IOC Radar
IPMediumSignal 96/100

89.221.217.206

Location
Czech RepublicCzech Republic
Hluboká nad Vltavou, Jihočeský kraj
ASN
AS197019
WEDOS Internet
First Seen
Nov 10, 2024
Last Seen
Feb 15, 2026
Nov 10
First Seen
577d ago
Feb 15
Last Seen
116d ago
24
Reports
source reports
96%
Confidence
medium
4/91
VirusTotal
detections
Found in 24 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
96%
Signal Score
96 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

28 techniques

Network Information

CountryCZCzech Republic
RegionHluboká nad Vltavou, Jihočeský kraj
ASNAS197019
OrganizationWEDOS Internet

IP Category

Proxy
Proxy server

Feed Intelligence Summary

24 reports96% confidence
24
Source reports
96%
Confidence score
Category tags
abuseaccess controlactive scanningattackauto-generated securitybotnetbrute forcebrute force attackcommand and controlcredential accesscredential harvestingcredential stuffingczczech republicczechiadata exfiltrationdetect-debug-environmentdistributed attacksexit nodefireholindicatorinfrastructure acquisitionreconnaissancejsonlong-sleepsmalicious activitymalicious softwaremalwaremalware distributionmanualnetworknetwork scanningnetwork trafficoverlaypassword attackspeexephishing attackprocess injectionproxyreconnaissanceresearchedscannersecurity policyservice-scansocial engineeringspamt1016t1055t1071t1071.001t1071.002t1071.004t1090t1110.001t1110.002t1110.003t1110.004t1133t1190t1486t1496t1499.002t1499.003t1565t1566.001t1566.002t1566.003t1572t1587.001t1588t1590.001t1595.001t1595.002t1595.003textthreat actorthreat preventiontortor activitytor exittor exit nodetor networkwindowszip

Activity Timeline

1 total obs
Feb 15Feb 15

Threat Activity Heatmap

· Peak: 2026-02-15
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Threat ScoreHigh Risk
96
SIGNAL
Signal Score
96%
Confidence
24
Reports
First seenNov 10, 2024
Last seenFeb 15, 2026
GeolocationCZ
CountryCzech Republic
LocationHluboká nad Vltavou, Jihočeský kraj
ASNAS197019
OrgWEDOS Internet
Coords50.0853, 14.4110
Proxy

VirusTotal

4/ 91vendors flagged
4% detection rateJun 8, 2026

WHOIS

description
IP Address belongs to Tor exit node.
raw
inetnum: 89.221.208.0 - 89.221.223.255 netname: CZ-WEDOS-20061011 country: CZ org: ORG-WIa5-RIPE admin-c: PS10635-RIPE admin-c: JG3833-RIPE tech-c: PS10635-RIPE status: ALLOCATED PA mnt-by: RIPE-NCC-HM-MNT mnt-by: WEDOS-MNT mnt-routes: WEDOS-MNT created: 2016-10-11T08:37:08Z last-modified: 2017-09-11T18:50:06Z source: RIPE # Filtered organisation: ORG-WIa5-RIPE org-name: WEDOS Internet, a.s. country: CZ org-type: LIR address: Masarykova 1230 address: 37341 address: Hluboka nad Vltavou address: CZECH REPUBLIC phone: +420380999333 fax-no: +420389501257 mnt-ref: RIPE-NCC-HM-MNT mnt-ref: WEDOS-MNT mnt-by: RIPE-NCC-HM-MNT mnt-by: WEDOS-MNT abuse-c: WED-RIPE created: 2010-07-20T15:55:48Z last-modified: 2023-04-18T05:40:41Z source: RIPE # Filtered admin-c: PS10635-RIPE admin-c: JG3833-RIPE person: Josef Grill address: WEDOS Internet, a.s. address: Masarykova 1230 address: Hluboka nad Vltavou address: 37341 address: CZ phone: +420 380999333 nic-hdl: JG3833-RIPE mnt-by: WEDOS-MNT created: 2010-07-20T17:53:36Z last-modified: 2017-10-30T22:10:22Z source: RIPE # Filtered person: Petr Stastny address: WEDOS Internet, a.s. address: Masarykova 1230 address: Hluboka nad Vltavou address: 37341 phone: +420 380999333 nic-hdl: PS10635-RIPE mnt-by: WEDOS-MNT created: 2010-07-20T17:40:40Z last-modified: 2017-10-30T22:10:22Z source: RIPE # Filtered route: 89.221.208.0/20 descr: WEDOS Internet, a.s. origin: AS197019 mnt-by: WEDOS-MNT created: 2016-10-13T13:21:43Z last-modified: 2016-10-13T13:21:43Z source: RIPE
references
https://check.torproject.org/torbulkexitlist, https://raw.githubusercontent.com/ahamed-rizvan/IOCs/refs/heads/main/Malicous%20IP%20Address.txt, https://iplists.firehol.org/?ipset=tor_exits

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 3 months ago
Appeared in 24 threat reports