IOC Radar
IPMediumSignal 100/100

94.156.167.205

Location
United StatesUnited States
Amsterdam, North Holland
ASN
AS208220
Offerhost Solutions Inc
First Seen
Oct 2, 2024
Last Seen
Aug 5, 2025
Oct 2
First Seen
629d ago
Aug 5
Last Seen
321d ago
16
Reports
source reports
99%
Confidence
medium
Found in 16 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
99%
Signal Score
100 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

52 techniques

Network Information

CountryUSUnited States
RegionAmsterdam, North Holland
ASNAS208220
OrganizationOfferhost Solutions Inc

Feed Intelligence Summary

16 reports99% confidence
16
Source reports
99%
Confidence score
Category tags
abuseaccessaccess controlactive scanningadbhoney honeypotapacheapache attackerattackbotnetbrute forcebrute force attackciscocisco devicecommand and controlcommunication protocolconnectcowriecowrie activitycowrie honeypotcredential accesscredential harvestingcredential stuffingctadata exfiltrationdatabase exploitationdatabase securitydecoy systemdevice managementdictionary attackdionaeadionaea activitydionaea honeypotdistributed attacksemailenterprise networkingexploitfin scanftp brute forcegithubgroupsheralding activityhoneytrap honeypotindicatorinformation gatheringinfrastructure acquisitionreconnaissancelamplamp attacklamp exploitation attemptsmailoney activitymailoney honeypotmalicious activitymalicious softwaremalicious_activitymalwaremalware behaviourmalware capturemanualnetherlandsnetworknetwork discoverynetwork infrastructurenetwork intrusionnetwork intrusion attemptsnetwork probingnetwork reconnaissancenetwork scanningnetwork securitynlnorth americanull scanopen port detectionpassword attacksphishingphishing attackphishing trappotential exploit targetingpotential malware distributionpotential vulnerability assessmentprocess injectionprotocol exploitationpythonreconnaissanceredis honeypotresearchedresource hijackingscannerscanning activityscriptscripting attackssecurity policysentrypeer activitysentrypeer botnetservice enumerationsftpsftp access attemptsftp attacksftp attemptsipsip brute forcesip scanningslugsmtp brute forcesocial engineeringsshssh attackssh monitoringsurface websyn port scansyn scant1016t1018t1021t1021.001t1021.002t1021.004t1021.006t1040t1041t1046t1053t1055t1059t1059.004t1059.007t1068t1071.001t1078t1078.004t1110t1110.001t1110.002t1110.003t1110.004t1133t1189t1190t1203t1204.002t1486t1496t1499.001t1499.002t1499.003t1565t1566t1566.001t1566.002t1566.003t1566.004t1583t1587.001t1588t1589t1589.002t1590.001t1592t1592.004t1595t1595.001t1595.002t1595.003tannertanner activitytcptelecommunicationstelnet threatthreat actorthreat detectionthreat intelligencethreat preventionudp port scanunauthorized accessunauthorized access attemptunited statesusvoipvoip attackweb attackweb exploitationxmas scan

Activity Timeline

1 total obs
Aug 5Aug 5

Threat Activity Heatmap

· Peak: 2025-08-05
Less
More
Mon
Wed
Fri
Jun
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Threat ScoreHigh Risk
100
SIGNAL
Signal Score
99%
Confidence
16
Reports
First seenOct 2, 2024
Last seenAug 5, 2025
GeolocationUS
CountryUnited States
LocationAmsterdam, North Holland
ASNAS208220
OrgOfferhost Solutions Inc
Coords52.3676, 4.9041

VirusTotal

Not checked

WHOIS

description
2024-12-29T19:46:40.319Z Honeypot : Dionaea : Source: 94.156.167.205 : Port: 27017 Connection: {'transport': 'tcp', 'protocol': 'mongod', 'type': 'accept'}

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 10 months ago
Appeared in 16 threat reports