104.16.85.20 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 104.16.85.20 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Likely Malicious Host 🟠 60/100

Host and Network Information

  • Mitre ATT&CK IDs: T1003 - OS Credential Dumping, T1005 - Data from Local System, T1012 - Query Registry, T1027 - Obfuscated Files or Information, T1030 - Data Transfer Size Limits, T1031 - Modify Existing Service, T1035 - Service Execution, T1036 - Masquerading, T1040 - Network Sniffing, T1041 - Exfiltration Over C2 Channel, T1043 - Commonly Used Port, T1045 - Software Packing, T1047 - Windows Management Instrumentation, T1053 - Scheduled Task/Job, T1055.012 - Process Hollowing, T1055 - Process Injection, T1056.001 - Keylogging, T1056 - Input Capture, T1057 - Process Discovery, T1059.005 - Visual Basic, T1059.006 - Python, T1059.007 - JavaScript, T1059 - Command and Scripting Interpreter, T1060 - Registry Run Keys / Startup Folder, T1063 - Security Software Discovery, T1068 - Exploitation for Privilege Escalation, T1070 - Indicator Removal on Host, T1071.001 - Web Protocols, T1071.003 - Mail Protocols, T1071.004 - DNS, T1071 - Application Layer Protocol, T1081 - Credentials in Files, T1082 - System Information Discovery, T1083 - File and Directory Discovery, T1090 - Proxy, T1095 - Non-Application Layer Protocol, T1096 - NTFS File Attributes, T1100 - Web Shell, T1105 - Ingress Tool Transfer, T1106 - Native API, T1110.002 - Password Cracking, T1110 - Brute Force, T1111 - Two-Factor Authentication Interception, T1112 - Modify Registry, T1114 - Email Collection, T1119 - Automated Collection, T1122 - Component Object Model Hijacking, T1129 - Shared Modules, T1140 - Deobfuscate/Decode Files or Information, T1143 - Hidden Window, T1158 - Hidden Files and Directories, T1173 - Dynamic Data Exchange, T1176 - Browser Extensions, T1179 - Hooking, T1189 - Drive-by Compromise, T1203 - Exploitation for Client Execution, T1204 - User Execution, T1210 - Exploitation of Remote Services, T1222 - File and Directory Permissions Modification, T1410 - Network Traffic Capture or Redirection, T1423 - Network Service Scanning, T1427 - Attack PC via USB Connection, T1445 - Abuse of iOS Enterprise App Signing Key, T1449 - Exploit SS7 to Redirect Phone Calls/SMS, T1450 - Exploit SS7 to Track Device Location, T1453 - Abuse Accessibility Features, T1472 - Generate Fraudulent Advertising Revenue, T1480 - Execution Guardrails, T1485 - Data Destruction, T1491 - Defacement, T1496 - Resource Hijacking, T1497.001 - System Checks, T1497 - Virtualization/Sandbox Evasion, T1518.001 - Security Software Discovery, T1518 - Software Discovery, T1543 - Create or Modify System Process, T1546.015 - Component Object Model Hijacking, T1546 - Event Triggered Execution, T1547.001 - Registry Run Keys / Startup Folder, T1547 - Boot or Logon Autostart Execution, T1552.001 - Credentials In Files, T1552 - Unsecured Credentials, T1555.003 - Credentials from Web Browsers, T1555 - Credentials from Password Stores, T1560 - Archive Collected Data, T1563 - Remote Service Session Hijacking, T1564 - Hide Artifacts, T1566 - Phishing, T1568 - Dynamic Resolution, T1569 - System Services, T1573 - Encrypted Channel, T1574 - Hijack Execution Flow, T1583.005 - Botnet, T1588.004 - Digital Certificates, T1588 - Obtain Capabilities, TA0002 - Execution, TA0003 - Persistence, TA0004 - Privilege Escalation, TA0005 - Defense Evasion, TA0006 - Credential Access, TA0007 - Discovery, TA0009 - Collection, TA0010 - Exfiltration, TA0011 - Command and Control

