IOC Radar
IPMediumSignal 0/100

172.217.20.66

Location
United StatesUnited States
Amsterdam, North Holland
ASN
AS15169
Google LLC
First Seen
Apr 8, 2026
Last Seen
Apr 8, 2026
Apr 8
First Seen
74d ago
Apr 8
Last Seen
74d ago
2
Reports
source reports
0%
Confidence
medium
Found in 2 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
0%
Signal Score
0 / 100
IDS Rule
No
Threat Context
Tags

Network Information

CountryUSUnited States
RegionAmsterdam, North Holland
ASNAS15169
OrganizationGoogle LLC

Feed Intelligence Summary

2 reports0% confidence
2
Source reports
0%
Confidence score
Category tags
indicatornetworkresearched

Activity Timeline

1 total obs
Apr 8Apr 8

Threat Activity Heatmap

· Peak: 2026-04-08
Less
More
Mon
Wed
Fri
Jun
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Intelligence SummaryAI Generated

This report details an Indicator of Compromise (IOC) identified as an IPv4 address, `172.217.20.66`. Despite its inclusion in certain threat intelligence feeds, this IOC has been explicitly whitelisted and carries a very low threat score of 0.0, signaling its benign nature. The presence of this IP address in threat intelligence should not be interpreted as an indication of malicious activity or an imminent threat to organizational assets. Instead, it points to legitimate infrastructure or a know…

Threat ScoreLow Risk
0
SIGNAL
Signal Score
0%
Confidence
2
Reports
First seenApr 8, 2026
Last seenApr 8, 2026
GeolocationUS
CountryUnited States
LocationAmsterdam, North Holland
ASNAS15169
OrgGoogle LLC
Coords52.3676, 4.9041

VirusTotal

Not checked

WHOIS

description
A Cuckoo executable, for MS Windows, runs at 12:12:57 on the morning of 11 November, 2024, and ends in an unauthorised binary that ends up in a box full of data.- rip.exe tied to a gov domain is a treat.

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 2 months ago · Last seen 2 months ago
Appeared in 2 threat reports