104.18.10.128 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 104.18.10.128 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Likely Malicious Host 🟠 56/100

Host and Network Information

  • Mitre ATT&CK IDs: T1012 - Query Registry, T1018 - Remote System Discovery, T1027 - Obfuscated Files or Information, T1031 - Modify Existing Service, T1036 - Masquerading, T1045 - Software Packing, T1053 - Scheduled Task/Job, T1055 - Process Injection, T1056 - Input Capture, T1057 - Process Discovery, T1060 - Registry Run Keys / Startup Folder, T1071 - Application Layer Protocol, T1082 - System Information Discovery, T1089 - Disabling Security Tools, T1095 - Non-Application Layer Protocol, T1096 - NTFS File Attributes, T1105 - Ingress Tool Transfer, T1112 - Modify Registry, T1119 - Automated Collection, T1129 - Shared Modules, T1497 - Virtualization/Sandbox Evasion, T1518 - Software Discovery, T1547 - Boot or Logon Autostart Execution, T1574 - Hijack Execution Flow

  • Tags: 0pgtwhu, aaaa, accept, adobe, a domains, adversaries, age86400 set, akamaias, akamaiasn1, alerts, all scoreblue, all search, amazon02, analysis date, analysis ob0001, analysis ob0002, april, as15169, as15169 google, as16509, as20940, as29873, as3359, as44273 host, as45102 alibaba, as46691, as4812 china, as54113, as8075, as852, ascii text, asnone united, authentihash, av detections, bcnt1, binary file, black mercedes, body, body xml, boot, botnet, catalog tree, check registry, china, china unknown, cname, code, connection, contacted, content type, control ob0004, cookie, copy, creation date, cuba, date, default, delete, delete c, delphi, detection b0009, displayname, dll sideloading, dns resolutions, domain, dynamic, dynamic link, dynamicloader, emails, embeddedwb, encryption, entries, error code, executable code, execution, execution t1547, expiration date, facebook, fastly error, file guard, filehash, files, file samples, file score, files location, files matching, flow t1574, geoip, germany unknown, get http, ghost, gmt content, google, hashes, high, high process, home welcome, hostid ec, hostname, http, http requests, hx88x9ax1e, ids detections, incorporated, indonesia, infection, info, injection t1055, intel, iocs, ip address, ip traffic, ipv4, javascript, jeff4son, july, june, keys, langchinese, legalcopyright, level3, levelbluelabs, library, library exe, local, logon autostart, lowfi, magic pe32, malicious, malware, mascore2, media, medium, memory pattern, meta, mexico, mike, mini, moved, msie, msil, ms windows, mx81xd1r, name servers, nct1, next, nxdomain, otx scoreblue, passive dns, path max, pattern domains, pdfcreator.sf.net, pe32, pe32 executable, persistence, pid425870621, please, please forgive me, port, potential scan, proton, public url, pulse pulses, pulse submit, push, query, ransom, read, read c, recon, record value, regbinary, registry, registry run, regsetvalueexa, related nids, related pulses, request, requestid, reserved, response, rtversion, salicode, scan endpoints, script domains, script script, script urls, sea p, search, server, servers, service, seznam, sha256, shellexecuteexw, show, showing, slot1, ssdeep, stack strings, startup folder, status, stream, suite, swipper, t1045, t1497 may, taobao network, telecom, therahand thouroughhand, tid700443057, tofsee, tools, tpid425870621, trid win32, trojan, trojanspy, twitter, type, ukraine, unid88000705, unique, united, unknown, upack, url analysis, url http, url https, urls, urls http, vhash, virtual machine, whitelisted, win32, win32 exe, win64, windows, windows nt, worm, write, write c, x84xa8xe8i, x87xe1x1d, x8dxb7xb7, x92xac, x95xd3xa4, xc2x84, yara detections, yara rule

  • View other sources: Spamhaus VirusTotal

