IPLowSignal 100/100
162.214.226.8
Location
Phoenix, Utah
ASN
AS31898
Oracle Corporation
First Seen
Sep 13, 2021
Last Seen
Mar 3, 2026
Sep 13
First Seen
1731d ago
Mar 3
Last Seen
100d ago
14
Reports
source reports
99%
Confidence
low
0/91
VirusTotal
detections
Found in 14 reports. Confidence: low. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
99%
Signal Score
100 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Network Information
Country
United States
RegionPhoenix, Utah
ASNAS31898
OrganizationOracle Corporation
Feed Intelligence Summary
14 reports99% confidence
14
Source reports
99%
Confidence score
Category tags
abuseaccess controlactive scanningattackaustraliaauthenticationauthentication attackauto-generated securityautomated attackbotnetbrute forcebrute force attackbrute force attemptcommand and controlcommunication protocolcowrie honeypotcredential accesscredential stuffingctadata exfiltrationdecoy systemdistributed attacksindicatorintrusion detectionlogin attackmalicious activitymalicious softwaremalwarenetworknetwork attacksnetwork intrusionnetwork securitynetwork service scanningnorth americaoceaniapassword attackpassword attacksprocess injectionreconnaissanceremote accessresearchedscanscannersecurity policysftp attackssh attackssh monitoringt1021.004t1040t1041t1055t1059t1059.004t1071.001t1078t1078.004t1110t1110.001t1110.002t1110.003t1110.004t1133t1486t1496t1499.001t1499.002t1499.003t1565t1588.004t1589t1589.002t1595t1595.001t1595.002t1595.003tcp protocolthreat actorthreat intelligencethreat preventionunited states
Activity Timeline
Mar 3Mar 3
Threat Activity Heatmap
· Peak: 2026-03-03LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Threat ScoreHigh Risk
100
SIGNAL
Signal Score
99%
Confidence
14
Reports
First seenSep 13, 2021
Last seenMar 3, 2026
GeolocationUS
CountryUnited States
LocationPhoenix, Utah
ASNAS31898
OrgOracle Corporation
Coords37.7510, -97.8220
WHOIS
- description
- Host bruteforcing SSH
- raw
- NetRange: 162.214.0.0 - 162.215.255.255 CIDR: 162.214.0.0/15 NetName: UNIFIEDLAYER-NETWORK-15 NetHandle: NET-162-214-0-0-1 Parent: NET162 (NET-162-0-0-0-0) NetType: Direct Allocation OriginAS: Organization: Unified Layer (BLUEH-2) RegDate: 2013-05-22 Updated: 2013-12-19 Comment: This space is statically assigned. Comment: Comment: -----BEGIN CERTIFICATE-----MIIDjjCCAnYCCQDwxS01pbJjyDANBgkqhkiG9w0BAQsFADCBiDELMAkGA1UEBhMCVVMxCzAJBgNVBAgMAlVUMQ4wDAYDVQQHDAVQcm92bzEMMAoGA1UECgwDRUlHMQ8wDQYDVQQLDAZOZXRvcHMxEjAQBgNVBAMMCWF3c19ieW9pcDEpMCcGCSqGSIb3DQEJARYaZWlnLW5ldC10ZWFtQGVuZHVyYW5jZS5jb20wHhcNMTgxMTEyMTg1ODAwWhcNMjgxMTA5MTg1ODAwWjCBiDELMAkGA1UEBhMCVVMxCzAJBgNVBAgMAlVUMQ4wDAYDVQQHDAVQcm92bzEMMAoGA1UECgwDRUlHMQ8wDQYDVQQLDAZOZXRvcHMxEjAQBgNVBAMMCWF3c19ieW9pcDEpMCcGCSqGSIb3DQEJARYaZWlnLW5ldC10ZWFtQGVuZHVyYW5jZS5jb20wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDhYkPGFYv/471uwfSNRUiGwx1WiF7iM0GYbmwHBY7KAOruObkhZrgVUwFXVVlZZED1BPxigOsgGdUVQ01BYBTxcBCaxim9hnJW3dVROdZg4HS0zuHnntveWfhkalBeGJGPhsdyE7zULg8jf+18I9fRtG32Qmm6E35CuDp9HwKrHlhgqIYIQ9JQiUykkdwfgWr4ho1JSP4pl/79WFgrv+0Hw7Ml0E2ZoTLIkgacr+9kLxmg82q+xWegYmcfPRC/Eh+g5Ln4mYkyzyLlTSyuHNnGI0wi3QYUX3ITBoPeex1ly5rPxYA3KM+4boKcxFR1DGS0RU+jzZnhKbxVw6YP5VpPAgMBAAEwDQYJKoZIhvcNAQELBQADggEBAMGzeUx283P9ophMPjguepuCn+vWl+ZLh0qjCneT6vS29/COAaR97obMfpnI4XPIbdj8Jch3M10q1yvjptzkeRcSN2MXCiC6QiNG7D4yeUu+dlQz3o9vBAp8asfG/jfU7qx2wxRLkf8vi1q+v52Z5jPpnUAZ1au6urhbSTpE/VLDGcBPxVIQQeohbzJvT/0WRbUVPojZ9ixKX7lI93V79na74AOD1d5/4PzW5myxQjNZpThR/mBG7C0c9sdI04/fxDAY7XTlwHxwaTxslZYhUtEIyqztIo80P7LGdhuKNBVbPP2rvrf2z7K78gsCMnLfAtUtM4Cv62k5H/4uE7WBwKI=-----END CERTIFICATE----- Ref: https://rdap.arin.net/registry/ip/162.214.0.0 OrgName: Unified Layer OrgId: BLUEH-2 Address: 1958 South 950 East City: Provo StateProv: UT PostalCode: 84606 Country: US RegDate: 2006-08-08 Updated: 2025-07-24 Ref: https://rdap.arin.net/registry/entity/BLUEH-2 ReferralServer: rwhois://rwhois.unifiedlayer.com:4321 OrgAbuseHandle: EIGAB1-ARIN OrgAbuseName: EIG-Abuse Mitigation OrgAbusePhone: +1-877-659-6181 OrgAbuseEmail: [email protected] OrgAbuseRef: https://rdap.arin.net/registry/entity/EIGAB1-ARIN OrgNOCHandle: ENO74-ARIN OrgNOCName: EIG Network Operations OrgNOCPhone: +1-877-659-6181 OrgNOCEmail: [email protected] OrgNOCRef: https://rdap.arin.net/registry/entity/ENO74-ARIN OrgTechHandle: ENO74-ARIN OrgTechName: EIG Network Operations OrgTechPhone: +1-877-659-6181 OrgTechEmail: [email protected] OrgTechRef: https://rdap.arin.net/registry/entity/ENO74-ARIN OrgAbuseHandle: NOC2320-ARIN OrgAbuseName: Network Operations Center OrgAbusePhone: +1-801-765-9400 OrgAbuseEmail: [email protected] OrgAbuseRef: https://rdap.arin.net/registry/entity/NOC2320-ARIN
- references
- https://redpiranha.net, https://github.com/telekom-security/tpotce
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
lowFirst detected 4 years ago · Last seen 3 months ago
Appeared in 14 threat reports