IOC Radar
IPHighVerifiedSignal 86/100

85.130.116.122

Location
BulgariaBulgaria
Plovdiv, Plovdiv
ASN
AS13124
Blizoo Media and Broadband EAD
First Seen
Jun 2, 2026
Last Seen
Jun 23, 2026
Jun 2
First Seen
24d ago
Jun 23
Last Seen
3d ago
462
Reports
source reports
95%
Confidence
high
Found in 462 reports. Confidence: high. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
95%
Signal Score
86 / 100
IDS Rule
Yes

Network Information

CountryBGBulgaria
RegionPlovdiv, Plovdiv
ASNAS13124
OrganizationBlizoo Media and Broadband EAD

Feed Intelligence Summary

462 reports95% confidence
AT
Abuse.ch ThreatFox
3d ago
3722 IOCs in report
AT
Abuse.ch ThreatFox
3d ago
3737 IOCs in report
AT
Abuse.ch ThreatFox
3d ago
3736 IOCs in report
AT
Abuse.ch ThreatFox
3d ago
3739 IOCs in report
AT
Abuse.ch ThreatFox
3d ago
3469 IOCs in report
AT
Abuse.ch ThreatFox
3d ago
3506 IOCs in report
AT
Abuse.ch ThreatFox
3d ago
3669 IOCs in report
AT
Abuse.ch ThreatFox
3d ago
3837 IOCs in report
AT
Abuse.ch ThreatFox
3d ago
3839 IOCs in report
AT
Abuse.ch ThreatFox
3d ago
3833 IOCs in report

Activity Timeline

462 total obs
Jun 23Jun 2

Threat Activity Heatmap

· Peak: 2026-06-08
Less
More
Mon
Wed
Fri
Jun
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
24h
0
Dormant
7d
71
Critical
30d
462
Critical
3mo
462
Critical
Threat ScoreHigh Risk
86
SIGNAL
Signal Score
95%
Confidence
462
Reports
First seenJun 2, 2026
Last seenJun 23, 2026
Verified IOC
GeolocationBG
CountryBulgaria
LocationPlovdiv, Plovdiv
ASNAS13124
OrgBlizoo Media and Broadband EAD
Coords42.1513, 24.7518

VirusTotal

Not checked

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

high
First detected 24 days ago · Last seen 3 days ago
Appeared in 462 threat reports from 10 sources
Associated with: Kimsuky, Hive, Sandworm, Turla, Play
Used by malware: XMRig, Remcos, DarkComet, FormBook, Rhysida, NjRAT, Mozi, XWorm, NetWire, Pegasus, Nanocore, Rhadamanthys, WannaCry, AsyncRAT, Lumma, Dridex, XorDDoS, SocGholish, QakBot, Cobalt Strike, META Stealer, PowerShell Empire, Gh0st RAT, Play, Stealc, Mirai, Vidar, Metasploit, Hive, Bumblebee, Gootloader, Havoc, Sliver, RedLine