104.16.88.20 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 104.16.88.20 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Likely Malicious Host 🟠 60/100

Host and Network Information

  • Mitre ATT&CK IDs: T1003 - OS Credential Dumping, T1005 - Data from Local System, T1012 - Query Registry, T1027 - Obfuscated Files or Information, T1030 - Data Transfer Size Limits, T1031 - Modify Existing Service, T1035 - Service Execution, T1036 - Masquerading, T1040 - Network Sniffing, T1041 - Exfiltration Over C2 Channel, T1043 - Commonly Used Port, T1045 - Software Packing, T1053 - Scheduled Task/Job, T1055.012 - Process Hollowing, T1055 - Process Injection, T1056.001 - Keylogging, T1056 - Input Capture, T1057 - Process Discovery, T1059.005 - Visual Basic, T1059.006 - Python, T1059.007 - JavaScript, T1059 - Command and Scripting Interpreter, T1060 - Registry Run Keys / Startup Folder, T1063 - Security Software Discovery, T1068 - Exploitation for Privilege Escalation, T1070 - Indicator Removal on Host, T1071.001 - Web Protocols, T1071.003 - Mail Protocols, T1071.004 - DNS, T1071 - Application Layer Protocol, T1081 - Credentials in Files, T1082 - System Information Discovery, T1083 - File and Directory Discovery, T1090 - Proxy, T1095 - Non-Application Layer Protocol, T1096 - NTFS File Attributes, T1105 - Ingress Tool Transfer, T1106 - Native API, T1110.002 - Password Cracking, T1110 - Brute Force, T1111 - Two-Factor Authentication Interception, T1112 - Modify Registry, T1114 - Email Collection, T1119 - Automated Collection, T1122 - Component Object Model Hijacking, T1129 - Shared Modules, T1140 - Deobfuscate/Decode Files or Information, T1158 - Hidden Files and Directories, T1173 - Dynamic Data Exchange, T1176 - Browser Extensions, T1179 - Hooking, T1189 - Drive-by Compromise, T1203 - Exploitation for Client Execution, T1204 - User Execution, T1210 - Exploitation of Remote Services, T1222 - File and Directory Permissions Modification, T1410 - Network Traffic Capture or Redirection, T1423 - Network Service Scanning, T1427 - Attack PC via USB Connection, T1445 - Abuse of iOS Enterprise App Signing Key, T1449 - Exploit SS7 to Redirect Phone Calls/SMS, T1450 - Exploit SS7 to Track Device Location, T1453 - Abuse Accessibility Features, T1472 - Generate Fraudulent Advertising Revenue, T1485 - Data Destruction, T1491 - Defacement, T1496 - Resource Hijacking, T1497.001 - System Checks, T1497 - Virtualization/Sandbox Evasion, T1518.001 - Security Software Discovery, T1518 - Software Discovery, T1543 - Create or Modify System Process, T1546.015 - Component Object Model Hijacking, T1546 - Event Triggered Execution, T1547.001 - Registry Run Keys / Startup Folder, T1547 - Boot or Logon Autostart Execution, T1552.001 - Credentials In Files, T1552 - Unsecured Credentials, T1555.003 - Credentials from Web Browsers, T1555 - Credentials from Password Stores, T1560 - Archive Collected Data, T1563 - Remote Service Session Hijacking, T1564 - Hide Artifacts, T1566 - Phishing, T1568 - Dynamic Resolution, T1569 - System Services, T1573 - Encrypted Channel, T1574 - Hijack Execution Flow, T1583.005 - Botnet, T1588.004 - Digital Certificates, T1588 - Obtain Capabilities, TA0002 - Execution, TA0003 - Persistence, TA0004 - Privilege Escalation, TA0005 - Defense Evasion, TA0006 - Credential Access, TA0007 - Discovery, TA0009 - Collection, TA0010 - Exfiltration, TA0011 - Command and Control

