IPMediumSignal 0/100
172.206.147.171
Location
San Antonio, Texas
ASN
AS8075
Microsoft Azure Cloud (southcentralus)
First Seen
Mar 4, 2025
Last Seen
Aug 5, 2025
Found in 1 report. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
0%
Signal Score
0 / 100
IDS Rule
No
Threat Context
Tags
Network Information
Country
United States
RegionSan Antonio, Texas
ASNAS8075
OrganizationMicrosoft Azure Cloud (southcentralus)
Feed Intelligence Summary
1 report0% confidence
1
Source reports
0%
Confidence score
Category tags
indicatornetworkresearched
Activity Timeline
Aug 5Aug 5
Threat Activity Heatmap
· Peak: 2025-08-05LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Intelligence SummaryAI Generated
This Indicator of Compromise (IOC) has been identified as a low-risk entity, specifically an IP address, with a score of 0.0 and an explicit 'Yes' whitelist status. This indicates that the IP address is considered benign and not associated with malicious activities, reducing the urgency for immediate containment or incident response. The designation primarily suggests that this IP address is part of an approved or known legitimate service, and its mere presence in threat intelligence feeds does …
Threat ScoreLow Risk
0
SIGNAL
Signal Score
0%
Confidence
1
Reports
First seenMar 4, 2025
Last seenAug 5, 2025
GeolocationUS
CountryUnited States
LocationSan Antonio, Texas
ASNAS8075
OrgMicrosoft Azure Cloud (southcentralus)
Coords29.4167, -98.5000
VirusTotal
Not checked
WHOIS
- description
- 2024-11-22T19:59:45.000Z Honeypot : Honeytrap : Source: 172.206.147.171 : Port: 4786 Message: {'payload': {'sha512_hash': '31a666a86c63f22a455779e8810bb55c1ea561390da7d08b4face798de4d11ca255eaa6ed34d7d42a5e4923d4228c9fc39a03f8675e0cb032cebccb826f6d925', 'md5_hash': '7535e9a4b754d2a16ba640f31143ef7a', 'length': 24, 'data_hex': '4d474c4e44445f39392e31382e32362e32315f343738360a'}, 'protocol': 'tcp'}
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 1 year ago · Last seen 10 months ago
Appeared in 1 threat report