IPMediumSignal 64/100
8.222.234.18
Location
Singapore, North West
ASN
AS45102
Alibaba.com Singapore E-Commerce Private Limited
First Seen
Sep 28, 2024
Last Seen
Feb 9, 2026
Found in 9 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
64%
Signal Score
64 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Network Information
Country
Singapore
RegionSingapore, North West
ASNAS45102
OrganizationAlibaba.com Singapore E-Commerce Private Limited
Feed Intelligence Summary
9 reports64% confidence
9
Source reports
64%
Confidence score
Category tags
abuseactive scanningasiaatif feedaustraliaauthenticationbanlist feedbinary defensebotnetbrute forcebrute force attemptclosed portcommand and controlcommunication protocolcredential accesscredential stuffingdata exfiltrationdistributed attacksexternal network scanexternal reconnaissancefiltered portindicatorinformation gatheringmalicious activitymalicious softwaremalwarenetworknetwork attacksnetwork discoverynetwork probingnetwork reconnaissancenetwork scanningoceaniaopen portpossible vulnerability assessmentpotential vulnerability scanpotential vulnerability scanningprocess injectionreconnaissanceremote accessresearchedscannerservice discoverysgsingaporessh attackstealtht1016t1018t1021.004t1040t1046t1055t1071.001t1078t1083t1110t1110.001t1110.002t1190t1210t1486t1496t1499.002t1499.003t1565t1589t1595t1595.001t1595.002t1595.003tcp protocolthreat actorunknown port
Activity Timeline
Feb 9Feb 9
Threat Activity Heatmap
· Peak: 2026-02-09LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Threat ScoreMedium Risk
64
SIGNAL
Signal Score
64%
Confidence
9
Reports
First seenSep 28, 2024
Last seenFeb 9, 2026
GeolocationSG
CountrySingapore
LocationSingapore, North West
ASNAS45102
OrgAlibaba.com Singapore E-Commerce Private Limited
Coords1.3673, 103.8014
VirusTotal
Not checked
WHOIS
- description
- Host scanning unknown application ports (Web, SMB, SSH, TELNET, ... are in other pulses). Details in pulse
- references
- https://redpiranha.net, https://blocklist.greensnow.co/greensnow.txt, https://www.binarydefense.com/banlist.txt, https://lists.blocklist.de/lists/all.txt, https://rules.emergingthreats.net/blockrules/compromised-ips.txt
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 1 year ago · Last seen 4 months ago
Appeared in 9 threat reports