IOC Radar
IPMediumSignal 68/100

87.227.42.247

Location
SwedenSweden
Gothenburg, Västra Götaland County
ASN
AS1257
Tele2 AB
First Seen
Apr 13, 2026
Last Seen
May 30, 2026
Apr 13
First Seen
60d ago
May 30
Last Seen
14d ago
13
Reports
source reports
68%
Confidence
medium
Found in 13 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
68%
Signal Score
68 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

8 techniques

Network Information

CountrySESweden
RegionGothenburg, Västra Götaland County
ASNAS1257
OrganizationTele2 AB

Feed Intelligence Summary

13 reports68% confidence
13
Source reports
68%
Confidence score
Category tags
abuseaccess controlactive scanactive scanningattackaustraliabad reputationbrute forcebrute force attackbrute-forcecredential accesscredential stuffingeuropeexploitexploitation activityhackingidentity & access exploitationindicatormalicious activitymalwarenetworkoceaniapassword attacksreconnaissanceresearchedscannersesecurity policysshssh attackswedent1110t1110.001t1110.002t1110.003t1110.004t1595.001t1595.002t1595.003threat actorthreat preventiontor nodetpotvulnerability scanvulnerability-exploitation

Activity Timeline

1 total obs
May 30May 30

Threat Activity Heatmap

· Peak: 2026-05-30
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Threat ScoreMedium Risk
68
SIGNAL
Signal Score
68%
Confidence
13
Reports
First seenApr 13, 2026
Last seenMay 30, 2026
GeolocationSE
CountrySweden
LocationGothenburg, Västra Götaland County
ASNAS1257
OrgTele2 AB
Coords59.3247, 18.0560

VirusTotal

Not checked

WHOIS

raw
inetnum: 87.227.0.0 - 87.227.63.255 netname: SE-TELE2-BROADBAND descr: In case of improper use, please mail <[email protected]> country: SE geoloc: 59.355596110016315 18.0615234375 language: SE admin-c: SWIP-RIPE tech-c: SWIP-RIPE status: ASSIGNED PA mnt-by: SWIPNET-LIR-MNT mnt-lower: SWIPNET-LIR-MNT mnt-lower: COMHEM-MNT mnt-routes: COMHEM-MNT created: 2021-01-19T13:42:01Z last-modified: 2021-05-04T09:58:49Z source: RIPE role: Swipnet Staff address: Tele2 AB/Swedish IP Network address: IP Registry address: Torshamnsgatan 17 164 40 Kista SWEDEN fax-no: +46 8 5626 42 10 abuse-mailbox: [email protected] remarks: The database object describes the staff of SWIPNET LIR. admin-c: ROSI3-RIPE admin-c: TH6544-RIPE tech-c: ROSI3-RIPE tech-c: TH6544-RIPE nic-hdl: SWIP-RIPE mnt-by: SWIPNET-LIR-MNT created: 2002-03-21T14:25:04Z last-modified: 2022-11-23T10:36:53Z source: RIPE # Filtered route: 87.227.0.0/17 origin: AS1257 mnt-by: AS1257-MNT created: 2021-07-13T10:14:08Z last-modified: 2021-07-13T10:14:08Z source: RIPE route: 87.227.0.0/17 origin: AS39651 mnt-by: COMHEM-MNT created: 2021-01-20T14:09:19Z last-modified: 2021-01-20T14:09:19Z source: RIPE
references
https://redpiranha.net, https://malware-filter.gitlab.io/malware-filter/botnet-filter.txt

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 2 months ago · Last seen 14 days ago
Appeared in 13 threat reports