  • Tags: 1996, 1tzv, 5555, a1ginaprincipal, a9dia, aaaa, abxcde, accept, accept ch, accept encoding, access denied, access ta0001, acint, activator, active related, active threat, activity, adams co, adaptivebee, adblock pro, address, address domain, address first, address google, address server, addtopayload, adload, adobe air, adobe portable, a domains, adversaries, adware, adware affiliate, af81 http, a fleecy, agency, agent, agent tesla, ai, aig, AIG Claims, akamaias, alerts, alexa, alexa proxy, alexa top, alf features, algorithm, alina, all octoseek, all scoreblue, all search, amazon, amazon 02, amazon02, amazonaes, amazon rsa, analysis, analysis date, analyzer paste, analyzer threat, android, andromeda, anonymisation, anonymizer, ansi, antivirus, antivm_network_adapters, antivm_queries_computername, a nxdomain, apache, api blog, appdata, apple, appleaustin, apple engineering, apple ios, apple notepad, apple phone, apple unlocker, applicunwnt, april, apt, artemis, as13335, as133618, as13768 aptum, as139021, as14061, as14720 gamma, as15169, as15169 google, as16276, as16552 tiggee, as16625 akamai, as19237 omnis, as19527 google, as20068 hawk, as20940, as212913 fop, as22169 omnis, as22489, as22612, as23393, as2914 ntt, as29789, as30148 sucuri, as31898 oracle, as36459, as39122, as396982, as396982 google, as397240, as397241, as40509, as4230 claro, as43350 nforce, as44273 host, as47846, as49453, as54113, as55286, as60558 phoenix, as61969 team, as62597 nsone, as6724 strato, as7018 att, as7922 comcast, as8068, as8075, as autonomous, ascii text, asn15169, asn16276, asn209242, asn4583, asn as16509, asnone, asnone united, asyncrat, athena, attack, attacking, attention, august, available from, avast avg, av detections, awful, azorult, azorult cnc, azure tls, back, backdoor, background, bambernek, bambernek gen, bambernek simda, banco, bandoo, bank, banker, basic, bayrob, bazaloader, b body, beach research, beginstring, behav, beijing gu, benjamin, best targets, betabot, bid site, binary file, bitrat, bitrep, blackhat, blacklist, blacklist http, blacklist https, blacknet rat, blocklist, body, body doctype, body html, body length, boot, bootstrap.libp2p.io, bot, botnet campaign, botnet command and control, botnetwork, bradesco, brazil, brazil unknown, breached, brent kimball, brian sabey, browser, c2, C2, camera usage, canada unknown, cape, catalog tree, cbe cnalphassl, center, centerchecks, certificate, cgb stgreater, checked url, checkin, checks amount, checks_debugger, child teen content illegal, china, china as4134, china education, china telecom, china unicom, Christopher Pool, chrome, ch ua, cins active, ciphersuite, cisco, cisco umbrella, citadel, ck id, ck matrix, ck techniques, class, classic poems, classname, cleaner, click, clickjacking, clipper dos, close, cloudflare, cloudflarenet, cloud host, cname, cnc, cnc feodo, cnc server, cndigicert sha2, cngts ca, cnus, coalition et, cobalt strike, cobaltstrike, code, coinminer, collection, collections, colorado, com laude, command, command and control, command_and_control, commerce, communicating, comodo rsa, comodo valkyrie, company limited, compiler, computer, conduit, cong ty, connect azurepc, connection, contact, contacted, contacted urls, contact phone, contained, content generating, content length, content reputation, content scraper, content type, control server, cookie, copy, copy md5, copyright, copy sha1, copy sha256, core, corruption, country, country unknown, cover up, covid19, crack, create, created, creation date, critical, critical risk, cronup threat, cryptexportkey, crypto, csc corporate, cultureneutral, cus cnmicrosoft, cus olet, customer, CVE-2005-1790, CVE-2009-3672, CVE-2010-3962, CVE-2012-3993, CVE-2014-3153, CVE-2014-6332, CVE-2016-0189, CVE-2017-0147, CVE-2017-0199, cve201711882, CVE-2017-11882, CVE-2017-8570, CVE-2018-4893, CVE-2020-0601, CVE-2020-0674, CVE-2021-27065, CVE-2021-40444, cve202322518, CVE-2023-4966, cyber attack, cyber crime, cyberlynk, cybersecurity, cyber stalking, cyberstalking, cyber