IOC Radar
IPMediumSignal 72/100

88.249.183.103

Location
TurkeyTurkey
Narlıdere, 35
ASN
AS9121
TurkTelecom
First Seen
Sep 21, 2024
Last Seen
Feb 16, 2026
Sep 21
First Seen
631d ago
Feb 16
Last Seen
119d ago
7
Reports
source reports
72%
Confidence
medium
Found in 7 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
72%
Signal Score
72 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

29 techniques

Network Information

CountryTRTurkey
RegionNarlıdere, 35
ASNAS9121
OrganizationTurkTelecom

Feed Intelligence Summary

7 reports72% confidence
7
Source reports
72%
Confidence score
Category tags
abuseactive scanningattackbotnetbrute forcebrute force attackcommand and controlcommunication protocolcompromised credentialscowrie honeypotcredential accesscredential stuffingdata exfiltrationddosdecoy systemdenial of servicedistributed attackseurope/asiaindicatorlateral movementmalicious activitymalicious softwaremalwarenetworknetwork securitypassword attacksprocess injectionprotocol exploitationreconnaissanceremote servicesresearchedresource hijackingscannerscanning activitysentrypeer botnetsftp attackssh attackssh monitoringt1018t1021t1021.004t1040t1041t1046t1055t1059t1059.004t1071.001t1078t1110t1110.001t1110.002t1110.003t1110.004t1190t1486t1496t1499.001t1499.002t1499.003t1550t1550.002t1565t1595t1595.001t1595.002t1595.003tannertcp/23telecommunicationstelnet threatthreat actortpotceturkeyvoipvoip attack

Activity Timeline

1 total obs
Feb 16Feb 16

Threat Activity Heatmap

· Peak: 2026-02-16
Less
More
Mon
Wed
Fri
Jun
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Threat ScoreHigh Risk
72
SIGNAL
Signal Score
72%
Confidence
7
Reports
First seenSep 21, 2024
Last seenFeb 16, 2026
GeolocationTR
CountryTurkey
LocationNarlıdere, 35
ASNAS9121
OrgTurkTelecom
Coords38.4869, 27.4334

VirusTotal

Not checked

WHOIS

description
2025-04-01T08:34:33.846Z Honeypot : Cowrie : Source: 88.249.183.103 Data: New connection: 88.249.183.103:36689 (172.26.0.2:23) [session: 4b3b22924f4c]
raw
inetnum: 88.249.160.0 - 88.249.234.255 netname: TurkTelekom descr: TT ADSL-TTnet_static_aci country: tr admin-c: TTBA1-RIPE tech-c: TTBA1-RIPE status: ASSIGNED PA mnt-by: as9121-mnt created: 2010-07-27T10:09:11Z last-modified: 2010-07-27T10:09:11Z source: RIPE # Filtered role: TT Administrative Contact Role address: Turk Telekomunikasyon A.S Turgut Ozal Blv. Aydinlikevler address: 06103 ANKARA TURKEY phone: +90 312 555 0000 fax-no: +90 312 313 1924 admin-c: BADB3-RIPE abuse-mailbox: [email protected] tech-c: BADB3-RIPE tech-c: BADB3-RIPE tech-c: BADB3-RIPE nic-hdl: TTBA1-RIPE mnt-by: AS9121-MNT created: 2002-02-28T12:22:28Z last-modified: 2022-01-28T07:15:56Z source: RIPE # Filtered route: 88.249.128.0/17 descr: TurkTelecom origin: AS9121 mnt-by: AS9121-MNT created: 2006-11-20T06:52:31Z last-modified: 2006-11-20T06:52:31Z source: RIPE
references
https://github.com/telekom-security/tpotce

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 3 months ago
Appeared in 7 threat reports