216.73.217.22

Silent Push Traffic Origin Data Combined with Residential Proxy Data Uncovers Suspicious Chinese VPN

· Published 10/02/2026 09:09 · Modified 10/02/2026 10:16

Export JSON

Essential information

Published
10/02/2026 09:09
Modified
10/02/2026 10:16
Tags
2026-02-10 geolocation spoofing residential proxies vpn
Related entities
3 observables, 1 techniques (mitre), 61 others

Description

An investigation using Silent Push's Traffic Origin and residential proxy data revealed a suspicious Chinese provider. The analysis focused on IP address 205.198.91.155, which showed unusual traffic from Russia, China, Myanmar, Iran, and Venezuela. This IP was linked to the domain lvcha.in, hosting a Chinese-language . Further investigation uncovered nearly 50 related domains promoting the same , suggesting attempts to bypass country-level firewalls. The 's infrastructure was found to use and had connections to various high-risk countries. This case study demonstrates the importance of verifying physical and technical behaviors of connections to protect against fraud and state-sponsored actors using stolen identities and spoofed locations.

External references