  • Country:
  • Network:
  • Noticed: 3 times
  • Protocols Attacked: Anonymous Proxy
  • Countries Attacked: Anguilla, Aruba, Australia, Bahamas, Barbados, Canada, Cayman Islands, Costa Rica, Curaçao, Georgia, Guatemala, Japan, Mexico, Netherlands, Panama, Philippines, Poland, Saint Kitts and Nevis, Saint Martin (French part), Saint Vincent and the Grenadines, Sint Maarten (Dutch part), Tanzania United Republic of, Trinidad and Tobago, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
  • Passive DNS Results: fieldcontrols.com barking-jobs.co.uk wohlstandstalent.de new999.com hdiglobalcpsui.support.uat.oceanwidebridge.com simedsui.support.uat.oceanwidebridge.com westonsui.support.uat.oceanwidebridge.com markel.support.uat.oceanwidebridge.com gaigomtestingsandbox01sv.support.uat.oceanwidebridge.com hdiglobalsui.support.uat.oceanwidebridge.com tfirthsandbox01sv.support.uat.oceanwidebridge.com atain.support.uat.oceanwidebridge.com ltisandbox01.support.uat.oceanwidebridge.com starrmarinesv.support.uat.oceanwidebridge.com vistamoderndentistry.com fc91dxctngnd20g5prodfo01-slot.paastest.epimore.com mgrfc91dxctngnd20g5prep.paastest.epimore.com fc91dxctngnd20g5inte.paastest.epimore.com www.norvestor.dk tadabet9.com dentistsofbuenapark.com qa-gb-viz-dsi-3954-secondbranchdecommiss.az.ssdgws.co.uk sarna.us latham-publisher.oniqa.com onfaker.com minehut.com dxctngnaq3tpm855prodfo01-slot.paastest.epimore.com sch-dxctngnaq3t5maa8prod.paastest.epimore.com coleteamrealestate.com fbc-erp.com www.sarna.us lexitascfs.com autobilthoven.nl powersage.com www.coleteamrealestate.com sch-dxctadminil7m3q0prep.paastest.epimore.com dxctadminil7m3q0inte.paastest.epimore.com www.mohovfr.live search.coleteamrealestate.com watchnicevideo.com bbbike.sourceforge.net scidavis.sourceforge.net gnome-kurdi.sourceforge.net kde-i18n-fi.sourceforge.net ro-oslib.sourceforge.net multiuso.sourceforge.net scardface.sourceforge.net foremost.sourceforge.net selfext.sourceforge.net msi2xml.sourceforge.net multi-search.sourceforge.net simonexplorer.sourceforge.net proxifier.sourceforge.net yasr.sourceforge.net mameosx.sourceforge.net xdxf.sourceforge.net cbios.sourceforge.net batchrunner.sourceforge.net utorrent.sourceforge.net phpmytourney.sourceforge.net phpscheduleit.sourceforge.net onzeminer.sourceforge.net phpmysport.sourceforge.net pommo.sourceforge.net zvonnews.sourceforge.net log1cms.sourceforge.net pas.sourceforge.net bfbtester.sourceforge.net htmlunit.sourceforge.net solex.sourceforge.net jwebunit.sourceforge.net noautorun.sourceforge.net skychart.sourceforge.net opennlp.sourceforge.net x-launcher.sourceforge.net arocesshacker.sourceforge.net u1x.sourceforge.net ksubtile.sourceforge.net cppcheck.sourceforge.net zinjai.sourceforge.net autogen.sourceforge.net sidplay-residfp.sourceforge.net tnef.sourceforge.net wiitar.sourceforge.net audioplex.sourceforge.net gmameui.sourceforge.net myfreetv.sourceforge.net bookmark-merger.sourceforge.net www.irrlicht.sourceforge.net psvlib.sourceforge.net openink.sourceforge.net kbackup.sourceforge.net impressive.sourceforge.net qcap.sourceforge.net openmcdf.sourceforge.net ltblighttaybind.sourceforge.net umit.sourceforge.net nmap6.sourceforge.net devildotnet.sourceforge.net ipmiutil.sourceforge.net ezmorph.sourceforge.net parcellite.sourceforge.net yabause.sourceforge.net festalon.sourceforge.net audiobookcutter.sourceforge.net dvi2bitmap.sourceforge.net trusthub.sourceforge.net bbwin.sourceforge.net mvdsv.sourceforge.net ezquake.sourceforge.net www.flac.sourceforge.net jdosbox.sourceforge.net syntenyminer.sourceforge.net xine.sourceforge.net swami.sourceforge.net spellerpages.sourceforge.net snapraid.sourceforge.net dvdauthor.sourceforge.net jtreeview.sourceforge.net crawl-ref.sourceforge.net vmpk.sourceforge.net structuremap.sourceforge.net krumo.sourceforge.net wix.sourceforge.net jackit.sourceforge.net jedit.sourceforge.net kdenlive.sourceforge.net condorcet-dd.sourceforge.net kernelbook.sourceforge.net sweethome3d.sourceforge.net amide.sourceforge.net stripesnoop.sourceforge.net hatari.sourceforge.net irda.sourceforge.net supercsv.sourceforge.net exist.sourceforge.net sidplay2.sourceforge.net smultron.sourceforge.net contineo.sourceforge.net cglib.sourceforge.net diseaseontology.sourceforge.net radiotray.sourceforge.net oralog.sourceforge.net taskswitchxp.sourceforge.net winstone.sourceforge.net phppgadmin.sourceforge.net snackamp.sourceforge.net jac64.sourceforge.net fremo-block.sourceforge.net atechcatalog.wellsfargorewards.com openvigil.sourceforge.net tpapro.sourceforge.net subit-app.sourceforge.net sf-xpaint.sourceforge.net anatimer.sourceforge.net anagmt.sourceforge.net subtorrent.sourceforge.net midiquickfix.sourceforge.net puttysm.sourceforge.net wx7-zip.sourceforge.net rtmk.sourceforge.net cgoban1.sourceforge.net saguarogw.sourceforge.net csql.sourceforge.net voxrend.sourceforge.net andlinux.sourceforge.net wisncp.sourceforge.net jbook.sourceforge.net unittest-cpp.sourceforge.net vimdoc.sourceforge.net fanauticclub.es netpbm.sourceforge.net pam-ssh.sourceforge.net aaaaaaaaaaaaa.sourceforge.net archivemail.sourceforge.net www-prod.securitasecuador.com gedakc.users.sourceforge.net ncclamp.sourceforge.net pbims.sourceforge.net fart-it.sourceforge.net mppviewer.sourceforge.net openimscore.sourceforge.net ezh.sourceforge.net smallbasic.sourceforge.net tidy.sourceforge.net stage.altrodent.com xampplite.sourceforge.net matplotlib.sourceforge.net freetype.sourceforge.net quakespasm.sourceforge.net libsdl-android.sourceforge.net mgme.sourceforge.net commcloud.stg-bbbq-masai-de.cc-ecdn.net www.jjcipats.com jjcipats.com xmljs.sourceforge.net libgmail.sourceforge.net aspxmlrpc.sourceforge.net xltoolbox.sourceforge.net chickenloleur.sourceforge.net edit.acuvue.hn safex3.fr medichanzo.com freeextractor.sourceforge.net firestarter.sourceforge.net seawall.sourceforge.net shorewall.sourceforge.net luckybackup.sourceforge.net ponacademy-app.nl www.sofary.com zthread.sourceforge.net tarquin.sourceforge.net davmail.sourceforge.net commcloud.stg-bdjh-bodystore-no.cc-ecdn.net eemailme.com smsclictr.sourceforge.net qa-se-i8z-cmsrd-526-api-validations.az.ssdgws.co.uk conky.sourceforge.net windjview.sourceforge.net sylpheeddoc.sourceforge.net splatmud.sourceforge.net vmstore.lv r4xyzrb9fhhnfgbm.sourceforge.net win32forth.sourceforge.net conceptbase.sourceforge.net phenommsrtweake.sourceforge.net eidors3d.sourceforge.net clish.sourceforge.net pwnpi.sourceforge.net gnomeicu.sourceforge.net platypuswiki.sourceforge.net o2em.sourceforge.net befs-driver.sourceforge.net elvira.sourceforge.net rocketworkbench.sourceforge.net flexviews.sourceforge.net embsysregview.sourceforge.net shfs.sourceforge.net mpatrol.sourceforge.net exiftool.sourceforge.net mslp.sourceforge.net dita-ot.sourceforge.net quickdc.sourceforge.net soma-dev.sourceforge.net xtests.sourceforge.net utf-x.sourceforge.net tianocore.sourceforge.net simplyvbunit.sourceforge.net tsqlunit.sourceforge.net savi.sourceforge.net jester.sourceforge.net soaos.sourceforge.net fluxspace.sourceforge.net ippersonality.sourceforge.net ipapers.sourceforge.net apertium.sourceforge.net cpptk.sourceforge.net staging-2.cf-ocscom.net lejos.sourceforge.net jessicacheshire.users.sourceforge.net weeblefm.sourceforge.net inutero.sourceforge.net mlabwrap.sourceforge.net dunelegacy.sourceforge.net awstats.sourceforge.net