IOC Radar
IPMediumSignal 99/100

81.215.130.142

Location
TürkiyeTürkiye
Bolu, Bolu
ASN
AS9121
TurkTelecom
First Seen
Jan 31, 2025
Last Seen
Feb 3, 2026
Jan 31
First Seen
507d ago
Feb 3
Last Seen
139d ago
9
Reports
source reports
99%
Confidence
medium
Found in 9 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
99%
Signal Score
99 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

30 techniques

Network Information

CountryTRTürkiye
RegionBolu, Bolu
ASNAS9121
OrganizationTurkTelecom

Feed Intelligence Summary

9 reports99% confidence
9
Source reports
99%
Confidence score
Category tags
abuseaccessactive scanningattackbotnetbrute forcecommand and controlcommunication protocolconnectcowriecowrie honeypotcredential accesscredential harvestingcredential stuffingctadata exfiltrationdecoy systemdionaeadionaea honeypotdistributed attacksemaileurope/asiaftp brute forcegroupshoneytrap honeypotindicatorlamplamp exploitation attemptsmailoney honeypotmalicious activitymalicious softwaremalwaremalware behaviourmalware capturenetworknetwork scanningnetwork securitynorth americaphishingphishing attackphishing trappotential malware distributionprocess injectionprotocol exploitationreconnaissanceresearchedresource hijackingscannerscriptsentrypeer botnetsftpsftp attacksipsip brute forcesip scanningslugsmtp brute forcesocial engineeringsshssh attackssh monitoringsurface webt1016t1018t1021t1040t1041t1046t1053t1055t1059t1071.001t1078t1110t1110.002t1190t1486t1496t1499.001t1499.002t1499.003t1565t1566.001t1566.002t1566.003t1566.004t1583t1588t1595t1595.001t1595.002t1595.003tcptelecommunicationstelnet threatthreat actorthreat detectionthreat intelligencetrturkeyunited statesvoipvoip attack

Activity Timeline

1 total obs
Feb 3Feb 3

Threat Activity Heatmap

· Peak: 2026-02-03
Less
More
Mon
Wed
Fri
Jun
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Threat ScoreHigh Risk
99
SIGNAL
Signal Score
99%
Confidence
9
Reports
First seenJan 31, 2025
Last seenFeb 3, 2026
GeolocationTR
CountryTürkiye
LocationBolu, Bolu
ASNAS9121
OrgTurkTelecom
Coords40.8049, 31.6062

VirusTotal

Not checked

WHOIS

description
2025-02-07T22:54:42.313Z Honeypot : Dionaea : Source: 81.215.130.142 : Port: 1433 Connection: {'protocol': 'mssqld', 'type': 'accept', 'transport': 'tcp'}
raw
inetnum: 81.215.128.0 - 81.215.143.255 netname: TurkTelekom descr: ADSL-MET-Acibadem-Dynamic Pool country: tr admin-c: TTBA1-RIPE tech-c: TTBA1-RIPE status: ASSIGNED PA mnt-by: as9121-mnt created: 2005-04-25T09:02:02Z last-modified: 2005-04-25T09:02:02Z source: RIPE # Filtered role: TT Administrative Contact Role address: Turk Telekomunikasyon A.S Turgut Ozal Blv. Aydinlikevler address: 06103 ANKARA TURKEY phone: +90 312 555 0000 fax-no: +90 312 313 1924 admin-c: BADB3-RIPE abuse-mailbox: [email protected] tech-c: BADB3-RIPE tech-c: BADB3-RIPE tech-c: BADB3-RIPE nic-hdl: TTBA1-RIPE mnt-by: AS9121-MNT created: 2002-02-28T12:22:28Z last-modified: 2022-01-28T07:15:56Z source: RIPE # Filtered route: 81.215.128.0/17 descr: TurkTelecom origin: AS9121 mnt-by: AS9121-MNT created: 2004-04-05T11:15:15Z last-modified: 2004-09-27T07:39:04Z source: RIPE
references
https://github.com/telekom-security/tpotce

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 4 months ago
Appeared in 9 threat reports