threat, cyberthreat, cyberwar, cymulate, dan.com, dangeroussig, dark consultants, darkgate, data, database, data center, data upload, date, date checked, date hash, date mon, dat ngoc, dau tu, december, decrypted ssl, deepscan, default, defense evasion, de indicators, delete, delete c, deleted, deleted virustotal graphs, deleting, de page, destination, de summary, detail domains, detection list, detections, detections file, detections none, detections type, device control, dexter, dga, diamondfox, discovery, district, div div, djcodychase.com, dll sideloading, dns, dns lookup, dnspionage, dns records, dns replication, dns resolutions, dnssec, dock, docs pricing, document file, document format, dofoil, domain, domain add, domain name, domain related, domain robot, domains, domains show, domain tree, dos com, dos exe, downer, downldr, download, downloader, dridex, driverpack, drivertalent, dropped, dropper, duckdns, dumped_buffer, duo insight, dynadot inc, dynadot llc, dynamicloader, dyndns checkip, e1082 impact, e1203 data, e1564 discovery, ecc domain, ecdhersa, ec oid, edsaid, ef3ghigj, el0kpmhlfz, elf collection, email, emails, emailworm, emotet, emotet ip, encdoc, encrypt, encrypt cnr3, engineering, english, enosch, enosch malware, enter, enter rexxfield, entries, entries http, entrust, erase, error, et, et cins, eternalblue, etpro malware, et tor, et useragents, evasion att, evasion ob0006, evil, evil c, excel, exe32, executable, execution, exit, expiration, expiration date, expires thu, expirestue, expl, exploit, exploitation, external ip, extraction, facebook, factory, facts otx, failure, fakealert, fakedout threat, falcon, falcon sandbox, fast, fcc, february, feodo, file, file defense, filehash, filehashmd5, filehashsha1, filehashsha256, filerepmetagen, files, file samples, file score, files domain, files ip, file size, files location, files matching, files related, files show, filetour, file type, final url, financial, find, findwindowa, firehol, first, flag united, flow t1574, flywheel, follow, font format, footer, forcud, form, format, formbook, formbook cnc, for privacy, frames domain, france mail, france unknown, frankfurt, free poems, friendship poems, fuery, fusioncore, g2 oglobalsign, gamers, gandi sas, gang breached, gb summary, gecko, general, general full, generator, generic, generic malware, generic windos, genkryptik, gen.o, geotracking, germany, germany unknown, get h2, get http, get na, getprocaddress, github pages, glupteba, gmbh version, gmt content, gmt server, gmt setcookie, gmt united, goldfinder, google, google llc, google team, gootloader, graph community, graph summary, greatness, group, gsqueue, gts ca, guard, gui32, gvt, hacked by phone call, hacker, hackers, hacking, hacktool, hallrender, hallrender.com, hash, hashes, hawkeye, header click, header intel, headers, headers date, head title, heaven, heavens, her beam, herself, heur, hidden users, hide artifacts, high, high level, highly targeted, high process, high security, hio50 c1, historical, historical ssl, history, hitmen, homepage, hong kong, host, hosting, hostname, hostname add, hostnames, hostname server, hosts, href, html, html info, http, http attacker, http header, httponly, http request, http requests, http response, https:/www.usaopps.com/government_contractors/contractor-5388777, hybrid, icedid, ice fog, icloud, icmp, icmp traffic, identifier, ids detections, iframe, ii llc, illegal, illegal practices, incapsula, indicator, indicator facts, indicator role, indonesia, industry_and_commerce, info, info compiler, info header, information, informative, infrastructure, infy, ingestion time, inject, injection t1055, inmortal, installcore, installer, installpack, intel, internal, internapblk4, internet storm, invalid pointer, invalid url, iobit, iocs, ioc search, Iowa.gov, ip address, ipasns ip, ip detections, ip information, ip reputation, ip summary, ip tcp, ipv4, ireland unknown, isotope, issuer, issuing ca, it’s back, jackpos, january, java, javascript, jeffrey reimer pt, jpeg