identified as `52.5.18.208`, has been explicitly whitelisted and assigned a risk score of 0.0, indicating it is currently considered benign and poses no immediate threat to organizational security. Its initial inclusion in threat intelligence feeds, specifically Abuse.ch-ThreatFox-C&Cs, which typically flags Command and Control (C2) infrastructure, was subsequently superseded by its whitelisted status from the Appealer Whitelist Service. This c…

Threat ScoreLow Risk
0
SIGNAL
Signal Score
0%
Confidence
1
Reports
First seenJan 12, 2026
Last seenJan 14, 2026
GeolocationUS
CountryUnited States
LocationAshburn, Virginia
ASNAS14618
OrgAWS EC2 (us-east-1)
Coords39.0438, -77.4874

VirusTotal

Not checked

WHOIS

description
ip:port combination that is used for botnet Command&control (C&C)

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 4 months ago · Last seen 4 months ago
Appeared in 1 threat report