IOC Radar
IPMediumSignal 34/100

144.24.202.66

Location
FranceFrance
Marseille, ENG
ASN
AS31898
Oracle Corporation
First Seen
Feb 11, 2025
Last Seen
Mar 31, 2026
Feb 11
First Seen
488d ago
Mar 31
Last Seen
75d ago
16
Reports
source reports
34%
Confidence
medium
Found in 16 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
34%
Signal Score
34 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

28 techniques

Network Information

CountryFRFrance
RegionMarseille, ENG
ASNAS31898
OrganizationOracle Corporation

Feed Intelligence Summary

16 reports34% confidence
16
Source reports
34%
Confidence score
Category tags
abuseaccess controlactive scanactive scanningattackauthentication attackauthentication attemptsautomated attacksautomated threatbad reputationbotnetbotnet activitybrute forcebrute force attackcommand and controlcowrie honeypotcredential accesscredential stuffingctadata exfiltrationdata store exposuredecoy systemdistributed attackseuropeexploitation activityfail2ban triggeredfailed login attemptsfrfranceftp brute forcegb-hosted serverhttp brute forceidentity & access exploitationindicatorinjection activityintrusion detectionlogin attacklogin attemptsmalicious activitymalicious softwaremalwarenetworknetwork intrusionnetwork scanningnetwork securitypassword attacksprocess injectionreconnaissanceresearchedrule based detectionscannersecurity operationssecurity policysftp attackssh attackssh monitoringt1021t1021.001t1021.004t1040t1041t1055t1059t1059.004t1071.001t1078t1078.001t1110t1110.001t1110.002t1110.003t1110.004t1133t1190t1486t1496t1499.001t1499.002t1499.003t1565t1595t1595.001t1595.002t1595.003threat actorthreat intelligencethreat preventiontor nodeunited kingdom

Activity Timeline

1 total obs
Mar 31Mar 31

Threat Activity Heatmap

· Peak: 2026-03-31
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Intelligence SummaryAI Generated

This Indicator of Compromise (IOC), an IPv4 address identified as 144.24.202.66, represents a significant threat primarily associated with persistent brute-force attacks and network scanning activities. Its presence in multiple reputable threat intelligence feeds, coupled with a score exceeding 33, strongly indicates its involvement in malicious operations aimed at gaining unauthorized access. Organizations potentially exposed to this IOC face a heightened risk of credential compromise, system e…

Threat ScoreLow Risk
34
SIGNAL
Signal Score
34%
Confidence
16
Reports
First seenFeb 11, 2025
Last seenMar 31, 2026
GeolocationFR
CountryFrance
LocationMarseille, ENG
ASNAS31898
OrgOracle Corporation
Coords51.5095, -0.0955

VirusTotal

Not checked

WHOIS

description
Banned by Fail2Ban [sshd]
raw
inetnum: 144.24.0.0 - 144.24.255.255 netname: ORACLE-UK descr: Oracle Corp UK Ltd descr: Oracle Parkway Thames Valley Park 550 descr: Reading, RG6 1RA country: GB org: ORG-OSA29-RIPE geoloc: 51.522373 -0.629251 admin-c: DM12756-RIPE tech-c: DM12756-RIPE status: LEGACY mnt-by: ORCL-MNT mnt-lower: ORCL-MNT mnt-routes: ORCL-MNT created: 2003-12-09T13:47:05Z last-modified: 2019-12-04T13:13:46Z source: RIPE organisation: ORG-OSA29-RIPE org-name: Oracle Svenska AB country: SE org-type: LIR address: R�sundav�gen 4 Box 1429 address: 169 57 address: Solna address: SWEDEN phone: +4684773376 fax-no: +4684773376 abuse-c: AR17199-RIPE mnt-ref: RIPE-NCC-HM-MNT mnt-ref: ORCL-MNT mnt-by: RIPE-NCC-HM-MNT mnt-by: ORCL-MNT created: 2010-12-02T11:14:19Z last-modified: 2020-12-16T12:47:27Z source: RIPE # Filtered person: Domain Administrator address: 500 Oracle Parkway, M/S 501ip3 address: Redwood Shores, CA, address: 94065 address: US phone: +1.6505062220 nic-hdl: DM12756-RIPE mnt-by: ORCL-MNT created: 2014-06-09T11:09:41Z last-modified: 2014-06-09T11:09:41Z source: RIPE
references
https://blog.edie.io/2020/04/30/diy-ip-threat-feed/, https://github.com/tankmek/threatfeed, https://redpiranha.net, https://github.com/telekom-security/tpotce

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 2 months ago
Appeared in 16 threat reports