IOC Radar
IPMediumSignal 75/100

85.215.181.244

Location
GermanyGermany
Berlin, State of Berlin
ASN
AS8560
Strato AG
First Seen
Jan 28, 2026
Last Seen
Jun 1, 2026
Jan 28
First Seen
137d ago
Jun 1
Last Seen
13d ago
9
Reports
source reports
75%
Confidence
medium
Found in 9 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
75%
Signal Score
75 / 100
IDS Rule
No
Threat Context
Tags

Network Information

CountryDEGermany
RegionBerlin, State of Berlin
ASNAS8560
OrganizationStrato AG

Feed Intelligence Summary

9 reports75% confidence
9
Source reports
75%
Confidence score
Category tags
abuseactive scanbad reputationbrute forcebrute force attackerbrute-forcebruteforcecowriededigital oceandionaeadns attackeuropefattgermanyhackingindicatornetworkopen_dns_resolvers-benignp0fportscanransomwareresearchedscannerscannerssensor-taggedservice scansshtannertpotverified-benignvultr

Activity Timeline

1 total obs
Jun 1Jun 1

Threat Activity Heatmap

· Peak: 2026-06-01
Less
More
Mon
Wed
Fri
Jun
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Threat ScoreHigh Risk
75
SIGNAL
Signal Score
75%
Confidence
9
Reports
First seenJan 28, 2026
Last seenJun 1, 2026
GeolocationDE
CountryGermany
LocationBerlin, State of Berlin
ASNAS8560
OrgStrato AG
Coords51.2993, 9.4910

VirusTotal

Not checked

WHOIS

description
IPv4 hosts detected port scanning Vultr Melbourne (Australia) honeypot
raw
inetnum: 85.215.160.0 - 85.215.191.255 netname: de-ber-ionos-cloud-txl descr: IONOS SE country: DE admin-c: IPAD-RIPE tech-c: IPOP-RIPE status: ASSIGNED PA mnt-by: AS8560-MNT created: 2024-11-21T17:03:30Z last-modified: 2025-06-03T16:17:35Z source: RIPE role: IP Administration address: IONOS SE admin-c: SH15342-RIPE tech-c: SH15342-RIPE mnt-ref: AS8560-MNT nic-hdl: IPAD-RIPE abuse-mailbox: [email protected] mnt-by: AS8560-MNT created: 2009-05-20T17:24:09Z last-modified: 2025-09-26T12:26:46Z source: RIPE # Filtered role: IP Operations address: IONOS SE admin-c: SH15342-RIPE tech-c: SH15342-RIPE mnt-ref: AS8560-MNT nic-hdl: IPOP-RIPE abuse-mailbox: [email protected] mnt-by: AS8560-MNT created: 2009-05-28T16:25:04Z last-modified: 2025-09-26T12:26:44Z source: RIPE # Filtered route: 85.215.128.0/17 descr: IONOS SE ber.de origin: AS8560 mnt-by: AS8560-MNT created: 2024-02-01T10:20:15Z last-modified: 2024-02-01T10:20:15Z source: RIPE # Filtered
references
https://jamesbrine.com.au/vultrmelbournetest-portscan-bruteforce-ip-list-2026-04-16/, https://jamesbrine.com.au, https://jamesbrine.com.au/vultrparis-portscan-bruteforce-ip-list-2026-04-16/, https://public-dns.info/

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 4 months ago · Last seen 13 days ago
Appeared in 9 threat reports