192.160.102.166
Classification: Suspicious
192.160.102.166 is a suspicious IP address. Linked to Tor malware. Reported by 15 threat sources, last seen 2026-03-02. Network: AS395089 Hextet Systems.
MITRE ATT&CK associations
Malware families: TOR (S0183)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Proxy | IPWhois.io | 2026-03-02 00:21:29 | 2026-03-02 00:21:29 | anonymization | |
| Proxy | FireHOL | 2023-01-02 22:31:25 | 2025-10-07 05:51:28 | anonymization | |
| ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic | Emerging Threats | 2018-06-20 22:15:51 | 2024-04-21 20:09:11 | anonymization | |
| TOR Exit Node | TorProject.org | 2019-11-03 13:31:16 | 2023-05-18 03:27:37 | anonymization anonymizer | |
| ET TOR Known Tor Exit Node TCP Traffic | Emerging Threats | 2018-06-26 07:46:48 | 2022-02-08 03:40:11 | anonymization | |
| Malicious Host | HoneyDB | 2019-07-14 00:00:00 | 2022-01-10 00:00:00 | malicious-activity | |
| Malware | Hybrid-Analysis | 2021-07-19 10:31:08 | 2021-12-13 15:17:36 | ||
| HTTP Spammer | Sblam | 2020-11-25 12:40:28 | 2021-07-20 06:35:37 | malicious-activity | |
| DDoS attack | Blocklist.net.ua | 2019-11-27 07:23:48 | 2021-05-25 07:12:02 | malicious-activity | |
| HTTP Spammer | StopForumSpam.com | 2020-11-27 23:04:07 | 2021-05-17 09:42:44 | malicious-activity | |
| HTTP Spammer | Cleantalk.org | 2018-07-13 07:09:38 | 2021-04-28 09:02:41 | ||
| Anonymizer | Maltiverse Research Team | 2020-11-22 09:13:42 | 2021-03-29 16:44:53 | anonymizer | |
| HTTP Attacker | BadIPs | 2018-06-07 06:56:09 | 2020-12-14 02:14:08 | malicious-activity | |
| DDoS Attacker | Blocklist.net.ua | 2020-03-26 01:18:34 | 2020-06-26 09:01:57 | ||
| SSH Attacker | Blocklist.net.ua | 2018-06-15 09:03:00 | 2019-09-03 01:04:14 | ||
| ET COMPROMISED Known Compromised or Hostile Host Traffic UDP | Emerging Threats | 2019-07-06 01:56:54 | 2019-08-30 08:07:02 | ||
| ET COMPROMISED Known Compromised or Hostile Host Traffic TCP | Emerging Threats | 2019-07-06 01:56:53 | 2019-08-29 08:08:55 | ||
| SSH Attacker | Telefonica CO SOC | 2019-02-23 15:58:03 | 2019-08-16 09:58:06 | ||
| SSH Attacker | Greynoise | 2019-03-10 00:00:00 | 2019-07-07 00:00:00 | ||
| Parasite traffic on site slavablagov.com. | Blocklist.net.ua | 2019-06-07 00:46:37 | 2019-06-07 07:24:48 | ||
| Tor | Hybrid-Analysis | 2019-03-22 14:01:56 | 2019-03-22 14:01:56 | S0183 Tor | |
| Parasite traffic on site test-drives.autopark.in.ua. | Blocklist.net.ua | 2018-09-16 07:07:53 | 2018-10-22 07:07:00 | ||
| Parasite traffic on site news.autopark.in.ua. | Blocklist.net.ua | 2018-09-06 07:05:39 | 2018-09-06 07:05:39 | ||
| ET TOR Known Tor Relay/Router (Not Exit) Node UDP Traffic | Emerging Threats | 2018-06-20 22:15:51 | 2018-08-29 07:36:45 | ||
| ET TOR Known Tor Exit Node UDP Traffic | Emerging Threats | 2018-06-20 22:15:21 | 2018-08-29 07:36:15 | ||
| Generic.Malware | Hybrid-Analysis | 2018-08-07 20:15:26 | 2018-08-07 20:15:26 | ||
| Proxy | Maltiverse Research Team | 2018-04-09 11:00:08 | 2018-04-09 11:00:08 | ||
| HTTP Spammer | Myip.ms | 2018-02-09 21:17:17 | 2018-02-09 21:17:17 |
Tags
tor anonymization anonymizer abuse bot apache attacker 404 script kiddies noscript ssh bruteforceWhois information
- AS name
- AS395089 Hextet Systems
- AS registry
- arin
- AS date
- 2015-07-09 00:00:00
- AS CIDR
- 192.160.102.0/24
- CIDR
- 192.160.102.0/24
- Registrant
- Hextet Systems
- Address
- 227 Houde Dr
- City
- Winnipeg
- State
- MB
- Postal code
- R3X 1V3
- Country
- CA — Canada 🇨🇦
- Contact email
- [email protected], [email protected]
- First indexed
- 2018-02-09 21:17:17
- Last updated
- 2026-03-02 00:21:31