198.16.66.156 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 198.16.66.156 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

🟠 Elevated — 60/100

Geographic Location

Host and Network Information

  • View other sources: Spamhaus VirusTotal Shodan AbuseIPDB
  • Country: Netherlands
  • Network: AS174 cogent communications
  • Noticed: 42 times
  • Protocols Attacked: Anonymous Proxy
  • Countries Attacked: Australia, Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
  • Open Ports: 427, 443, 80
  • Tor Node: No

Tags

  • auth0cic case
  • compromise
  • cyber security
  • har file
  • http archive
  • ioc
  • malicious
  • Nextray
  • okta
  • okta customer
  • okta security
  • okta service
  • okta support
  • phishing
  • system log

MITRE ATT&CK TTPs

  • T1105 - Ingress Tool Transfer
  • T1134 - Access Token Manipulation

Passive DNS

  • nl86.trafcfy.com

Attack Log References

Whois Information

NetRange: 198.16.64.0 - 198.16.127.255 CIDR: 198.16.64.0/18 NetName: FDCSERVERS NetHandle: NET-198-16-64-0-1 Parent: NET198 (NET-198-0-0-0-0) NetType: Direct Allocation OriginAS: AS174, AS30058 Organization: FDCservers.net (FDCSE) RegDate: 2012-08-02 Updated: 2018-10-12 Ref: https://rdap.arin.net/registry/ip/198.16.64.0 OrgName: FDCservers.net OrgId: FDCSE City: Destin StateProv: FL PostalCode: 32540 Country: US RegDate: 2003-05-20 Updated: 2021-06-09 Ref: https://rdap.arin.net/registry/entity/FDCSE OrgAbuseHandle: ABUSE438-ARIN OrgAbuseName: ABUSE department OrgAbusePhone: +1-312-423-6675 OrgAbuseEmail: abuse@fdcservers.net OrgAbuseRef: https://rdap.arin.net/registry/entity/ABUSE438-ARIN OrgTechHandle: ABUSE438-ARIN OrgTechName: ABUSE department OrgTechPhone: +1-312-423-6675 OrgTechEmail: abuse@fdcservers.net OrgTechRef: https://rdap.arin.net/registry/entity/ABUSE438-ARIN OrgNOCHandle: ABUSE438-ARIN OrgNOCName: ABUSE department OrgNOCPhone: +1-312-423-6675 OrgNOCEmail: abuse@fdcservers.net OrgNOCRef: https://rdap.arin.net/registry/entity/ABUSE438-ARIN NetRange: 198.16.66.0 - 198.16.67.255 CIDR: 198.16.66.0/23 NetName: FDCSERVERS-AMSTERDAM2 NetHandle: NET-198-16-66-0-1 Parent: FDCSERVERS (NET-198-16-64-0-1) NetType: Reallocated OriginAS: AS174, AS30058 Organization: FDCservers.net (FDCSE-21) RegDate: 2016-01-27 Updated: 2019-05-23 Ref: https://rdap.arin.net/registry/ip/198.16.66.0 OrgName: FDCservers.net OrgId: FDCSE-21 Address: Haarlemmerstraatweg 135 City: Halfweg StateProv: NORTH HOLLAND PostalCode: 1165 MK Country: NL RegDate: 2015-11-09 Updated: 2015-11-09 Ref: https://rdap.arin.net/registry/entity/FDCSE-21 OrgTechHandle: ABUSE438-ARIN OrgTechName: ABUSE department OrgTechPhone: +1-312-423-6675 OrgTechEmail: abuse@fdcservers.net OrgTechRef: https://rdap.arin.net/registry/entity/ABUSE438-ARIN OrgAbuseHandle: ABUSE438-ARIN OrgAbuseName: ABUSE department OrgAbusePhone: +1-312-423-6675 OrgAbuseEmail: abuse@fdcservers.net OrgAbuseRef: https://rdap.arin.net/registry/entity/ABUSE438-ARIN network:Auth-Area:198.16.64.0/18 network:Class-Name:network network:OrgName:FDCservers.net network:OrgID;I:FDCSE network:City:Chicago network:StateProv:IL network:PostalCode:60604 network:Country:US network:NetRange:198.16.64.0 - 198.16.127.255 network:CIDR:198.16.64.0/18 network:NetName:FDCSERVERS network:OrgAbuseHandle:ABUSE438-ARIN network:OrgAbuseName:Abuse Department network:OrgAbusePhone:+1-312-423-6675 network:OrgAbuseEmail:abuse@fdcservers.net network:OrgNOCHandle:ABUSE438-ARIN network:OrgNOCName:Tech Support network:OrgNOCPhone:+1-312-423-6675 network:OrgNOCEmail:abuse@fdcservers.net network:OrgTechHandle:ABUSE438-ARIN network:OrgTechName:Tech Support network:OrgTechPhone:+1-312-423-6675 network:OrgTechEmail:abuse@fdcservers.net