IOC Radar
IPMediumSignal 53/100

84.54.180.228

Location
BulgariaBulgaria
Burgas, 02
ASN
AS29084
Comnet Bulgaria Holding Ltd.
First Seen
May 29, 2025
Last Seen
Feb 4, 2026
May 29
First Seen
393d ago
Feb 4
Last Seen
141d ago
8
Reports
source reports
53%
Confidence
medium
Found in 8 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
53%
Signal Score
53 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

29 techniques

Network Information

CountryBGBulgaria
RegionBurgas, 02
ASNAS29084
OrganizationComnet Bulgaria Holding Ltd.

Feed Intelligence Summary

8 reports53% confidence
8
Source reports
53%
Confidence score
Category tags
abuseactive scanningbotnetbrute forcebrute force attackbulgariacommand and controlcredential accesscredential stuffingdata exfiltrationddosdenial of servicedistributed attackseuropeexploit attemptsftp brute forcehackinghttp brute forceindicatorlateral movementmalicious softwaremalwaremalware propagationmalware scanningnetworknetwork probingnetwork scanningpassword attacksprocess injectionreconnaissanceremote accessremote servicesresearchedscannersmtp brute forcesql injection attemptsssh attackt1021t1021.001t1046t1055t1059t1071.001t1076t1078t1110t1110.001t1110.002t1110.003t1110.004t1133t1187t1190t1199t1210t1486t1496t1499.002t1499.003t1563t1565t1588t1595t1595.001t1595.002t1595.003

Activity Timeline

1 total obs
Feb 4Feb 4

Threat Activity Heatmap

· Peak: 2026-02-04
Less
More
Mon
Wed
Fri
Jun
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Threat ScoreMedium Risk
53
SIGNAL
Signal Score
53%
Confidence
8
Reports
First seenMay 29, 2025
Last seenFeb 4, 2026
GeolocationBG
CountryBulgaria
LocationBurgas, 02
ASNAS29084
OrgComnet Bulgaria Holding Ltd.
Coords42.4963, 27.4646

VirusTotal

Not checked

WHOIS

raw
inetnum: 84.54.176.0 - 84.54.183.255 netname: COMNET-AW descr: ComNet Bourgas PPPoE and Leased country: BG admin-c: II147-RIPE tech-c: DK1476-RIPE status: ASSIGNED PA mnt-by: COMNET-ADM mnt-routes: COMNET-ADM remarks: <INFRA-AW> created: 2007-09-19T07:28:05Z last-modified: 2019-04-17T07:39:43Z source: RIPE # Filtered person: Dimitar Kostadinov address: Comnet Bulgaria Holding Ltd. address: Bulgaria address: 8000 Bourgas address: Stefan Stambolov 74 phone: +359 56 800416 nic-hdl: DK1476-RIPE mnt-by: COMNET-ADM created: 2004-07-26T15:49:22Z last-modified: 2025-05-07T06:18:41Z source: RIPE # Filtered person: Ivan Ivanov address: Comnet Bulgaria Holding Ltd. address: Bulgaria address: 8000 Bourgas address: Stefan Stambolov 74 phone: +359 56 813022 nic-hdl: II147-RIPE mnt-by: COMNET-ADM created: 2003-05-28T07:07:42Z last-modified: 2006-11-27T13:42:31Z source: RIPE # Filtered route: 84.54.180.0/24 descr: ComNet Bulgaria Ltd. origin: AS29084 mnt-by: COMNET-ADM created: 2005-10-10T09:54:19Z last-modified: 2005-10-10T09:54:19Z source: RIPE

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 4 months ago
Appeared in 8 threat reports