IOC Radar
IPMediumSignal 26/100

89.187.181.117

Location
United StatesUnited States
Chicago, Illinois
ASN
AS60068
Cdn77 CHI
First Seen
Oct 28, 2024
Last Seen
May 24, 2026
Oct 28
First Seen
593d ago
May 24
Last Seen
20d ago
8
Reports
source reports
26%
Confidence
medium
Found in 8 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
26%
Signal Score
26 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

33 techniques

Network Information

CountryUSUnited States
RegionChicago, Illinois
ASNAS60068
OrganizationCdn77 CHI

Feed Intelligence Summary

8 reports26% confidence
8
Source reports
26%
Confidence score
Category tags
active scanactive scanningattackaustraliabotnetbrute forcebrute force attackcitrix exploitation attemptcitrix securitycommand and controlcommunication protocolcompromised credentialscowrie honeypotcowrie loginscredential accesscredential stuffingdata exfiltrationddosdecoy systemdenial of servicedionaea capturedionaea honeypotdistributed attacksenterprise securityexploitfattftphackinghoneytrap honeypothttp scannermailoney honeypotmalicious activitymalicious softwaremalwaremalware behaviourmalware capturenetworknetwork reconnaissancenetwork scanningnetwork securitynetwork traffic analysisnorth americaoceaniap0fpassword attacksphishing attackphishing trapprocess injectionprotocol exploitationproxyreconnaissanceresearchedresource hijackingscannerscanning activitysensor-taggedsentrypeer botnetsftp attacksmtpspamssh attackssh monitoringt1021t1021.002t1040t1041t1046t1053.005t1055t1059t1059.004t1068t1071.001t1078t1110t1110.001t1110.002t1110.003t1110.004t1133t1189t1190t1203t1204.002t1486t1496t1499.001t1499.002t1499.003t1555t1565t1595t1595.001t1595.002t1595.003tannertelnet threatthreat actorthreat detectionthreat intelligencetpotunited statesusvoip attackweb application attackweb exploitationweb traffic

Activity Timeline

1 total obs
May 24May 24

Threat Activity Heatmap

· Peak: 2026-05-24
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Threat ScoreLow Risk
26
SIGNAL
Signal Score
26%
Confidence
8
Reports
First seenOct 28, 2024
Last seenMay 24, 2026
GeolocationUS
CountryUnited States
LocationChicago, Illinois
ASNAS60068
OrgCdn77 CHI
Coords41.8758, -87.6206

VirusTotal

Not checked

WHOIS

description
2024-11-01T04:07:28.469Z Honeypot : Dionaea : Source: 89.187.181.117 : Port: 3306 Connection: {'protocol': 'mysqld', 'type': 'accept', 'transport': 'tcp'}

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 20 days ago
Appeared in 8 threat reports