  • Tags: 1996, 1tzv, a1ginaprincipal, a9dia, aaaa, accept, accept ch, accept encoding, access denied, access ta0001, acint, activator, active threat, activity, adams co, adblock pro, address, address domain, address first, address google, addtopayload, adload, adobe air, adobe portable, a domains, adversaries, adware, adware affiliate, af81 http, a fleecy, agency, agent, ai, aig, AIG Claims, akamaias, alexa, alexa proxy, alexa top, alf features, algorithm, alina, all octoseek, all scoreblue, all search, amazon 02, amazon02, amazonaes, analyzer paste, analyzer threat, android, andromeda, anonymisation, anonymizer, ansi, antivirus, antivm_network_adapters, antivm_queries_computername, a nxdomain, apache, api blog, appdata, apple, appleaustin, apple engineering, apple ios, apple notepad, apple phone, apple unlocker, applicunwnt, april, apt, artemis, as13335, as133618, as13768 aptum, as139021, as14061, as14720 gamma, as15169 google, as16276, as16552 tiggee, as16625 akamai, as19237 omnis, as19527 google, as20068 hawk, as20940, as212913 fop, as22169 omnis, as22489, as22612, as23393, as2914 ntt, as29789, as30148 sucuri, as31898 oracle, as36459, as39122, as396982, as396982 google, as397240, as397241, as40509, as4230 claro, as43350 nforce, as44273 host, as47846, as49453, as54113, as55286, as60558 phoenix, as61969 team, as62597 nsone, as6724 strato, as7018 att, as7922 comcast, as8068, as8075, as autonomous, ascii text, asn15169, asn16276, asn209242, asn4583, asnone, asnone united, asyncrat, athena, attack, attacking, attention, august, available from, avast avg, awful, azorult, azorult cnc, azure tls, back, backdoor, bambernek, bambernek gen, bambernek simda, banco, bandoo, bank, banker, basic, bayrob, bazaloader, b body, beach research, beginstring, behav, beijing gu, benjamin, best targets, betabot, binary file, bitrat, bitrep, blackhat, blacklist, blacklist http, blacklist https, blacknet rat, blocklist, body, body doctype, body html, body length, boot, bot, botnet campaign, botnet command and control, botnetwork, bradesco, brazil, brazil unknown, brent kimball, brian sabey, browser, c2, C2, camera usage, canada unknown, canvas, cape, catalog tree, cbe cnalphassl, center, centerchecks, certificate, cgb stgreater, checked url, checkin, checks_debugger, child teen content illegal, china, china as4134, china education, china telecom, china unicom, Christopher Pool, chrome, cins active, ciphersuite, cisco, cisco umbrella, citadel, ck id, class, classic poems, classname, cleaner, click, clickjacking, clipper dos, close, cloudflare, cloudflarenet, cloud host, cname, cnc, cnc feodo, cnc server, cndigicert sha2, cnus, coalition et, cobalt strike, cobaltstrike, code, coinminer, collection, collections, colorado, com laude, command and control, command_and_control, commerce, communicating, comodo rsa, comodo valkyrie, company limited, compiler, computer, conduit, cong ty, connect azurepc, connection, contact, contacted, contacted urls, contact phone, contained, content generating, content length, content reputation, content type, control server, cookie, copy, copyright, core, corruption, country, country unknown, cover up, covid19, crack, create, created, creation date, critical, critical risk, cronup threat, crypto, csc corporate, cultureneutral, cus cnmicrosoft, cus olet, customer, cve201711882, CVE-2017-11882, CVE-2020-11022, CVE-2020-11023, CVE-2021-22941, cve202322518, CVE-2023-4966, cyber attack, cyber crime, cyberlynk, cybersecurity, cyber stalking, cyberstalking, cyber threat, cyberthreat, cyberwar, cymulate, dan.com, dangeroussig, dark consultants, darkgate, data, database, data center, date, date hash, date mon, dat ngoc, dau tu, december, decrypted ssl, deepscan, default, defense evasion, de indicators, delete, delete c, deleted, deleted virustotal graphs, deleting, de page, de summary, detail domains, detection list, detections file, detections type, device control, dexter, dga, diamondfox, discovery, district, div div, djcodychase.com, dll sideloading, dns, dns lookup, dnspionage, dns records, dns replication, dns resolutions, dnssec, docs pricing, document file, document format, dofoil, domain, domain name, domain related, domain robot, domains, domains show, domain tree, dos com, dos exe, downer, downldr, download, downloader, dridex, driverpack, drivertalent, dropped, dropper, duckdns, dummy, dumped_buffer, duo insight, dynadot llc, dynamicloader, e1082 impact, e1203 data, e1564 discovery, ecc domain, ecdhersa, ec oid, edsaid, el0kpmhlfz, elf collection, email, emails, emailworm, emotet, emotet ip, encdoc, encrypt, encrypt cnr3, engineering, english, enosch, enosch malware, enter, enter rexxfield, entries, entrust, erase, error, et, et