IOC Radar
IPMediumSignal 72/100

89.105.204.97

Location
NetherlandsNetherlands
Enschede, Overijssel
ASN
AS24875
Tweeweg IT B.V.
First Seen
Mar 18, 2026
Last Seen
Jun 10, 2026
Mar 18
First Seen
84d ago
Jun 10
Last Seen
yesterday
6
Reports
source reports
72%
Confidence
medium
Found in 6 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
72%
Signal Score
72 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

25 techniques

Network Information

CountryNLNetherlands
RegionEnschede, Overijssel
ASNAS24875
OrganizationTweeweg IT B.V.

Feed Intelligence Summary

6 reports72% confidence
6
Source reports
72%
Confidence score
Category tags
active scanactive scanningaustraliabad web botbotnetbotnet activitybrute forcebrute force attackbrute force attackercloud environmentcommunication protocolcowriecowrie honeypotcredential accesscredential stuffingdata store exposuredatabase attackddosddos attackdecoy systemdenial of servicedigital oceandionaeadionaea honeypoteuropeexploitation activityfattftphackinghoneytrap honeypothttp scanneridentity & access exploitationindicatorinitial accessipv4mailoney honeypotmalicious activitymalwaremalware behaviourmalware capturenetherlandsnetworknetwork attacksnetwork intrusion attemptsnetwork probingnetwork protocolnetwork reconnaissancenetwork scanningnetwork securitynetwork servicesnloceaniap0fpassword attacksphishingphishing attackphishing trapportscanprotocol exploitationreconnaissanceremote accessremote servicesresearchedresource hijackingscannerscannerssensor-taggedsentrypeer botnetservice scansmtpssh attackssh monitoringsystem accesst1021t1021.001t1040t1046t1071.001t1076t1078t1110t1110.001t1110.002t1110.003t1110.004t1133t1190t1203t1496t1499.001t1499.002t1499.003t1563t1590t1595t1595.001t1595.002t1595.003tannertargeting databasetcp scanningtelecommunicationstelnet threatthreat actorthreat detectionthreat intelligencetor nodetpotvoipvoip attackweb application attackweb exploitweb exploitationweb traffic

Activity Timeline

1 total obs
Jun 10Jun 10

Threat Activity Heatmap

Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
1
Minimal
30d
1
Minimal
3mo
1
Minimal
Threat ScoreHigh Risk
72
SIGNAL
Signal Score
72%
Confidence
6
Reports
First seenMar 18, 2026
Last seenJun 10, 2026
GeolocationNL
CountryNetherlands
LocationEnschede, Overijssel
ASNAS24875
OrgTweeweg IT B.V.
Coords52.3824, 4.8995

VirusTotal

Not checked

WHOIS

raw
inetnum: 89.105.204.0 - 89.105.204.127 netname: NLISPTWEEWEG01 descr: Tweeweg IT B.V. country: NL admin-c: NRA29-RIPE tech-c: NRA29-RIPE status: ASSIGNED PA mnt-by: nl-novoserve-1-mnt created: 2008-07-16T11:40:06Z last-modified: 2017-02-21T07:37:48Z source: RIPE role: Novoserve Role Account address: Hengelosestraat 201 nic-hdl: NRA29-RIPE mnt-by: nl-novoserve-1-mnt created: 2016-05-11T12:25:10Z last-modified: 2021-08-13T12:06:02Z source: RIPE # Filtered route: 89.105.192.0/20 origin: AS24875 mnt-by: nl-novoserve-1-mnt created: 2018-10-20T14:03:57Z last-modified: 2018-10-20T14:03:57Z source: RIPE
references
https://jamesbrine.com.au/digitaloceantoronto-portscan-bruteforce-ip-list-2026-03-17/, https://jamesbrine.com.au, https://jamesbrine.com.au/digitaloceantoronto-portscan-bruteforce-ip-list-2026-03-21/

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 2 months ago · Last seen 1 day ago
Appeared in 6 threat reports