IPHighVerifiedSignal 88/100
84.21.189.225
Location
Frankfurt am Main, Hesse
ASN
AS213702
Qwins LTD
First Seen
Jun 2, 2026
Last Seen
Jun 6, 2026
Jun 2
First Seen
3d ago
Jun 6
Last Seen
today
76
Reports
source reports
95%
Confidence
high
15/91
VirusTotal
detections
Found in 76 reports. Confidence: high. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
95%
Signal Score
88 / 100
IDS Rule
Yes
Threat Context
Network Information
Country
Germany
RegionFrankfurt am Main, Hesse
ASNAS213702
OrganizationQwins LTD
IP Category
⟲
Proxy
Proxy server
Feed Intelligence Summary
76 reports95% confidence
Activity Timeline
Jun 6Jun 2
Threat Activity Heatmap
LessMore
Mon
Wed
Fri
24h
13
Elevated
7d
76
Critical
30d
76
Critical
3mo
76
Critical
Threat ScoreHigh Risk
88
SIGNAL
Signal Score
95%
Confidence
76
Reports
First seenJun 2, 2026
Last seenJun 6, 2026
Verified IOC
GeolocationDE
CountryGermany
LocationFrankfurt am Main, Hesse
ASNAS213702
OrgQwins LTD
Coords50.1169, 8.6837
Proxy
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
highFirst detected 3 days ago · Last seen today
Appeared in 76 threat reports from 10 sources
Associated with: Sandworm, LockBit
Used by malware: Vidar, Rhadamanthys, Pegasus, Lumma, NetWire, Mozi, SocGholish, XMRig, Remcos, Rhysida, XorDDoS, Nanocore, Stealc, Mirai, LockBit, Sliver, XWorm, Havoc, AsyncRAT