IPMediumSignal 100/100
94.156.105.167
Location
Almaty, Almaty
ASN
AS200590
NLS Kazakhstan LLC
First Seen
Oct 3, 2024
Last Seen
Apr 5, 2025
Found in 13 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
99%
Signal Score
100 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Network Information
Country
Kazakhstan
RegionAlmaty, Almaty
ASNAS200590
OrganizationNLS Kazakhstan LLC
Feed Intelligence Summary
13 reports99% confidence
13
Source reports
99%
Confidence score
Category tags
abuseack scanactive scanningattackbotnetcommand and controlcommunication protocolcredential harvestingctadata exfiltrationdenial of servicedistributed attacksenumerationfin scanfirewall detectionindicatorinfrastructure acquisitionreconnaissancemalicious activitymalicious softwaremalwaremanualmasscan activitynetherlandsnetworknetwork attacksnetwork mappingnetwork protocolnetwork reconnaissancenetwork scanningnlnmap scan detectednull scanos detectionphishing attackpossible vulnerability probingpotential exploit targetingpotential reconnaissance activitypotential threat activityprocess injectionreconnaissancereconnaissance activityresearchedscannerservice discoveryservice version detectionsocial engineeringstealth scansyn scant1018t1040t1046t1055t1071.001t1133t1190t1486t1496t1499.002t1499.003t1565t1566.001t1566.002t1566.003t1587.001t1588t1588.002t1590.001t1595t1595.001t1595.002t1595.003tcp protocolthreat actorudp port scanusxmas scan
Activity Timeline
Apr 5Apr 5
Threat Activity Heatmap
LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Threat ScoreHigh Risk
100
SIGNAL
Signal Score
99%
Confidence
13
Reports
First seenOct 3, 2024
Last seenApr 5, 2025
GeolocationKZ
CountryKazakhstan
LocationAlmaty, Almaty
ASNAS200590
OrgNLS Kazakhstan LLC
Coords43.2525, 76.9115
VirusTotal
Not checked
WHOIS
- description
- Port Scan 2024-10-15T10:08:04.000Z -> 94.156.105.167 scanned port 3702 on one of our servers
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 1 year ago · Last seen 1 year ago
Appeared in 13 threat reports