103.229.73.122 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 103.229.73.122 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

🟠 Elevated — 47/100

Geographic Location

Host and Network Information

  • View other sources: Spamhaus VirusTotal Shodan AbuseIPDB
  • Country: Indonesia
  • Network: AS55660 pt master web network
  • Noticed: 1 time
  • Open Ports: 2082, 2083, 2086, 2087, 2096, 443, 80, 993
  • Tor Node: No
  • Associated Malware Samples: 2

Tags

  • agent tesla
  • appdata
  • cobalt strike
  • cobaltstrike
  • desktop
  • domains
  • email
  • emotet
  • emotet malware
  • emotet trojan
  • emotet virus
  • eternalblue
  • fake net
  • fallout
  • first
  • flawedammyy
  • hashes
  • http get
  • iocs ip
  • malware
  • microsoft
  • ms17010
  • powershell code
  • qbot
  • systembc
  • trickbot
  • trojan
  • united
  • vba code
  • wannacry
  • wannycry
  • wcry

MITRE ATT&CK TTPs

  • T1027 - Obfuscated Files or Information
  • T1053 - Scheduled Task/Job
  • T1080 - Taint Shared Content
  • T1102 - Web Service
  • T1210 - Exploitation of Remote Services
  • T1486 - Data Encrypted for Impact
  • T1490 - Inhibit System Recovery
  • T1566 - Phishing

Passive DNS

  • metavisualar.com

Whois Information

inetnum: 103.229.72.0 - 103.229.75.255 netname: IDNIC-CDT-ID descr: PT Cyber Data Technology descr: Corporate / Direct Member IDNIC descr: Cyber Building 9th Floor descr: Jl. Kuningan Barat No.8 descr: Jakarta Selatan 12710 admin-c: TH585-AP tech-c: TH585-AP country: ID mnt-by: MNT-APJII-ID mnt-routes: MAINT-ID-CDT mnt-irt: IRT-CDT-ID status: ASSIGNED PORTABLE last-modified: 2014-04-08T03:21:03Z irt: IRT-CDT-ID address: PT CYBER DATA TECHNOLOGY address: Cyber Building 9th Floor address: Jl. Kuningan Barat No.8 address: Jakarta Selatan 12710 e-mail: abuse@cyberdata.co.id abuse-mailbox: abuse@cyberdata.co.id admin-c: TH585-AP tech-c: TH585-AP mnt-by: MAINT-ID-CDT last-modified: 2018-05-31T22:30:33Z person: Tommie Haryanto address: Cyber Building 9th Floor address: Jl. Kuningan Barat No.8 address: DKI Jakarta 12710 country: ID phone: +62-21-5266899 fax-no: +62-21-5276899 e-mail: Tommie@masterweb.net nic-hdl: TH585-AP mnt-by: MAINT-ID-MWN last-modified: 2010-05-26T03:48:01Z inetnum: 103.229.72.0 - 103.229.75.255 netname: IDNIC-CDT-ID descr: PT Cyber Data Technology descr: Corporate / Direct Member IDNIC descr: Cyber Building 9th Floor descr: Jl. Kuningan Barat No.8 descr: Jakarta Selatan 12710 admin-c: TH585-AP tech-c: TH585-AP country: ID mnt-by: MNT-APJII-ID mnt-routes: MAINT-ID-CDT mnt-irt: IRT-CDT-ID status: ASSIGNED PORTABLE last-modified: 2014-04-08T03:21:03Z irt: IRT-CDT-ID address: PT CYBER DATA TECHNOLOGY address: Cyber Building 9th Floor address: Jl. Kuningan Barat No.8 address: Jakarta Selatan 12710 e-mail: abuse@cyberdata.co.id abuse-mailbox: abuse@cyberdata.co.id admin-c: TH585-AP tech-c: TH585-AP mnt-by: MAINT-ID-CDT last-modified: 2014-03-19T10:21:16Z person: Tommie Haryanto address: Cyber Building 9th Floor address: Jl. Kuningan Barat No.8 address: DKI Jakarta 12710 country: ID phone: +62-21-5266899 fax-no: +62-21-5276899 e-mail: Tommie@masterweb.net nic-hdl: TH585-AP mnt-by: MAINT-ID-MWN last-modified: 2010-05-26T03:48:01Z