IOC Radar
IPMediumSignal 81/100

161.153.73.17

Location
United StatesUnited States
Phoenix, Arizona
ASN
AS31898
Oracle Cloud Infrastructure (us-phoenix-1)
First Seen
Apr 14, 2026
Last Seen
May 11, 2026
Apr 14
First Seen
60d ago
May 11
Last Seen
33d ago
9
Reports
source reports
81%
Confidence
medium
Found in 9 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
81%
Signal Score
81 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

7 techniques

Network Information

CountryUSUnited States
RegionPhoenix, Arizona
ASNAS31898
OrganizationOracle Cloud Infrastructure (us-phoenix-1)

Feed Intelligence Summary

9 reports81% confidence
9
Source reports
81%
Confidence score
Category tags
active scanactive scanningattackbrute forcebrute force attackbrute-forcecredential accesscredential stuffingexploitation activityidentity & access exploitationindicatormalicious activitymalwarenetworknorth americapassword attacksreconnaissanceresearchedscannersshssh attackt1110.001t1110.002t1110.003t1110.004t1595.001t1595.002t1595.003threat actortor nodeunited statesus

Activity Timeline

1 total obs
May 11May 11

Threat Activity Heatmap

· Peak: 2026-05-11
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreHigh Risk
81
SIGNAL
Signal Score
81%
Confidence
9
Reports
First seenApr 14, 2026
Last seenMay 11, 2026
GeolocationUS
CountryUnited States
LocationPhoenix, Arizona
ASNAS31898
OrgOracle Cloud Infrastructure (us-phoenix-1)
Coords33.4660, -112.0120

VirusTotal

Not checked

WHOIS

raw
NetRange: 161.153.0.0 - 161.153.255.255 CIDR: 161.153.0.0/16 NetName: ORACLE-4 NetHandle: NET-161-153-0-0-1 Parent: NET161 (NET-161-0-0-0-0) NetType: Direct Allocation OriginAS: Organization: Oracle Corporation (ORACLE-4) RegDate: 2024-07-01 Updated: 2024-07-01 Ref: https://rdap.arin.net/registry/ip/161.153.0.0 OrgName: Oracle Corporation OrgId: ORACLE-4 Address: 2300 Oracle Way Address: Attn: Domain Administrator City: Austin StateProv: TX PostalCode: 78741 Country: US RegDate: 1988-04-29 Updated: 2024-11-07 Ref: https://rdap.arin.net/registry/entity/ORACLE-4 OrgTechHandle: ORACL1-ARIN OrgTechName: ORACLE NIS OrgTechPhone: +1-800-633-0738 OrgTechEmail: [email protected] OrgTechRef: https://rdap.arin.net/registry/entity/ORACL1-ARIN OrgAbuseHandle: NISAM-ARIN OrgAbuseName: Network Information Systems Abuse Management OrgAbusePhone: +1-800-633-0738 OrgAbuseEmail: [email protected] OrgAbuseRef: https://rdap.arin.net/registry/entity/NISAM-ARIN OrgRoutingHandle: ORACL2-ARIN OrgRoutingName: ORACLEROUTING OrgRoutingPhone: +1-800-392-2999 OrgRoutingEmail: [email protected] OrgRoutingRef: https://rdap.arin.net/registry/entity/ORACL2-ARIN

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 2 months ago · Last seen 1 month ago
Appeared in 9 threat reports