cins, eternalblue, etpro malware, et tor, et useragents, evasion ob0006, evil, evil c, excel, exe32, executable, execution, exit, expiration, expiration date, expires thu, expirestue, expl, exploit, exploitation, extraction, facebook, factory, fakealert, fakedout threat, falcon, falcon sandbox, fcc, february, feodo, file, filehashmd5, filehashsha1, filehashsha256, filerepmetagen, files, file samples, files domain, files ip, file size, files location, files matching, files related, filetour, file type, final url, financial, find, findwindowa, firehol, first, flow t1574, follow, font format, footer, form, format, formbook, formbook cnc, for privacy, frames domain, france mail, france unknown, frankfurt, free poems, freeze, friendship poems, fuery, fusioncore, g2 oglobalsign, gamers, gandi sas, gb summary, gecko, general, general full, generator, generic, generic malware, generic windos, genkryptik, gen.o, geotracking, germany, germany unknown, get h2, get http, get na, getprocaddress, github pages, glupteba, gmbh version, gmt content, gmtetag, gmt server, gmt setcookie, gmt united, goldfinder, google, gootloader, graph community, graph summary, greatness, group, gsqueue, gts ca, guard, gui32, gvt, hacked by phone call, hacker, hackers, hacking, hacktool, hallrender, hallrender.com, hash, hashes, hash seen, hawkeye, header click, header intel, headers, headers date, head title, heaven, heavens, her beam, herself, heur, hidden users, hide artifacts, high, high level, highly targeted, high process, high security, historical, historical ssl, history, hitmen, homepage, hong kong, host, hosting, hostname, hostnames, hostname server, html, html info, http, http attacker, http header, httponly, http request, http requests, http response, hybrid, icedid, ice fog, icloud, icmp, identifier, ids detections, iframe, ii llc, illegal, illegal practices, incapsula, indicator, indicator facts, indonesia, industry_and_commerce, infinity, info, info compiler, info header, information, infrastructure, infy, ingestion time, inject, injection t1055, inmortal, installcore, installer, installpack, intel, internal, internapblk4, internet storm, invalid url, iobit, iocs, ioc search, Iowa.gov, ip address, ipasns ip, ip detections, ip information, ip reputation, ip summary, ip tcp, ipv4, ireland unknown, isotope, issuer, issuing ca, it’s back, jackpos, january, java, javascript, jeffrey reimer pt, jpeg image, jquery, js, json data, july, june, junk data, kali, kangen, kb acrotray, kb body, kb file, kb image, kb program, keitaro, key algorithm, key identifier, key info, keylogger, kgs0, khtml, killav, kls0, known tor, kong asn, kraken, kryptik, kuaizip, language, laplasclipper, law, leasewebuklon11, legal, less see, librouter, life, limited, link, linker, linkid252669, links certs, llc registry, lmenlo park, loader, local, localappdata, location hong, location united, lockbit, logic, login, logon autostart, loki, london, look, love poems, lowfi, ltd dba, lumma stealer, magniber, mail collection, mail spammer, main, makop, maliciosa, malicious, malicious site, malicious url, maltiverse, maltiverse safe, maltiverse top, malvertizing, malware, malware generic, malware host, malware scripting, malware site, malware spreader, manjusaka, march, mark, mark brian sabey, markmonitor, masquerading, matches rule, matsnu, mb iesettings, mb opera, mb super, media, media center, mediaget, medium, memcommit, memory pattern, message interception, meta, metastealer, meta tags, meterpreter, metro, metro hacker, microsoftcorpas, milemighmedia, million, mimikatz, mirai, misc attack, mitre att, mitre attack, modification, modifies_proxy_wpad, modify system, monitoring, mon jul, moved, mozilla, mr windows, msie, ms visual, ms windows, mtb apr, mtb jul, multiple botnetworks, mumblehard, murderers, music, mwin, my boy dan, name, namecheap inc, name md5, name servers, name value, name verdict, nameweb bvba, nanocore, nanocore rat, netgear router, netgear twitter, netherlands, netsky, network, network capture, network_http, network_icmp, network rat, networks, network_smtp, network traffic, neutrino, new ioc, next, nginx, ninite, nircmd, nivdort, njrat, no data, node tcp, node traffic, no expiration, noname057, nosy pega, november, nr agent, nreum, nsisinetc, null, number, nxdomain, nymaim, ob0005 defense, ob0007 system, ob0012 hide, object, obz4usfn0 http, oc0008, october, odigicert inc, okdate, ollydbg, ometa platforms, open, opencandy, openioc, optimizer, os2 executable, otx octoseek, outbreak, outlook, overlay, ovh sas, page url, parent parent, passive dns, password, password bypass, paste, patcher, path, pattern match, pcap, pcap frame, pcap processing, pcidump rasman, pdf document, pdf report, pe32, pe32 