166.70.97.3 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 166.70.97.3 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

🟡 Low Risk — 35/100

Geographic Location

Host and Network Information

  • View other sources: Spamhaus VirusTotal Shodan AbuseIPDB
  • Country: United States
  • Noticed: 30 times
  • Protocols Attacked: telnet
  • Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
  • Tor Node: No

Tags

  • bruteforce
  • cyber security
  • digital ocean
  • ioc
  • malicious
  • Nextray
  • phishing
  • telnet

Attack Log References

Whois Information

NetRange: 166.70.0.0 - 166.70.255.255 CIDR: 166.70.0.0/16 NetName: XMISSION-166-70-0-0 NetHandle: NET-166-70-0-0-1 Parent: NET166 (NET-166-0-0-0-0) NetType: Direct Allocation OriginAS: Organization: XMission, L.C. (XMIS) RegDate: 1997-02-19 Updated: 2024-09-05 Comment: Geofeed: https://asset.xmission.com/geofeed/geofeed.csv Comment: Comment: Please use the abuse@xmission.com email address for all Comment: complaints regarding UCE (spam), copyright violations, security Comment: intrusions, and other suspected network abuse sourcing from Comment: XMission networks. DO NOT COPY your complaint to any other ARIN Comment: XMission POC's or email addresses on the XMission network. Comment: Failure to comply with this statement will result in your Comment: complaint being ignored. Ref: https://rdap.arin.net/registry/ip/166.70.0.0 OrgName: XMission, L.C. OrgId: XMIS Address: 51 E 400 S Address: Suite 000 City: Salt Lake City StateProv: UT PostalCode: 84111-2753 Country: US RegDate: 1993-11-15 Updated: 2024-10-04 Comment: Geofeed: https://asset.xmission.com/geofeed/geofeed.csv Comment: Comment: Please use the abuse@xmission.com email address for all Comment: complaints regarding UCE (spam), copyright violations, Comment: security intrusions, and other suspected network abuse sourcing from Comment: XMission networks. DO NOT COPY your complaint to any other ARIN Comment: XMission POC's or email addresses on the XMission network. Comment: Failure to comply with this statement will result in your Comment: complaint being ignored. Ref: https://rdap.arin.net/registry/entity/XMIS OrgTechHandle: TECHN5-ARIN OrgTechName: Technical Support OrgTechPhone: +1-801-539-0852 OrgTechEmail: support@xmission.com OrgTechRef: https://rdap.arin.net/registry/entity/TECHN5-ARIN OrgAbuseHandle: NETAB-ARIN OrgAbuseName: Netabuse Manager OrgAbusePhone: +1-801-539-0852 OrgAbuseEmail: abuse@xmission.com OrgAbuseRef: https://rdap.arin.net/registry/entity/NETAB-ARIN OrgNOCHandle: NETWO22-ARIN OrgNOCName: Network Manager OrgNOCPhone: +1-801-539-0852 OrgNOCEmail: net-manager@xmission.com OrgNOCRef: https://rdap.arin.net/registry/entity/NETWO22-ARIN RAbuseHandle: NETAB-ARIN RAbuseName: Netabuse Manager RAbusePhone: +1-801-539-0852 RAbuseEmail: abuse@xmission.com RAbuseRef: https://rdap.arin.net/registry/entity/NETAB-ARIN RNOCHandle: NETWO22-ARIN RNOCName: Network Manager RNOCPhone: +1-801-539-0852 RNOCEmail: net-manager@xmission.com RNOCRef: https://rdap.arin.net/registry/entity/NETWO22-ARIN RTechHandle: TECHN5-ARIN RTechName: Technical Support RTechPhone: +1-801-539-0852 RTechEmail: support@xmission.com RTechRef: https://rdap.arin.net/registry/entity/TECHN5-ARIN