IPMediumSignal 51/100
89.44.198.254
Location
Eschborn, SAM
ASN
AS202422
GCL
First Seen
Mar 15, 2025
Last Seen
Jun 17, 2026
Found in 6 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
51%
Signal Score
51 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Network Information
Country
Germany
RegionEschborn, SAM
ASNAS202422
OrganizationGCL
Feed Intelligence Summary
6 reports51% confidence
6
Source reports
51%
Confidence score
Category tags
accessactive scanningactorsandroidbackdoorbackdoor installationblack lotusbodyboombotnetbotnet activitybrute forcebusiness email compromisebuttonc2 communicationchinacmdcodecode executioncode injectioncommand and controlcommand executioncommand injectioncommunication protocolconnectcovid19coyotecredential accesscredential harvestingcredential stuffingcritical infrastructurecsscvecyber espionagecyber securitydata breachdata encryptiondata exfiltrationdata theftdatabase securityddosddos attacksdedenial of servicedirectory traversaldistributed attacksdosdroppereducationemaileuropeexploitexploit kit usagefilefilesfinfinchformftpftp brute forcegdrivegermanygithubglobalgroupshigher educationhttphttp brute forcehttp scannerhttpsindicatorinfoinformation technologyinfrastructure acquisitionreconnaissanceinitial accessinjection attacksinternet of thingsintrusion detectioniociocsiotiot botnetiot/ics attacklabslateral movementlinkmalicious softwaremalwaremanualmedia & entertainmentmetadata analysismirai botnetmsinetnetworknetwork attacksnetwork compromisenetwork intrusionnetwork probingnetwork protocolnetwork scanningnetwork securityngroknosediveonepassword sprayingphishingphishing attackphishing campaignprivilege escalationprocess injectionransomware threatraptor trainreconnaissancereloadremote accessremote code executionremote servicesresearchedroutersrussian federationscannerscanning activityscriptscripting attacksslugsocial engineeringsocial media securitysohospansparrowssh attackstarstealersummitsupportsurface websynsystem compromiset1016t1018t1021t1021.001t1021.002t1040t1047t1053t1055t1059t1059.003t1059.004t1059.005t1059.007t1068t1071t1071.001t1076t1077t1078t1083t1110t1110.001t1110.002t1110.003t1133t1189t1190t1203t1204t1210t1486t1490t1496t1499.001t1499.002t1499.003t1547t1563t1565t1566t1566.001t1566.002t1566.003t1587.001t1589t1589.002t1590t1590.001t1590.002t1590.003t1590.004t1592t1592.001t1592.002t1592.003t1595t1595.001t1595.002t1595.003tcp protocoltelecommunicationsthreat intelligencetiertopunauthorized accessunauthorized access attemptunixurlvulnerabilityweb attackweb exploitationweb loginweb trafficwebsitewindowsxmasxssyara
Activity Timeline
Jun 17Jun 17
Threat Activity Heatmap
· Peak: 2026-06-17LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Threat ScoreMedium Risk
51
SIGNAL
Signal Score
51%
Confidence
6
Reports
First seenMar 15, 2025
Last seenJun 17, 2026
GeolocationDE
CountryGermany
LocationEschborn, SAM
ASNAS202422
OrgGCL
Coords53.1785, 50.1267
VirusTotal
Not checked
WHOIS
- description
- CC=DE ASN=AS202422 G-Core Labs S.A.
- raw
- inetnum: 89.44.198.0 - 89.44.198.255 descr: G-Core Labs Customer assignment netname: GCL-CUSTOMER-EU country: EU admin-c: LA5122-RIPE tech-c: LA5122-RIPE status: ASSIGNED PA mnt-by: GCL1-MNT created: 2023-04-18T11:18:58Z last-modified: 2023-04-18T11:18:58Z source: RIPE geoloc: 50.081545 8.623434 person: LIR Admin address: G-Core Labs S.A. address: 2 Rue Edmond Reuter address: 5326 Contern phone: +35220880507 nic-hdl: LA5122-RIPE mnt-by: GCL1-MNT created: 2012-12-05T15:05:34Z last-modified: 2023-07-17T19:38:48Z source: RIPE # Filtered route: 89.44.198.0/24 origin: AS199524 mnt-by: GCL1-MNT created: 2021-04-29T15:24:02Z last-modified: 2021-04-29T15:24:09Z source: RIPE route: 89.44.198.0/24 descr: GCL-89-44-198-0-24 origin: AS202422 mnt-by: GCL1-MNT created: 2021-09-14T11:01:56Z last-modified: 2021-09-14T11:01:56Z source: RIPE
- references
- https://media.defense.gov/2024/Sep/18/2003547016/-1/-1/0/CSA-PRC-LINKED-ACTORS-BOTNET.PDF, https://blog.lumen.com/derailing-the-raptor-train, https://blog.lumen.com/derailing-the-raptor-train/, https://github.com/blacklotuslabs/IOCs/blob/main/Raptor_Train_IOCs.txt
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 1 year ago · Last seen 7 days ago
Appeared in 6 threat reports