image, jquery, js, json data, july, june, junk data, kali, kangen, kb acrotray, kb body, kb file, kb image, kb program, keitaro, key algorithm, keybase, key identifier, key info, keylogger, keysystems gmbh, key usage, kgs0, khtml, killav, kls0, known tor, kong asn, kraken, kryptik, kuaizip, language, laplasclipper, law, learn, leasewebuklon11, legal, length, less see, librouter, life, light, limited, link, linker, linkid252669, links certs, live, llc address, llc registry, lmenlo park, local, localappdata, location hong, location united, lockbit, login, logon autostart, loki, london, look, lookup, love poems, lowfi, ltd dba, lumma stealer, magniber, mail collection, mail spammer, main, makop, maliciosa, malicious, malicious host, malicious link, malicious site, malicious url, maltiverse, maltiverse safe, maltiverse top, malvertizing, malware, malware generic, malware host, malware hosting, malware scripting, malware site, malware spreader, manjusaka, march, mark, mark brian sabey, markmonitor, masquerading, matches rule, matsnu, mb iesettings, mb opera, mb super, media, media center, mediaget, mediamagnet, medium, memcommit, memory pattern, memreserve, message interception, meta, metastealer, meta tags, meterpreter, metro, metro hacker, microsoftcorpas, milemighmedia, million, mimikatz, mirai, misc attack, miss x, mitre att, mitre attack, modification, modifies_proxy_wpad, modify system, monitoring, mon jul, moved, mozilla, mr windows, msie, ms visual, ms windows, mtb apr, mtb jul, mtb nov, mtb yara, multiple botnetworks, mumblehard, murderers, music, mwin, my boy dan, name, namecheap inc, name md5, name servers, name tactics, name value, name verdict, nameweb bvba, nanocore, nanocore rat, net108, net1080000, netgear router, netgear twitter, nethandle, netherlands, netrange, netsky, network, network capture, network_http, network_icmp, network pty, network rat, networks, network_smtp, network traffic, neutrino, new ioc, next, next associated, nginx, ninite, nircmd, nivdort, njrat, no data, node tcp, node traffic, no expiration, noname057, none google, none indicator, none related, nosy pega, november, nr agent, nreum, nsisinetc, null, number, nxdomain, nymaim, ob0005 defense, ob0007 system, ob0012 hide, object, obz4usfn0 http, oc0008, october, odigicert inc, ogoogle trust, ollydbg, ometa platforms, online, open, opencandy, openioc, open ports, optimizer, orgabusehandle, orgdnshandle, orgdnsref, org domains, orgtechhandle, orgtechref, os2 executable, otx octoseek, otx telemetry, ouno sni, outbreak, outlook, overlay, ovh sas, page url, parent parent, passive dns, password, password bypass, paste, patcher, path, pattern match, pcap, pcidump rasman, pdf document, pdf report, pe32, pe32 compiler, pe32 executable, pe32 packer, pe resource, persistence, persistence_autorun, phase, phi, phishing, phishingms, phishing site, phishtank, phone hacking, pii, pjp3sltkz, plasma, playgame, please, plugx, png image, poem, poems, poem topics, poetry, pony, Pool’s Closed, poor reputation, porkbun llc, porn, pornhub, pornographers, port, portugal, possible, possiblecerber, post, post http, pragma, presenoker, present apr, present dec, present jun, present mar, present may, present nov, present sep, privacy inc, private name, probe, problems, process32nextw, processes tree, process t1543, productidis, products id, protocol h2, proud evening, proxy, psiusa, ps ord, pte ltd, public key, pulse, pulse indicator, pulse pulses, pulses, pulses none, pulse submit, pulses url, purplewave, push, pykspa, python, python connection, q0gpyr1balpdgpo, qakbot, qbot, qdkxgr24yz, quasar rat, quasi, query, query type, raccoon, raccoonstealer, radar ineractive, radar tracking, ramnit, random domains, random hosts, rank, rank value, ransom, ransomexx, ransomware, Ransomware, ransomware gang, raspberry robin, rat, read, read c, reads, recon, record type, record value, redline stealer, redlinestealer, redrum, red team, referral url, referrer, referring, refresh, regbinary, regdword, regex, registrar, registrar abuse, registrar url, registrar whois, registry domain, registry expiry, registry keys, regsetvalueexa, regsz, relacionada, relacionada con, related file, related nids, related pulses, related tags, relayrouter, relic, remote, remote attacker, remote attacks, remote system, replacement, replication, report, reputation ip, request, requested, resolutions, resource, resource hash, response, response ip, restart, revengeporn, revenge rat, revengerat, reverse dns, review, riskware, road city, roberts, romantic poems, rostpay, roundup, router login, rufus, runescape, runtime data, russia unknown, sabey, safe browsing, safe site, sale, sality, sample, samplepath, samples, sandbox, san jose, satellite tracking, savbwcd, scan endpoints, scanning host, scans record, screenshot, script, script urls, search, search live, sea x, sec ch, secure server, security, security tls, seen asn, seen last, september, seraph, server, server ca, servers, service, services, service tool, serving ip, settingswpad, setup, sha1, sha256, sharecare, shell, shell commands, shellexecuteexw, shelltraywnd, shone pale, show, showing, show technique, siblings, siblings domain, sibot, silence, silencing, simda, singlehopllc, site, sites, size, skynet, skynet bot, slcc2, slingshot, smith, smoke loader, smsspy, smtp_gmail, snatch, sneaky server, soa nxdomain, soc, social engineering, softcnapp, software, solutions, spammer, span, spawns, spitmo, spotify artist, spyeye, spyware, sql, sqli dumper, squarespace, ssl cert, ssl certificate, st201601152, stalker, star, startpage, start service, state, status, status code, status hostname, stcalifornia, stealer, steam, steganography, stix, stop service, strings, stus, style, subdomains, subject key, subject public, submission, submit, submitters, sucurisec, summary, summary iocs, suppobox, suspected, suspicious, suspicious c2, svg scalable, swrort, system, systweak, t, t1055, t1063, t1189 found, t1480 execution, ta0004 process, tag count, tag manager, tags, tags none, target, targeting, tcp traffic, td td, team, team internet, team phishing, teams, teams api, team top, technology, telecom italia, telefonica co, temp, text archiver, than, thebrotherssabey, then brothers sabey, thinclient, thomsonreuters, thou bearest, threat, threat analyzer, threat level, threat network, threat report, threat round, threat roundup, threats, threats et, thu apr, tiggre, Timothy Pool, title, title added, title error, tls handshake, tls sni, tlsv1, tlsv1 apr, tmobile, tmobileas21928, t-mobile hacker, tmos, tnhh quan, tofsee, tools, topic, topics, tor known, tor relayrouter, torrent trecker, tracker, tracking, traffic, trojan, trojandropper, trojanspy, trojanx, tsara brashears, ttl value, tucows, tucows domains, tue apr, tulach, twitter, twitter running, type, type name, ua full, ua platform, uchealth, umbrella rank, unauthorized, unicode text, union, unique, united, united kingdom, unknown, unknown ns, unknown site, unknown soa, unknown traffic, unlocker, unruy, unsafe, unsigned, updater, url add, url analysis, url collection, url history, url hostname, url http, url https, urls, urls date, urls http, urls https, urls show, url summary, urls url, ursnif, us creation, usd twitter, user, utc google, utc gtmsxrf, utc submissions, v2 document, v3 serial, validity, value, variables, vawtrak, vector graphics, verdict mobile, verify, vidar, view, virtool, virus network, virut, vs2003, vskimmer, vt graph, vxstream, wacatac, WannaCry, warbot, waypoint object, webcompanion, Web generator, webico company, web open, webshell, webtoolbar, wed sep, westlaw, westlaw njrat, whitelisted, whois lookup, whois record, whois registrar, whois server, whois sslcert, whois whois, wide, win16 ne, win32, win32 dll, win32 exe, win32qqpass apr, win64, windir, windows, windows nt, windows service, wiper, workers compensation, worm, worn, wow64, write, write c, x509v3 key, x8bxe5, x amz, x cache, xml title, x powered, xrat, x sucuri, xtrat, xtreme, yandex, yara detections, yara rule, yndx, zbot, zeus, zfglddkl58a url, zuorat