compiler, pe32 executable, pe32 packer, pe resource, persistence, persistence_autorun, phase, phi, phishing, phishingms, phishing site, phishtank, phone hacking, pii, pjp3sltkz, plasma, playgame, please, plugx, png image, poem, poems, poem topics, poetry, pony, Pool’s Closed, poor reputation, porkbun llc, porn, pornhub, pornographers, portugal, possible, possiblecerber, post, post http, pragma, presenoker, present mar, privacy inc, probe, problems, processes tree, process t1543, productidis, products id, prop, protocol h2, proud evening, proxy, psiusa, ps ord, pte ltd, public key, pulse indicator, pulse pulses, pulse submit, push, pykspa, python, python connection, q0gpyr1balpdgpo, qakbot, qbot, qdkxgr24yz, quasar rat, quasi, query type, raccoon, raccoonstealer, radar ineractive, radar tracking, ramnit, random domains, random hosts, rank, rank value, ransom, ransomexx, ransomware, Ransomware, raspberry robin, rat, recon, record type, record value, redline stealer, redlinestealer, redrum, red team, referrer, referring, refresh, regbinary, regdword, regex, registrar, registrar abuse, registrar url, registrar whois, registry domain, registry expiry, registry keys, regsetvalueexa, regsz, relacionada, relacionada con, related file, related nids, related pulses, relayrouter, relic, remote, remote attacker, remote attacks, remote system, replacement, replication, report, reputation ip, request, requested, resolutions, resource, resource hash, response, response ip, restart, revengeporn, revenge rat, revengerat, reverse dns, review, riskware, roberts, romantic poems, rostpay, roundup, router login, ruby, rufus, runescape, russia unknown, sabey, safe browsing, safe site, sale, sample, samplepath, samples, sandbox, san jose, satellite tracking, scan endpoints, scanning host, screen, screenshot, script, script urls, search, search live, sec ch, secure server, security, security tls, seen asn, seen last, september, seraph, server, server ca, servers, service, services, service tool, serving ip, settingswpad, setup, sha1, sha256, sharecare, shell commands, shelltraywnd, shone pale, show, showing, siblings, siblings domain, sibot, silence, silencing, simda, singlehopllc, site, sites, skynet, skynet bot, slcc2, slingshot, smith, smoke loader, smsspy, smtp_gmail, snatch, sneaky server, soa nxdomain, soc, social engineering, softcnapp, software, spammer, span, spawns, spitmo, spotify artist, spyeye, spyware, sql, sqli dumper, squarespace, ssl cert, ssl certificate, st201601152, stalker, star, startpage, start service, state, status, status code, status hostname, stcalifornia, stealer, steam, steganography, stix, stop service, strings, stus, style, subdomains, subject key, subject public, submission, submitters, sucurisec, summary, summary iocs, suppobox, suspected, suspicious, suspicious c2, svg scalable, swrort, system, systweak, t, t1063, t1189 found, ta0004 process, tag count, tag manager, tags none, target, targeting, tcp traffic, td td, team, team internet, team phishing, teams, teams api, team top, technology, telecom italia, telefonica co, temp, text archiver, than, thebrotherssabey, then brothers sabey, thinclient, thomsonreuters, thou bearest, threat, threat analyzer, threat level, threat network, threat report, threat round, threat roundup, threats, threats et, thu apr, tiggre, Timothy Pool, title, title error, tls sni, tlsv1 apr, tmobile, tmobileas21928, t-mobile hacker, tnhh quan, tofsee, tools, topic, topics, tor known, tor relayrouter, torrent trecker, tracker, tracking, traffic, trojan, trojandropper, trojanspy, tsara brashears, ttl value, tucows, tucows domains, tue apr, tulach, twitter, type, type name, uchealth, umbrella rank, unauthorized, unicode, unicode text, union, united, united kingdom, unknown, unknown traffic, unlocker, unruy, unsafe, unsigned, updater, url analysis, url collection, url history, url http, url https, urls, urls date, urls http, urls https, url summary, urls url, ursnif, usd twitter, user, utc google, utc gtmsxrf, utc submissions, v2 document, v3 serial, validity, value, variables, vawtrak, vector graphics, verdict mobile, verify, vidar, view, virtool, virus network, virut, vs2003, vskimmer, vt graph, wacatac, WannaCry, warbot, waypoint object, webcompanion, Web generator, webico company, web open, webtoolbar, wed sep, westlaw, westlaw njrat, whitelisted, whois record, whois sslcert, whois whois, wide, win16 ne, win32, win32 dll, win32 exe, win64, windir, windows nt, windows service, wiper, workers compensation, worm, worn, wow64, write, x509v3 key, x8bxe5, xml title, x powered, xrat, x sucuri, xtrat, xtreme, yad2-js.nagich.co.il, yandex, yara detections, yara rule, yndx, zbot, zeus, zfglddkl58a url, zuorat

