104.16.149.172 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 104.16.149.172 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Likely Malicious Host 🟠 54/100

Host and Network Information

  • Mitre ATT&CK IDs: T1012 - Query Registry, T1018 - Remote System Discovery, T1027.002 - Software Packing, T1033 - System Owner/User Discovery, T1043 - Commonly Used Port, T1057 - Process Discovery, T1059.002 - AppleScript, T1094 - Custom Command and Control Protocol, T1112 - Modify Registry, T1129 - Shared Modules, T1176 - Browser Extensions, T1215 - Kernel Modules and Extensions, T1449 - Exploit SS7 to Redirect Phone Calls/SMS, T1457 - Malicious Media Content, T1491 - Defacement, T1497 - Virtualization/Sandbox Evasion, T1583.005 - Botnet, TA0003 - Persistence, TA0005 - Defense Evasion, TA0011 - Command and Control

  • Tags: aaaa, address, alerts, all octoseek, all search, amazonaes, analysis date, apple ios, april, as15169 google, as16625 akamai, as20940, as2914 ntt, as3257 gtt, as46606, as54113, as54990, as6185 apple, as62597 nsone, as62729, as6453 tata, as6461 zayo, as714 apple, as7843 charter, august, av detections, awful, backdoor, body, body length, bouvet island, ck id, ck matrix, cloudflarenet, com laude, communicating, contacted, contacted urls, copy, creation date, crypto, cyber criminal, date, december, document, domain, domains ii, dropped, encrypt, entries, execution, expiration date, february, filehash, files, file type, final url, first, formbook, for privacy, found, germany unknown, goldfinder, goldmax, gvb gelimed, hacktool, hallrender, hashes, hashes hashes, headers, historical ssl, hostnames, http, http response, ids detections, intellectual property theft, iocs, ip address, ireland unknown, j490s6lkpppw, january, jpeg, june, kb body, lfqprnkje8dni0, location united, malicious, malicious file transfers, malware, march, maui ransomware, mb super, moved, ms word, name servers, network, next, njrat, none related, october, open, optimizer, otx octoseek, passive dns, paste, premium, probe, problems, pulse pulses, pulse submit, ransomware, record type, record value, referrer, related pulses, resolutions, sality, scan endpoints, scheme, search, self, servers, serving ip, sha256, show, showing, sibot, snatch, ssl certificate, startpage, status code, submitters, summary iocs, tags none, target, targeting, threat, threat network, threat roundup, trojan, tsara brashears, ttl value, tulach, twitter, type name, united, united kingdom, unknown, url analysis, url http, urls, urls http, urls https, urls url, utc submissions, virtool, whitelisted, whois record, whois whois, win32, win32mydoom feb, worm, yara detections

  • View other sources: Spamhaus VirusTotal

  • Country:
  • Network:
  • Noticed: 2 times
  • Protocols Attacked: Anonymous Proxy
  • Countries Attacked: Canada, United States of America
  • Passive DNS Results: dgc.blockr.io ltc.blockr.io two.blockr.io blockr.io mec.blockr.io qrk.blockr.io tbtc.blockr.io btc.blockr.io

Malware Detected on Host

Count: 1123 2d36230599acc2164a2c63e336a059cd5af405aaaa93cd39be91d91577025346 a3bb76926f593d81d92c9f11a452ea7675f81d33de0c3cc2843b0ddb990cffe5 7baf630a2ddc7cf88be0b1746f85e7abc5a65e8967a294b1a437d298fafea65c f25cf4c3815260c616761c052dcb1ffcdefab98add91778b0917da7873e9f8f9 940aafaedf4ef86ae84557f065df7cd45621724f534aceabeca61ad9e87cf96d d554f76489661f9babbdc0f083509558dd91f6cb0bb3960f7600e433384adc86 d821296ad5698aa552cad2daf54c525fabfb488ed094af4aca18e68ed7e1c7bd ab299702866be62d28d7342d85feaef85fb35d1b690581cdb06d86b4b14b7fb1 3a85815b187d0f05c6ff54e7fb29dc1c9dacd003789db71a27b6aaa7a53e82b6 da08d48725ac940a99b25c676fbc800af49ccb7f26eb6194044a192fd50b3717

Open Ports Detected

2082 2083 2086 2087 2095 443 80 8080 8443 8880

Map

Whois Information

Links to attack logs

anonymous-proxy-ip-list-2025-06-22

Share on: