IOC Radar
IPMediumSignal 70/100

150.171.109.146

Location
South AfricaSouth Africa
Nairobi, Western Cape
ASN
AS8075
Microsoft Corporation
First Seen
Apr 9, 2026
Last Seen
Jun 3, 2026
Apr 9
First Seen
62d ago
Jun 3
Last Seen
7d ago
7
Reports
source reports
70%
Confidence
medium
Found in 7 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
70%
Signal Score
70 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

48 techniques

Network Information

CountryZASouth Africa
RegionNairobi, Western Cape
ASNAS8075
OrganizationMicrosoft Corporation

Feed Intelligence Summary

7 reports70% confidence
7
Source reports
70%
Confidence score
Category tags
a50 dataacceptactive scanaddress rangeafricaagentai reportalertaalertsall ipv4allocation typeamazon dataamazonawsamerica asnamerica flaganalysis dateanguillaapplayerappleappleremotesupportaptascii textauthenticationav detectionav detectionsavast avgbackbackdoorbazaarbodybootkitbridgebrute forcebuildidca ocspcabinet archivecidrck idclickcloud infrastructurecnmicrosoft tlscodecode signingcommandcommand & controlcommand linecontent lengthcontent typecreation datecreato touccrypt32d4n timestampdatadata uploaddefense evasiondelphidigice rsadiscovery attdns attackdropped infodropsdump filedynamicloaderedgeeducationelfelf executableelf infoelf64 operationemailsencryptencryptionenter scentity adsn1entrieserrorexec amd6464executable fileexpiresfriexploitexploitation activityextr dataextrac dataextraction dataextre dataextri datafailedfalsefilesfiles cfindfirst counterflagsformatfoundfull pathg2 rsageofencegermany as8560get httpglobalgmtnguest systemhacking toolshacktool codehandlehashes ohid ivhighhtml documenthtml internethttpsidentity & access exploitationids detectionsimpactinclude reviewindicatorinfoinfo processinsideinstalliot securityipv4kekenyakevsight toxlayer protocollearnlegacy adminlevellibrarylinuxlinux verdictlittle endianlocallog idlogmeinlow riskmadagascarmal_elf_systembc_ratmalwaremcafeemedia centermediummitre attmitre attackmodify systemmovedmrasnms windowsmsiemutexes nothingmwdbname logmeinname serversname tacticsnetherlands asnnetworknetwork infonetwork namenextnext generationnlrnsrdbnorth americanothingobserved dnsobserved rmmocspoffset sizeorg logmeinoverview zenboxparent pidpathpattern matchpayloadpcappe filepegasuspegasus relatedperforms dnsphishingpleasepng imagepost httppost naprocessprocesses extraqnapcryptqueryransomransomwareratratiorecord valueregistry keysremotelyanywhereresearchedrestartreverse dnsrgbarmm domainrootsalfordsc datasearchsectigo limitedsectigo rsaselfself-deleteserver caserversservice scanservice-scansh certificshowsigning defensesizeslcc2smtpsocradarsouth africaspanspawnsssdeepstop typstringsstrongstwasummer stsystembcsysvt1003t1005t1012t1027t1033t1036t1045t1046t1055t1057t1059t1060t1064t1069t1069.002t1070t1071t1071.001t1082t1083t1095t1105t1106t1112t1113t1129t1140t1480t1480.002t1485t1486t1497t1518t1539t1542t1543t1543 privilet1543.002t1547t1548t1552t1553t1553.002t1555t1562t1564t1573t1574t1592ta0004 crthreat actortitletitle errortls snitls webtrojantrojandroppertrumusicu extractiounicode textunitedunited statesunixurlsusutf8 textuwagavercelverdictwhois serverwhois showwindowwindows ntwinmmwireshark pcapwritewrite cx msedgex poweredx vercelyara detectionsza

Activity Timeline

1 total obs
Jun 3Jun 3

Threat Activity Heatmap

· Peak: 2026-06-03
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Threat ScoreMedium Risk
70
SIGNAL
Signal Score
70%
Confidence
7
Reports
First seenApr 9, 2026
Last seenJun 3, 2026
GeolocationZA
CountrySouth Africa
LocationNairobi, Western Cape
ASNAS8075
OrgMicrosoft Corporation
Coords-33.9249, 18.4241

VirusTotal

Not checked

WHOIS

raw
NetRange: 150.171.0.0 - 150.171.255.255 CIDR: 150.171.0.0/16 NetName: MSFT NetHandle: NET-150-171-0-0-1 Parent: APNIC-ERX-150 (NET-150-0-0-0-0) NetType: Direct Allocation OriginAS: Organization: Microsoft Corporation (MSFT) RegDate: 2015-11-24 Updated: 2021-12-14 Ref: https://rdap.arin.net/registry/ip/150.171.0.0 OrgName: Microsoft Corporation OrgId: MSFT Address: One Microsoft Way City: Redmond StateProv: WA PostalCode: 98052 Country: US RegDate: 1998-07-10 Updated: 2025-06-10 Comment: To report suspected security issues specific to traffic emanating from Microsoft online services, including the distribution of malicious content or other illicit or illegal material through a Microsoft online service, please submit reports to: Comment: * https://cert.microsoft.com. Comment: Comment: For SPAM and other abuse issues, such as Microsoft Accounts, please contact: Comment: * [email protected]. Comment: Comment: To report security vulnerabilities in Microsoft products and services, please contact: Comment: * [email protected]. Comment: Comment: For legal and law enforcement-related requests, please contact: Comment: * [email protected] Comment: Comment: For routing, peering or DNS issues, please Comment: contact: Comment: * [email protected] Ref: https://rdap.arin.net/registry/entity/MSFT OrgTechHandle: BEDAR6-ARIN OrgTechName: Bedard, Dawn OrgTechPhone: +1-425-538-6637 OrgTechEmail: [email protected] OrgTechRef: https://rdap.arin.net/registry/entity/BEDAR6-ARIN OrgTechHandle: MRPD-ARIN OrgTechName: Microsoft Routing, Peering, and DNS OrgTechPhone: +1-425-882-8080 OrgTechEmail: [email protected] OrgTechRef: https://rdap.arin.net/registry/entity/MRPD-ARIN OrgTechHandle: IPHOS5-ARIN OrgTechName: IPHostmaster, IPHostmaster OrgTechPhone: +1-425-538-6637 OrgTechEmail: [email protected] OrgTechRef: https://rdap.arin.net/registry/entity/IPHOS5-ARIN OrgTechHandle: SINGH683-ARIN OrgTechName: Singh, Prachi OrgTechPhone: +1-425-707-5601 OrgTechEmail: [email protected] OrgTechRef: https://rdap.arin.net/registry/entity/SINGH683-ARIN OrgRoutingHandle: CHATU3-ARIN OrgRoutingName: Chaturmohta, Somesh OrgRoutingPhone: +1-425-882-8080 OrgRoutingEmail: [email protected] OrgRoutingRef: https://rdap.arin.net/registry/entity/CHATU3-ARIN OrgAbuseHandle: MAC74-ARIN OrgAbuseName: Microsoft Abuse Contact OrgAbusePhone: +1-425-882-8080 OrgAbuseEmail: [email protected] OrgAbuseRef: https://rdap.arin.net/registry/entity/MAC74-ARIN

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 2 months ago · Last seen 7 days ago
Appeared in 7 threat reports