IOC Radar
IPMediumSignal 64/100

95.106.64.61

Location
Russian FederationRussian Federation
Ryazan, RYA
ASN
AS12389
Ryazan branch of Joint-Stock Central Telecommunication Company
First Seen
May 24, 2025
Last Seen
Dec 4, 2025
May 24
First Seen
397d ago
Dec 4
Last Seen
203d ago
6
Reports
source reports
64%
Confidence
medium
Found in 6 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
64%
Signal Score
64 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

29 techniques

Network Information

CountryRURussian Federation
RegionRyazan, RYA
ASNAS12389
OrganizationRyazan branch of Joint-Stock Central Telecommunication Company

Feed Intelligence Summary

6 reports64% confidence
6
Source reports
64%
Confidence score
Category tags
abuseactive scanningbotnetbrute forcebrute force attackcommand and controlcredential accesscredential stuffingdata exfiltrationddosdenial of servicedistributed attackseurope/asiaexploit attemptsftp brute forcehttp brute forceindicatorlateral movementmalicious softwaremalwaremalware propagationmalware scanningnetworknetwork probingnetwork scanningpassword attacksprocess injectionreconnaissanceremote accessremote servicesresearchedrussiarussian federationsmtp brute forcesql injection attemptsssh attackt1021t1021.001t1046t1055t1059t1071.001t1076t1078t1110t1110.001t1110.002t1110.003t1110.004t1133t1187t1190t1199t1210t1486t1496t1499.002t1499.003t1563t1565t1588t1595t1595.001t1595.002t1595.003

Activity Timeline

1 total obs
Dec 4Dec 4

Threat Activity Heatmap

· Peak: 2025-12-04
Less
More
Mon
Wed
Fri
Jun
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Threat ScoreMedium Risk
64
SIGNAL
Signal Score
64%
Confidence
6
Reports
First seenMay 24, 2025
Last seenDec 4, 2025
GeolocationRU
CountryRussian Federation
LocationRyazan, RYA
ASNAS12389
OrgRyazan branch of Joint-Stock Central Telecommunication Company
Coords54.6161, 39.7376

VirusTotal

Not checked

WHOIS

raw
inetnum: 95.106.64.0 - 95.106.79.255 netname: MACROREGIONAL_CENTER descr: OJSC Rostelecom, Ryazan Branch descr: ex-netname:DOMOLINK-RYAZAN country: RU admin-c: SAM18-RIPE tech-c: SAM18-RIPE status: ASSIGNED PA mnt-lower: INECO-MNT-RIPE mnt-by: INECO-MNT-RIPE created: 2012-03-27T06:03:37Z last-modified: 2017-04-26T08:43:27Z source: RIPE mnt-lower: ROSTELECOM-MNT mnt-routes: ROSTELECOM-MNT person: Sergey A. Mironov address: Ryazan branch of Joint-Stock Central Telecommunication Company address: 43, Schedrina st. address: 390006, Ryazan address: Russia remarks: phone: +7 0912 270217 phone: +7 4912 270217 remarks: fax-no: +7 0912 217540 fax-no: +7 4912 217540 nic-hdl: SAM18-RIPE mnt-by: INECO-MNT-RIPE created: 2002-09-23T12:26:58Z last-modified: 2018-10-02T14:11:23Z source: RIPE # Filtered remarks: modified for Russian phone area changes route: 95.106.64.0/18 descr: Rostelecom networks origin: AS12389 mnt-by: ROSTELECOM-MNT created: 2018-10-25T14:23:33Z last-modified: 2018-10-25T14:23:33Z source: RIPE # Filtered

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 6 months ago
Appeared in 6 threat reports