IOC Radar
IPHighVerifiedSignal 86/100

91.134.139.176

Location
FranceFrance
Roubaix, Hauts-de-France
ASN
AS16276
OVH
First Seen
Jun 2, 2026
Last Seen
Jun 14, 2026
Jun 2
First Seen
23d ago
Jun 14
Last Seen
12d ago
242
Reports
source reports
95%
Confidence
high
Found in 242 reports. Confidence: high. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
95%
Signal Score
86 / 100
IDS Rule
Yes

Network Information

CountryFRFrance
RegionRoubaix, Hauts-de-France
ASNAS16276
OrganizationOVH

IP Category

Hosting
Hosting provider

Feed Intelligence Summary

242 reports95% confidence
AT
Abuse.ch ThreatFox
Jun 14, 2026
2818 IOCs in report
AT
Abuse.ch ThreatFox
Jun 14, 2026
2934 IOCs in report
AT
Abuse.ch ThreatFox
Jun 14, 2026
2946 IOCs in report
AT
Abuse.ch ThreatFox
Jun 14, 2026
2945 IOCs in report
AT
Abuse.ch ThreatFox
Jun 14, 2026
2950 IOCs in report
AT
Abuse.ch ThreatFox
Jun 14, 2026
2906 IOCs in report
AT
Abuse.ch ThreatFox
Jun 14, 2026
2910 IOCs in report
AT
Abuse.ch ThreatFox
Jun 14, 2026
2908 IOCs in report
AT
Abuse.ch ThreatFox
Jun 14, 2026
2905 IOCs in report
AT
Abuse.ch ThreatFox
Jun 13, 2026
2953 IOCs in report

Activity Timeline

242 total obs
Jun 14Jun 2

Threat Activity Heatmap

· Peak: 2026-06-08
Less
More
Mon
Wed
Fri
Jun
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
24h
0
Dormant
7d
0
Dormant
30d
242
Critical
3mo
242
Critical
Threat ScoreHigh Risk
86
SIGNAL
Signal Score
95%
Confidence
242
Reports
First seenJun 2, 2026
Last seenJun 14, 2026
Verified IOC
GeolocationFR
CountryFrance
LocationRoubaix, Hauts-de-France
ASNAS16276
OrgOVH
Coords50.6924, 3.2011
Hosting

VirusTotal

Not checked

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

high
First detected 23 days ago · Last seen 12 days ago
Appeared in 242 threat reports from 10 sources
Associated with: Kimsuky, LockBit, Sandworm, Turla, Hive, Play
Used by malware: AsyncRAT, Mozi, NetWire, Pegasus, Nanocore, SocGholish, XMRig, Remcos, Lumma, Dridex, DarkComet, Rhysida, XorDDoS, NjRAT, XWorm, Cobalt Strike, Sliver, PowerShell Empire, META Stealer, Hive, Bumblebee, Play, Stealc, Gootloader, Mirai, Vidar, Metasploit, RedLine, LockBit, Havoc