IPMediumSignal 50/100
89.233.107.97
Location
Amsterdam, North Holland
ASN
AS29802
HIVELOCITY, Inc.
First Seen
Mar 3, 2025
Last Seen
Jun 6, 2026
Mar 3
First Seen
465d ago
Jun 6
Last Seen
5d ago
24
Reports
source reports
50%
Confidence
medium
7/91
VirusTotal
detections
Found in 24 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
50%
Signal Score
50 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Network Information
Country
Netherlands
RegionAmsterdam, North Holland
ASNAS29802
OrganizationHIVELOCITY, Inc.
Feed Intelligence Summary
24 reports50% confidence
24
Source reports
50%
Confidence score
Category tags
abuseaccess controlaccount compromiseactive scanactive scanningapacheapache attackeraptasiaattackattacker ipauthenticationauthentication attackbad reputationblacklisted ip addressblocklist_allbotnetbotnet activitybotnet activity detectedbotnet activity detectionbotnet indicatorsbrute forcebrute force attackbrute force attackerbrute force attacksbrute force attemptbrute-forcebruteforcec&c communicationc2c2 communicationclifton data centercloud environmentcloud infrastructurecloud infrastructure attackcloud servicescommand & controlcommand and controlcommunication protocolcompromised credentialscompromised hostscompromised systemcompromised systemscowrie honeypotcredential accesscredential stuffingcredential theftcredentialaccessdata exfiltrationdata store exposureddosddos activityddos attackddos botnetdecoy systemdenial of servicedistributed attacksenumerationeuropeexploit attemptexploit attemptsexploitation activityexploited hostftpftp brute forceftp brute-forcehackinghttp brute forcehttp scannerhttpsidentity & access exploitationinformation technologyinitial accessinjection activityinternet facing assetintrusion detectioniocipv4it infrastructurejapanlateral movementloginattackmalicious activitymalicious communication blockingmalicious softwaremalwaremalware beaconingmalware distributionmalware indicatorsnetherlandsnetworknetwork attacksnetwork discoverynetwork enumerationnetwork intrusionnetwork intrusion detectionnetwork probingnetwork protocolnetwork reconnaissancenetwork scanningnetwork securitynetwork trafficnlnoticepassword attacksphishingphishing campaignportscanprocess injectionproxyransomwarereconnaissancereconnaissance activityremote accessremote servicesresearchedresource hijackingscannerscannersscanning activitysecurity operationssecurity policyservice scansftp attacksftp exploitation attemptssmtp brute forcesocradar honeypotsoftware developmentspamspam botnetspam campaignsspam sendingsshssh attackssh monitoringsystem discoveryt1003t1003.001t1003.002t1003.003t1003.004t1003.005t1003.006t1003.007t1003.008t1005t1018t1021t1021.001t1021.002t1021.003t1021.004t1021.005t1021.006t1021.007t1021.008t1029t1040t1041t1046t1047t1055t1059t1059.001t1059.003t1059.004t1059.005t1059.006t1068t1070t1070.001t1070.002t1070.003t1071t1071.001t1071.004t1076t1078t1078.002t1078.003t1105t1110t1110.001t1110.002t1110.003t1110.004t1133t1189t1190t1203t1486t1496t1499.001t1499.002t1499.003t1555t1555.001t1555.002t1555.003t1555.004t1555.005t1555.006t1563t1565t1566t1566.001t1566.002t1566.003t1566.004t1568t1568.002t1571t1573t1573.001t1573.002t1583t1583.001t1589t1590t1595t1595.001t1595.002t1595.003tcp protocoltcp scanthreat actorthreat intelligencethreat preventiontor nodetraffic anomalyudp scanunauthorized accessurlsvpsvulnerability scanvultrweb app attackweb application attackweb exploitationweb traffic
Activity Timeline
Jun 6Jun 6
Threat Activity Heatmap
· Peak: 2026-06-06LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
1
Minimal
30d
1
Minimal
3mo
1
Minimal
Threat ScoreMedium Risk
50
SIGNAL
Signal Score
50%
Confidence
24
Reports
First seenMar 3, 2025
Last seenJun 6, 2026
GeolocationNL
CountryNetherlands
LocationAmsterdam, North Holland
ASNAS29802
OrgHIVELOCITY, Inc.
Coords52.3891, 4.6563
WHOIS
- description
- IPv4 hosts detected port scanning Vultr Tokyo (Japan) honeypot
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 1 year ago · Last seen 5 days ago
Appeared in 24 threat reports