IPMediumSignal 100/100
94.156.167.205
Location
Amsterdam, North Holland
ASN
AS208220
Offerhost Solutions Inc
First Seen
Oct 2, 2024
Last Seen
Aug 5, 2025
Found in 16 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
99%
Signal Score
100 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Network Information
Country
United States
RegionAmsterdam, North Holland
ASNAS208220
OrganizationOfferhost Solutions Inc
Feed Intelligence Summary
16 reports99% confidence
16
Source reports
99%
Confidence score
Category tags
abuseaccessaccess controlactive scanningadbhoney honeypotapacheapache attackerattackbotnetbrute forcebrute force attackciscocisco devicecommand and controlcommunication protocolconnectcowriecowrie activitycowrie honeypotcredential accesscredential harvestingcredential stuffingctadata exfiltrationdatabase exploitationdatabase securitydecoy systemdevice managementdictionary attackdionaeadionaea activitydionaea honeypotdistributed attacksemailenterprise networkingexploitfin scanftp brute forcegithubgroupsheralding activityhoneytrap honeypotindicatorinformation gatheringinfrastructure acquisitionreconnaissancelamplamp attacklamp exploitation attemptsmailoney activitymailoney honeypotmalicious activitymalicious softwaremalicious_activitymalwaremalware behaviourmalware capturemanualnetherlandsnetworknetwork discoverynetwork infrastructurenetwork intrusionnetwork intrusion attemptsnetwork probingnetwork reconnaissancenetwork scanningnetwork securitynlnorth americanull scanopen port detectionpassword attacksphishingphishing attackphishing trappotential exploit targetingpotential malware distributionpotential vulnerability assessmentprocess injectionprotocol exploitationpythonreconnaissanceredis honeypotresearchedresource hijackingscannerscanning activityscriptscripting attackssecurity policysentrypeer activitysentrypeer botnetservice enumerationsftpsftp access attemptsftp attacksftp attemptsipsip brute forcesip scanningslugsmtp brute forcesocial engineeringsshssh attackssh monitoringsurface websyn port scansyn scant1016t1018t1021t1021.001t1021.002t1021.004t1021.006t1040t1041t1046t1053t1055t1059t1059.004t1059.007t1068t1071.001t1078t1078.004t1110t1110.001t1110.002t1110.003t1110.004t1133t1189t1190t1203t1204.002t1486t1496t1499.001t1499.002t1499.003t1565t1566t1566.001t1566.002t1566.003t1566.004t1583t1587.001t1588t1589t1589.002t1590.001t1592t1592.004t1595t1595.001t1595.002t1595.003tannertanner activitytcptelecommunicationstelnet threatthreat actorthreat detectionthreat intelligencethreat preventionudp port scanunauthorized accessunauthorized access attemptunited statesusvoipvoip attackweb attackweb exploitationxmas scan
Activity Timeline
Aug 5Aug 5
Threat Activity Heatmap
· Peak: 2025-08-05LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Threat ScoreHigh Risk
100
SIGNAL
Signal Score
99%
Confidence
16
Reports
First seenOct 2, 2024
Last seenAug 5, 2025
GeolocationUS
CountryUnited States
LocationAmsterdam, North Holland
ASNAS208220
OrgOfferhost Solutions Inc
Coords52.3676, 4.9041
VirusTotal
Not checked
WHOIS
- description
- 2024-12-29T19:46:40.319Z Honeypot : Dionaea : Source: 94.156.167.205 : Port: 27017 Connection: {'transport': 'tcp', 'protocol': 'mongod', 'type': 'accept'}
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 1 year ago · Last seen 10 months ago
Appeared in 16 threat reports