  • JARM: 29d3fd00029d29d21c42d43d00041d44609a5a9a88e797f466e878a82e8365

  • View other sources: Spamhaus VirusTotal

Malware Detected on Host

Count: 3877 27f3bfef41c8fb4cc97c6d4e28ce052722d0ad88d56ed876b390f37e0894997f cffa750438fca34607e99edb86ab8850bde7d031134d3ec4bea6c059e4c7f40e 8356bed98f502ba29402041c450af6a4e540b5f776a9a937101ed7ab73b3cc43 01d69b5cf09169a765d1681b4a623c4c8b138837540ffe4f5210ce4f32b5983f 5e44d5c2177807d15675752eab7e4799ec9f0e13b7f22996ecd5d565c2b8eab1 d7fc6e2bb668eb1c28e00c181c05060b72a4d4c1fd9055539b13c13af7e65382 3b9d476642b39a19411d46afbebde4b40ce4eb616316a48aa5e01539589d46c2 c61deca57b2df23d6bf40af741124b22edec0fbe3f39d96dc376ce79403ac17a c8be0e5878a49125d3e20289899677b48e82d7497280a1d4b49d84c4ca552b82 05924b64fcf03da8232b4927d288d9c46aa37f762aa9a6a657d45d8185b54409

Open Ports Detected

2052 2082 2083 2087 443 80 8080 8443 8880

Map

Whois Information

Links to attack logs

anonymous-proxy-ip-list-2024-02-21 anonymous-proxy-ip-list-2024-03-06 anonymous-proxy-ip-list-2024-03-04 anonymous-proxy-ip-list-2023-06-28 anonymous-proxy-ip-list-2024-02-22 anonymous-proxy-ip-list-2023-07-28 anonymous-proxy-ip-list-2024-03-14 anonymous-proxy-ip-list-2024-03-20 anonymous-proxy-ip-list-2023-06-29 anonymous-proxy-ip-list-2023-07-18 anonymous-proxy-ip-list-2023-07-19 anonymous-proxy-ip-list-2024-03-12 anonymous-proxy-ip-list-2024-03-24 ****** anonymous-proxy-ip-list-2024-02-23 anonymous-proxy-ip-list-2024-03-03 anonymous-proxy-ip-list-2024-03-11 anonymous-proxy-ip-list-2024-03-13 anonymous-proxy-ip-list-2024-03-21 anonymous-proxy-ip-list-2024-03-08 anonymous-proxy-ip-list-2024-03-23 anonymous-proxy-ip-list-2024-03-16 anonymous-proxy-ip-list-2024-02-13 anonymous-proxy-ip-list-2024-02-16 anonymous-proxy-ip-list-2024-02-17 anonymous-proxy-ip-list-2024-02-27 anonymous-proxy-ip-list-2024-02-18 anonymous-proxy-ip-list-2024-02-19 anonymous-proxy-ip-list-2023-06-30 anonymous-proxy-ip-list-2023-07-16 anonymous-proxy-ip-list-2024-02-14 anonymous-proxy-ip-list-2024-03-18 anonymous-proxy-ip-list-2024-02-26 anonymous-proxy-ip-list-2024-03-15 anonymous-proxy-ip-list-2023-07-08 anonymous-proxy-ip-list-2023-07-09 anonymous-proxy-ip-list-2024-02-20 anonymous-proxy-ip-list-2024-02-29 anonymous-proxy-ip-list-2024-03-02 anonymous-proxy-ip-list-2023-06-22 ****** anonymous-proxy-ip-list-2023-07-02 anonymous-proxy-ip-list-2023-07-03 anonymous-proxy-ip-list-2024-03-22 anonymous-proxy-ip-list-2024-02-25 anonymous-proxy-ip-list-2024-03-05 anonymous-proxy-ip-list-2024-03-17 anonymous-proxy-ip-list-2024-03-19 anonymous-proxy-ip-list-2024-03-25 ****** anonymous-proxy-ip-list-2023-07-21 anonymous-proxy-ip-list-2024-02-15 anonymous-proxy-ip-list-2024-02-24 anonymous-proxy-ip-list-2024-02-28 anonymous-proxy-ip-list-2024-03-07

Share on: