IPHighVerifiedSignal 88/100
167.86.72.220
Location
Nuremberg, Bavaria
ASN
AS51167
Contabo GmbH
First Seen
Jun 4, 2026
Last Seen
Jun 6, 2026
Jun 4
First Seen
20d ago
Jun 6
Last Seen
18d ago
40
Reports
source reports
95%
Confidence
high
13/91
VirusTotal
detections
Found in 40 reports. Confidence: high. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
95%
Signal Score
88 / 100
IDS Rule
Yes
Threat Context
Network Information
Country
Germany
RegionNuremberg, Bavaria
ASNAS51167
OrganizationContabo GmbH
IP Category
⟲
Proxy
Proxy server
⬢
Hosting
Hosting provider
Feed Intelligence Summary
40 reports95% confidence
Activity Timeline
Jun 6Jun 4
Threat Activity Heatmap
· Peak: 2026-06-04LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
40
Critical
3mo
40
Critical
Threat ScoreHigh Risk
88
SIGNAL
Signal Score
95%
Confidence
40
Reports
First seenJun 4, 2026
Last seenJun 6, 2026
Verified IOC
GeolocationDE
CountryGermany
LocationNuremberg, Bavaria
ASNAS51167
OrgContabo GmbH
Coords49.4050, 11.1617
ProxyHosting
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
highFirst detected 20 days ago · Last seen 18 days ago
Appeared in 40 threat reports from 10 sources
Used by malware: Mozi, XWorm, Pegasus, Lumma, Nanocore, SocGholish, Remcos, Rhysida, AsyncRAT, XMRig, Stealc, Mirai, Vidar, Havoc, Sliver