IOC Radar
IPLowSignal 43/100

150.171.109.184

Location
South AfricaSouth Africa
Nairobi, Nairobi County
ASN
AS8075
Microsoft Corporation
First Seen
Apr 17, 2026
Last Seen
May 31, 2026
Apr 17
First Seen
63d ago
May 31
Last Seen
19d ago
6
Reports
source reports
43%
Confidence
low
0/91
VirusTotal
detections
Found in 6 reports. Confidence: low. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
43%
Signal Score
43 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

3 techniques

Network Information

CountryZASouth Africa
RegionNairobi, Nairobi County
ASNAS8075
OrganizationMicrosoft Corporation

Feed Intelligence Summary

6 reports43% confidence
6
Source reports
43%
Confidence score
Category tags
acceptaccess ta0001active scanadded activeafricaalibaba cloudall domainall hostnameall reportanchoranchor httpsappleartifacts vascioattackbackdoorbad reputationbrian sabeysbrothbrute forcebruteforcebypasschecks creationchristopher ahmannck idck matrixclickcode integritycommandcrypdata uploaddelete servicedenmarkdns attackdoin itdomaindomainsdopple aidump filedynadot llcemailsencryptencryptionenter sceuropeexclude suggesexpiration httpexploitation activityextr dataextr pleaseextra datafailedfilesfiles domainfiles relatedflagformformatfull reportsget httpgooglehall evanshelp dnshichinahostnamehtml documenthtml internethttphttpshunterhybrididron anviframeinclude datainclude reviewindicatorindicators showinfo initialinitial accessinquest labsinsurance carriers and related activitiesiocsiot securitykenyakill-chain exploitationkill-chain reconnaissancelaw enforcementlearnlearn moreliberalliberal friendslink initiallittle endianlow-risklucas achamalwaremetamitre attname serversname tacticsnamecheap incnetworknext generationnone googlenorth americaosintotx descriptionotx logopackingpalantirian abusepassive dnspathpcapphishingplease subpoemporkbun llcporn revengepresent decpresent febpresent janprotectquasi governmentreferenreimerrelated pulsesrelated tagsreport spamresearchedrl httprole titlesabeysabey data centerssabey pornsafe browsingsc datasc pulsescanse httpsnitspamspam brianspam deletespawnsssl certificatestop showstringsswippert1110t1110.001t1189 networkt1595.001tbmvidtelnetthe brother sabeythreat actortitletor nodetrojantyp domaintype indicatorunicode textunitedunited statesurlsutf8 textvessel statevictim won casevirtoolwindows ntwireshark pcapwormxxx videos

Activity Timeline

1 total obs
May 31May 31

Threat Activity Heatmap

· Peak: 2026-05-31
Less
More
Mon
Wed
Fri
Jun
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Threat ScoreMedium Risk
43
SIGNAL
Signal Score
43%
Confidence
6
Reports
First seenApr 17, 2026
Last seenMay 31, 2026
GeolocationZA
CountrySouth Africa
LocationNairobi, Nairobi County
ASNAS8075
OrgMicrosoft Corporation
Coords-1.2921, 36.8219

VirusTotal

0/ 91vendors flagged
0% detection rateJun 5, 2026

WHOIS

raw
NetRange: 150.171.0.0 - 150.171.255.255 CIDR: 150.171.0.0/16 NetName: MSFT NetHandle: NET-150-171-0-0-1 Parent: APNIC-ERX-150 (NET-150-0-0-0-0) NetType: Direct Allocation OriginAS: Organization: Microsoft Corporation (MSFT) RegDate: 2015-11-24 Updated: 2021-12-14 Ref: https://rdap.arin.net/registry/ip/150.171.0.0 OrgName: Microsoft Corporation OrgId: MSFT Address: One Microsoft Way City: Redmond StateProv: WA PostalCode: 98052 Country: US RegDate: 1998-07-10 Updated: 2025-06-10 Comment: To report suspected security issues specific to traffic emanating from Microsoft online services, including the distribution of malicious content or other illicit or illegal material through a Microsoft online service, please submit reports to: Comment: * https://cert.microsoft.com. Comment: Comment: For SPAM and other abuse issues, such as Microsoft Accounts, please contact: Comment: * [email protected]. Comment: Comment: To report security vulnerabilities in Microsoft products and services, please contact: Comment: * [email protected]. Comment: Comment: For legal and law enforcement-related requests, please contact: Comment: * [email protected] Comment: Comment: For routing, peering or DNS issues, please Comment: contact: Comment: * [email protected] Ref: https://rdap.arin.net/registry/entity/MSFT OrgTechHandle: BEDAR6-ARIN OrgTechName: Bedard, Dawn OrgTechPhone: +1-425-538-6637 OrgTechEmail: [email protected] OrgTechRef: https://rdap.arin.net/registry/entity/BEDAR6-ARIN OrgTechHandle: MRPD-ARIN OrgTechName: Microsoft Routing, Peering, and DNS OrgTechPhone: +1-425-882-8080 OrgTechEmail: [email protected] OrgTechRef: https://rdap.arin.net/registry/entity/MRPD-ARIN OrgTechHandle: IPHOS5-ARIN OrgTechName: IPHostmaster, IPHostmaster OrgTechPhone: +1-425-538-6637 OrgTechEmail: [email protected] OrgTechRef: https://rdap.arin.net/registry/entity/IPHOS5-ARIN OrgTechHandle: SINGH683-ARIN OrgTechName: Singh, Prachi OrgTechPhone: +1-425-707-5601 OrgTechEmail: [email protected] OrgTechRef: https://rdap.arin.net/registry/entity/SINGH683-ARIN OrgRoutingHandle: CHATU3-ARIN OrgRoutingName: Chaturmohta, Somesh OrgRoutingPhone: +1-425-882-8080 OrgRoutingEmail: [email protected] OrgRoutingRef: https://rdap.arin.net/registry/entity/CHATU3-ARIN OrgAbuseHandle: MAC74-ARIN OrgAbuseName: Microsoft Abuse Contact OrgAbusePhone: +1-425-882-8080 OrgAbuseEmail: [email protected] OrgAbuseRef: https://rdap.arin.net/registry/entity/MAC74-ARIN

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

low
First detected 2 months ago · Last seen 19 days ago
Appeared in 6 threat reports