  • JARM: 29d3fd00029d29d21c42d43d00041d44609a5a9a88e797f466e878a82e8365

  • View other sources: Spamhaus VirusTotal

Malware Detected on Host

Count: 3771 a16baaf25edc00a1af041c34d369f4b134557c2f1dcc6d2188d9a2996b3fb9e3 8fb30a3bbdbe2df7f6d0ee80d718914895290adff595ecca57aeb9b579b2d73a 218371ebea0f41fa795c24c3100e160e09d814414df527844e608aad81b29a27 41eeb419954e38f8cf60ab1910693424443298345f9e8c3d81a623e2c3b6fb7e 69b2dad20c42e69cc0d4e04bb6c508af53f00c254ec64400d2f271db4333fc2e 8ea3d1d4895367daf014a10bdb0f1e8b01f68bcc34089d615560d18e22c92c44 abf685fa52e59044280be9a96db5b55d5966bbd2106d3db94899a304287f4fff 05c83d715d050a7e90c884c52ee9c717ea39a42fae4d2e69c1758f374cc7db34 0be5c111d33dbbd130a340292e7f953ee72c062d1dabe303b57c6896c608bd73 20c23245bb02208fd4c23531971f2fa6bd288eef37a8c227edeabd4d6da4fd8f

Open Ports Detected

2082 2083 2086 2087 443 80 8080 8443 8880

Map

Whois Information

Links to attack logs

anonymous-proxy-ip-list-2025-06-23 anonymous-proxy-ip-list-2025-06-22

Share on: