IPMediumSignal 99/100
81.215.130.142
Location
Bolu, Bolu
ASN
AS9121
TurkTelecom
First Seen
Jan 31, 2025
Last Seen
Feb 3, 2026
Found in 9 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
99%
Signal Score
99 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Network Information
Country
Türkiye
RegionBolu, Bolu
ASNAS9121
OrganizationTurkTelecom
Feed Intelligence Summary
9 reports99% confidence
9
Source reports
99%
Confidence score
Category tags
abuseaccessactive scanningattackbotnetbrute forcecommand and controlcommunication protocolconnectcowriecowrie honeypotcredential accesscredential harvestingcredential stuffingctadata exfiltrationdecoy systemdionaeadionaea honeypotdistributed attacksemaileurope/asiaftp brute forcegroupshoneytrap honeypotindicatorlamplamp exploitation attemptsmailoney honeypotmalicious activitymalicious softwaremalwaremalware behaviourmalware capturenetworknetwork scanningnetwork securitynorth americaphishingphishing attackphishing trappotential malware distributionprocess injectionprotocol exploitationreconnaissanceresearchedresource hijackingscannerscriptsentrypeer botnetsftpsftp attacksipsip brute forcesip scanningslugsmtp brute forcesocial engineeringsshssh attackssh monitoringsurface webt1016t1018t1021t1040t1041t1046t1053t1055t1059t1071.001t1078t1110t1110.002t1190t1486t1496t1499.001t1499.002t1499.003t1565t1566.001t1566.002t1566.003t1566.004t1583t1588t1595t1595.001t1595.002t1595.003tcptelecommunicationstelnet threatthreat actorthreat detectionthreat intelligencetrturkeyunited statesvoipvoip attack
Activity Timeline
Feb 3Feb 3
Threat Activity Heatmap
· Peak: 2026-02-03LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Threat ScoreHigh Risk
99
SIGNAL
Signal Score
99%
Confidence
9
Reports
First seenJan 31, 2025
Last seenFeb 3, 2026
GeolocationTR
CountryTürkiye
LocationBolu, Bolu
ASNAS9121
OrgTurkTelecom
Coords40.8049, 31.6062
VirusTotal
Not checked
WHOIS
- description
- 2025-02-07T22:54:42.313Z Honeypot : Dionaea : Source: 81.215.130.142 : Port: 1433 Connection: {'protocol': 'mssqld', 'type': 'accept', 'transport': 'tcp'}
- raw
- inetnum: 81.215.128.0 - 81.215.143.255 netname: TurkTelekom descr: ADSL-MET-Acibadem-Dynamic Pool country: tr admin-c: TTBA1-RIPE tech-c: TTBA1-RIPE status: ASSIGNED PA mnt-by: as9121-mnt created: 2005-04-25T09:02:02Z last-modified: 2005-04-25T09:02:02Z source: RIPE # Filtered role: TT Administrative Contact Role address: Turk Telekomunikasyon A.S Turgut Ozal Blv. Aydinlikevler address: 06103 ANKARA TURKEY phone: +90 312 555 0000 fax-no: +90 312 313 1924 admin-c: BADB3-RIPE abuse-mailbox: [email protected] tech-c: BADB3-RIPE tech-c: BADB3-RIPE tech-c: BADB3-RIPE nic-hdl: TTBA1-RIPE mnt-by: AS9121-MNT created: 2002-02-28T12:22:28Z last-modified: 2022-01-28T07:15:56Z source: RIPE # Filtered route: 81.215.128.0/17 descr: TurkTelecom origin: AS9121 mnt-by: AS9121-MNT created: 2004-04-05T11:15:15Z last-modified: 2004-09-27T07:39:04Z source: RIPE
- references
- https://github.com/telekom-security/tpotce
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 1 year ago · Last seen 4 months ago
Appeared in 9 threat reports