IPv4 address
172.66.167.179
Last fetched
172.66.167.179 is announced in 172.66.160.0/20 by CLOUDFLARENET - Cloudflare, Inc. and geolocates to CA. 172.66.167.179 is not listed on any threat feed indexed by WhisperGraph; reconciled level NONE.
Threat posture
0threat score (procedure-native scale)
NONENo threats observed.
- Threat feeds listing this
- 0
- Verdict coverage
- no-data
Nutrition Label
Attribution
- Announced prefix
- 172.66.160.0/20
- Announcing network
- CLOUDFLARENET - Cloudflare, Inc.
- RIR-registered prefix
- 172.64.0.0/13
- RPKI
- valid
Abuse contact
Report abuse from 172.66.167.179 to the address block's holder first and copy the announcing network. These are the abuse contacts WhisperGraph holds for the block and the network.
- Address block and network (as13335)
- abuse@cloudflare.com
Network context
- SaaS or cloud vendor range
- cloudflare
Signals on the covering block
- prefix-age-anomalyThis block's registration age is inconsistent with its routing history.
Anycast detection
This does not appear to be an anycast address on the three signals Canon evaluates: reverse DNS, announced-prefix width and the announcing network's peer count.
Reverse DNS
- subtest.intertubes.cc
- callloom.com
- adminsupport.callloom.com
- api.callloom.com
- www.api.callloom.com
- app.callloom.com
- autodiscover.callloom.com
- backend-peoplelookup.callloom.com
- blog.callloom.com
- www.blog.callloom.com
- callmeapi.callloom.com
- core.callloom.com
- cpanel.callloom.com
- cpcalendars.callloom.com
- cpcontacts.callloom.com
- demo.callloom.com
- www.demo.callloom.com
- develop.callloom.com
- developers.callloom.com
- dialmonitor.callloom.com
- get.callloom.com
- www.get.callloom.com
- mail.callloom.com
- new.callloom.com
- pay.callloom.com
- portal.callloom.com
- receiver.callloom.com
- v2.callloom.com
- webdisk.callloom.com
- webmail.callloom.com
- www.callloom.com
- northsideimports.com
- staging.northsideimports.com
- www.northsideimports.com
- salonappy.com
- admin-sandbox.salonappy.com
- ar.salonappy.com
- cs.salonappy.com
- da.salonappy.com
- de.salonappy.com
- el.salonappy.com
- es.salonappy.com
- fi.salonappy.com
- fr.salonappy.com
- hi.salonappy.com
- hu.salonappy.com
- it.salonappy.com
- ja.salonappy.com
- ko.salonappy.com
- mobile-api.salonappy.com
Geographic detail
- City
- Toronto, CA
- Country
- CA
- Dominant city of the prefix
- Toronto, CA
Threat-feed evidence
History
Related pages
Pivot from 172.66.167.179 into the prefix, network and country that carry it.
Queries
This address's full card — routing attribution, reverse DNS and listed feeds.
MATCH (ip:IPV4 {name: $ip})
OPTIONAL MATCH (ip)-[:BELONGS_TO]->(rp:REGISTERED_PREFIX)
OPTIONAL MATCH (ip)-[:ANNOUNCED_BY]->(ap:ANNOUNCED_PREFIX)
OPTIONAL MATCH (a:ASN)-[:ROUTES]->(ap)
OPTIONAL MATCH (a)-[:HAS_NAME]->(an:ASN_NAME)
OPTIONAL MATCH (ip)-[:LOCATED_IN]->(city:CITY)
OPTIONAL MATCH (ip)-[:HAS_COUNTRY]->(ipc:COUNTRY)
WITH ip, rp, ap, a, an, city, ipc
LIMIT 10
WITH ip,
collect(rp.name) AS registeredPrefixes,
collect(rp.abuseEmail) AS registeredAbuseEmails,
collect({prefix: ap.name, asn: a.name, network: an.name, isMoas: ap.isMoas, rpkiStatus: ap.rpkiStatus, isAnycast: ap.isAnycast, dominantCity: ap.dominantCity, abuseEmail: ap.abuseEmail, networkAbuseEmail: a.abuseEmail}) AS announcements,
collect(city.name) AS cities,
collect(ipc.name) AS countries,
collect(a.name) AS announcerNames,
head(collect(a)) AS primaryAsn,
head(collect(ap)) AS primaryPrefix
OPTIONAL MATCH (primaryPrefix)-[:CONFLICTS_WITH]->(conflict:ASN)
WITH ip, registeredPrefixes, registeredAbuseEmails, announcements, cities, countries, announcerNames, primaryAsn,
collect(conflict.name) AS conflictAsns
CALL { WITH primaryAsn MATCH (primaryAsn)-[:ROUTES]->(p:ANNOUNCED_PREFIX) RETURN count(p) AS asnPrefixCount }
CALL { WITH primaryAsn MATCH (primaryAsn)-[:BGP_NEIGHBOR]-(peer:ASN) RETURN count(peer) AS asnPeerCount }
RETURN ip.name AS name,
ip.verdictLevel AS verdictLevel,
ip.verdictScore AS verdictScore,
ip.verdictBlocking AS verdictBlocking,
ip.verdictCoverage AS verdictCoverage,
ip.verdictAdvisory AS verdictAdvisory,
ip.threatSources AS threatSources,
ip.threatFirstSeen AS threatFirstSeen,
ip.threatLastSeen AS threatLastSeen,
ip.isTor AS isTor,
ip.isVpn AS isVpn,
ip.isProxy AS isProxy,
ip.isC2 AS isC2,
ip.isPhishing AS isPhishing,
registeredPrefixes, registeredAbuseEmails, announcements, cities, countries, announcerNames, conflictAsns,
asnPrefixCount, asnPeerCountRun yourself →Network context — Tor exit relays, attributed actors, and the covering blocks' signals, cloud region and vendor.
MATCH (ip:IPV4 {name: $ip})
OPTIONAL MATCH (ip)-[:OPERATES_EXIT_NODE]->(tor:TOR_RELAY)
WITH ip, count(tor) AS torRelays
OPTIONAL MATCH (ip)-[:ATTRIBUTED_TO]->(actor:ACTOR)
WITH ip, torRelays, collect(actor.name)[0..5] AS actors
OPTIONAL MATCH (ip)-[:BELONGS_TO]->(p:PREFIX)
WITH torRelays, actors, collect(p.name) AS coveringPrefixes
UNWIND (CASE WHEN size(coveringPrefixes) = 0 THEN [null] ELSE coveringPrefixes END) AS pn
OPTIONAL MATCH (cp:PREFIX {name: pn})
OPTIONAL MATCH (cp)-[:HAS_SIGNAL]->(sig:THREAT_SIGNAL_TYPE)
OPTIONAL MATCH (cp)-[:PREFIX_IN_REGION]->(reg:CLOUD_REGION)
OPTIONAL MATCH (cp)-[:DELEGATED_TO]->(v:VENDOR)
RETURN torRelays, actors,
collect(sig.name) AS signals,
collect(reg.name) AS regions,
collect(v.name) AS vendorsRun yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.