104.17.108.199 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 104.17.108.199 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Potentially Malicious Host 🟡 38/100

Host and Network Information

  • Tags: akamaias, akamaiasn1, algorithm, allusersprofile, amazon02, as15169, as16509, as20940, as3359, as8075, as852, blacklist fri, ca1 odigicert, cisco umbrella, cname, collections, communicating, contacted, cuba, cus cndigicert, data, date filename, dns requests, execution, facebook, fri dec, fri jan, full name, gamesmetadata, generic malware, geoip, ghost, google, historical ssl, hybridanalysis, inc validity, indonesia, install league, legends, level3, malicious, malware, media, mexico, mini, mon jan, mon jul, number, online thu, osuser, parent, process list, proton, public url, record type, relic, resolutions, safe site, seznam, sha256, siblings, site, ssl certificate, sun jan, telecom, tls rsa, ttl value, twitter, ukraine, v3 serial, whois record, win32, win64

  • JARM: 27d40d40d00040d1dc42d43d00041d6183ff1bfae51ebd88d70384363d525c

  • View other sources: Spamhaus VirusTotal

  • Country:
  • Network:
  • Noticed: 4 times
  • Protocols Attacked: Anonymous Proxy
  • Countries Attacked: Anguilla, Aruba, Australia, Bahamas, Barbados, Canada, Cayman Islands, Costa Rica, Curaçao, Georgia, Guatemala, Japan, Mexico, Netherlands, Panama, Philippines, Poland, Saint Kitts and Nevis, Saint Martin (French part), Saint Vincent and the Grenadines, Sint Maarten (Dutch part), Tanzania United Republic of, Trinidad and Tobago, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
  • Passive DNS Results: static.legacy.net.cdn.cloudflare.net ak-qasympathy.legacy.net ak-qacache.legacy.net ak-qastatic.legacy.net qacache.legacy.net ak-static.legacy.net.cdn.cloudflare.net ak-cache.legacy.net.cdn.cloudflare.net cache.legacy.net.cdn.cloudflare.net forms.hscollectedforms.net js.hscollectedforms.net t.strk01.email

Malware Detected on Host

Count: 10 18e140be301bd84357bd05291e7767dc33fa6323d9675360c6ba531c8d0b1070 0746fbba5d5fc5d1c23dec08871301cd52d16eac8a5ba538ac9cc5f7d018aa28 4c82e505d27787eb37ced24047b670d9ce83d2cd15159f97a301331e2904962a a4ba25e8c067479690eecfcc04d85921c42a35812b2caef283e9ebf0ae6dbe5e ae0971fc3dec8ff6fdd842adacf67859f5f5a443a7aaf4a39585b7a5939f90d8 4469c02f7b5b6958ee7a26550b10f066dd9e5e6b354a437a0d33e5b0bf649dd9 0375419db1c8eccf7853fe3d9d87f358746f36e881efeaf83e2a6e896388ec0b 5a611ca3b77a915635e62fd37c7de59e710199f9f58cdceec40e09ccd7eb8aaa 2cecb387e9cf59f3d2ac530ce0c4b4bf57ebe1e9cdd8bf2e2133cf6fcd99d39c 4c5f54125215a18419c0350a1b52137f169a0af16fe2f3f162500a26af04d572

Open Ports Detected

2053 2082 2083 2086 2087 2096 443 80 8080 8443 8880

Map

Whois Information

Links to attack logs

anonymous-proxy-ip-list-2025-06-23 anonymous-proxy-ip-list-2025-06-22

Share on: