IOC Radar
IPMediumSignal 74/100

197.248.15.66

Location
KenyaKenya
Nairobi, Nairobi County
ASN
AS37061
Safaricom Limited
First Seen
Apr 8, 2026
Last Seen
May 23, 2026
Apr 8
First Seen
81d ago
May 23
Last Seen
36d ago
12
Reports
source reports
74%
Confidence
medium
15/91
VirusTotal
detections
Found in 12 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
74%
Signal Score
74 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

7 techniques

Network Information

CountryKEKenya
RegionNairobi, Nairobi County
ASNAS37061
OrganizationSafaricom Limited

Feed Intelligence Summary

12 reports74% confidence
12
Source reports
74%
Confidence score
Category tags
abuseactive scanactive scanningafricaapacheapache attackeraptattackbad reputationbrute forcebrute force attackbrute-forcebruteforcecredential accesscredential stuffingddosddos attackexploitation activityexploited hosthackingidentity & access exploitationindicatorkekenyamalicious activitymalwarenetworkpassword attacksreconnaissanceresearchedscannersshssh attackt1110.001t1110.002t1110.003t1110.004t1595.001t1595.002t1595.003threat actortor nodeweb app attack

Activity Timeline

1 total obs
May 23May 23

Threat Activity Heatmap

· Peak: 2026-05-23
Less
More
Mon
Wed
Fri
Jun
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreHigh Risk
74
SIGNAL
Signal Score
74%
Confidence
12
Reports
First seenApr 8, 2026
Last seenMay 23, 2026
GeolocationKE
CountryKenya
LocationNairobi, Nairobi County
ASNAS37061
OrgSafaricom Limited
Coords-1.2921, 36.8219

VirusTotal

15/ 91vendors flagged
16% detection rateJun 5, 2026

WHOIS

raw
inetnum: 197.248.0.0 - 197.248.63.255 netname: Safaricom-Business descr: For Safaricom KENYA Enterprise Business Unit country: KE admin-c: JM27-AFRINIC admin-c: DA1485-AFRINIC tech-c: DA1485-AFRINIC status: ASSIGNED PA remarks: For Safaricom KENYA Enterprise Business Unit mnt-by: MNT-SAF2004 source: AFRINIC # Filtered parent: 197.248.0.0 - 197.248.255.255 person: Domain Admin address: Safaricom Limited address: Safaricom House address: POBox 46350-00100 Nairobi address: Kenya address: Nairobi address: Kenya phone: tel:+254-020427 nic-hdl: DA1485-AFRINIC mnt-by: MNT-SAF2004 source: AFRINIC # Filtered person: John Muita address: P.O Box 66827, 00800 address: Nairobi address: Kenya address: Nairobi address: Kenya phone: tel:+254-722-002829 fax-no: tel:+254-722-003272 nic-hdl: JM27-afrinic mnt-by: GENERATED-UNS1E7EXFG6F7TJILQ9DMMHDN4Y0VRSV-MNT source: AFRINIC # Filtered route: 197.248.0.0/18 descr: Safaricom Limited origin: AS33771 mnt-by: MNT-SAF2004 source: AFRINIC # Filtered

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 2 months ago · Last seen 1 month ago
Appeared in 12 threat reports