IOC Radar
IPHighVerifiedSignal 86/100

185.236.25.119

Location
SpainSpain
Madrid, VA
ASN
AS400992
JaJoJoo LLC
First Seen
Mar 3, 2026
Last Seen
Jun 17, 2026
Mar 3
First Seen
115d ago
Jun 17
Last Seen
9d ago
53
Reports
source reports
95%
Confidence
high
Found in 53 reports. Confidence: high. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
95%
Signal Score
86 / 100
IDS Rule
Yes
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

32 techniques

Network Information

CountryESSpain
RegionMadrid, VA
ASNAS400992
OrganizationJaJoJoo LLC

Feed Intelligence Summary

53 reports95% confidence
AT
Abuse.ch ThreatFox
Jun 17, 2026
3185 IOCs in report
AT
Abuse.ch ThreatFox
Jun 17, 2026
3191 IOCs in report
AT
Abuse.ch ThreatFox
Jun 17, 2026
3133 IOCs in report
AT
Abuse.ch ThreatFox
Jun 17, 2026
3135 IOCs in report
AT
Abuse.ch ThreatFox
Jun 17, 2026
3142 IOCs in report
AT
Abuse.ch ThreatFox
Jun 17, 2026
3149 IOCs in report
AT
Abuse.ch ThreatFox
Jun 17, 2026
3168 IOCs in report
AT
Abuse.ch ThreatFox
Jun 17, 2026
3161 IOCs in report
AT
Abuse.ch ThreatFox
Jun 17, 2026
3160 IOCs in report
AT
Abuse.ch ThreatFox
Jun 17, 2026
3152 IOCs in report

Activity Timeline

46 total obs
Jun 17Jun 15

Threat Activity Heatmap

· Peak: 2026-06-16
Less
More
Mon
Wed
Fri
Jun
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
24h
0
Dormant
7d
0
Dormant
30d
46
Critical
3mo
46
Critical
Threat ScoreHigh Risk
86
SIGNAL
Signal Score
95%
Confidence
53
Reports
First seenMar 3, 2026
Last seenJun 17, 2026
Verified IOC
GeolocationES
CountrySpain
LocationMadrid, VA
ASNAS400992
OrgJaJoJoo LLC
Coords38.6583, -77.2481

VirusTotal

Not checked

WHOIS

description
CC=US ASN=AS22773 cox communications inc.
references
https://ctrlaltintel.com/threat%20research/MuddyWater/, https://hunt.io/blog/iranian-apt-infrastructure-state-aligned-clusters, IOCs.2026.1.csv, https://malware-filter.gitlab.io/malware-filter/botnet-filter.txt

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

high
First detected 3 months ago · Last seen 9 days ago
Appeared in 53 threat reports from 10 sources