oprofile.sourceforge.net www.swegon.rs www.ffdshow-tryout.sourceforge.net buzzbuzzu.users.sourceforge.net libosmscout.sourceforge.net md-xed.sourceforge.net e2fsprogs.sourceforge.net readable.sourceforge.net jmono.sourceforge.net dbnm.sourceforge.net pigale.sourceforge.net goblin2.sourceforge.net asa-caltech.sourceforge.net www.zeoslib.sourceforge.net dorgel.sourceforge.net nms-cgi.sourceforge.net php-dropbox.sourceforge.net moepii.sourceforge.net miranda-icq.sourceforge.net apim.lawa.org chromium-bsu.sourceforge.net freefilesync.sourceforge.net cac.sandoz.com intralan.sourceforge.net ncompress.sourceforge.net mbm.sourceforge.net innounp.sourceforge.net essmodel.sourceforge.net gbsroofing.biz portecle.sourceforge.net u3-tool.sourceforge.net liba.sourceforge.net libmpeg.sourceforge.net acfilter.sourceforge.net mailsync.sourceforge.net exchange-away.sourceforge.net isync.sourceforge.net static.deporvillage.pt pagelayout.sourceforge.net rmir.sourceforge.net fivehundred.sourceforge.net buttonmasher.sourceforge.net arborrow.users.sourceforge.net healpix.sourceforge.net addanc.sourceforge.net gsim85.sourceforge.net ttfedit.sourceforge.net webchamado.sourceforge.net eveincome.sourceforge.net aviones.sourceforge.net dml.sourceforge.net mmmysql.sourceforge.net javalogging.sourceforge.net useq.sourceforge.net emdb.sourceforge.net fmpp.sourceforge.net mongoose.sourceforge.net simplescript.sourceforge.net vncsnapshot.sourceforge.net fping.sourceforge.net rkhunter.sourceforge.net www.securitasecuador.com.cdn.cloudflare.net m-play.sourceforge.net schememaker.sourceforge.net cdexos.sourceforge.net accessdb.sourceforge.net kmeleon.sourceforge.net wolf3d-s60.sourceforge.net ipac-ng.sourceforge.net audio-smarc.sourceforge.net wikidpad.sourceforge.net metsnavigator.sourceforge.net collatex.sourceforge.net anastasia.sourceforge.net cntlm.sourceforge.net netserver.sourceforge.net pywbem.sourceforge.net edlin.sourceforge.net uftp-multicast.sourceforge.net qa-nl-blq-mcl-19-codeoptimisation.az.ssdgws.co.uk lawk.sourceforge.net blackz.sourceforge.net firefloo.sourceforge.net hlan.sourceforge.net christtrekker.users.sourceforge.net decompiler.sourceforge.net iaw-scan2.sourceforge.net aimlbot.sourceforge.net esense.sourceforge.net anet.sourceforge.net waveshop.sourceforge.net findbugs.sourceforge.net automataeditor.sourceforge.net surf.sourceforge.net javaxm.sourceforge.net jgen.sourceforge.net staruml.sourceforge.net msgnet.sourceforge.net satsuma.sourceforge.net psrpop.sourceforge.net supercollider.sourceforge.net pebl.sourceforge.net wapache.sourceforge.net smoot.sourceforge.net rodi.sourceforge.net omv2.sourceforge.net zocalo.sourceforge.net openrods.sourceforge.net bitmate.sourceforge.net ector.sourceforge.net mindraider.sourceforge.net edict.sourceforge.net yaph.sourceforge.net nltk.sourceforge.net fswordfinder.sourceforge.net ngram.sourceforge.net ijbswa.sourceforge.net asteriskathome.sourceforge.net ripple.sourceforge.net noegnud.sourceforge.net bnt.sourceforge.net jpicedt.sourceforge.net sox.sourceforge.net cwb.sourceforge.net pasteit.sourceforge.net jpo.sourceforge.net ez-library.sourceforge.net simplebashbu.sourceforge.net coverfetcher.sourceforge.net sueca-ojogo.sourceforge.net jsc.sourceforge.net dirssync.sourceforge.net eigenms.sourceforge.net ltsp.sourceforge.net webmusic.sourceforge.net phlips.sourceforge.net mmcdlogger.sourceforge.net jsmol.sourceforge.net sheridanautotech.com deporvillage.pt spezios.sourceforge.net cpptcl.sourceforge.net pyschool3.sourceforge.net zmeter.sourceforge.net rebinf.users.sourceforge.net jibx.sourceforge.net pcsx-df.sourceforge.net avr-cpp-lib.sourceforge.net pdfview.sourceforge.net pbotagger.sourceforge.net zinf.sourceforge.net webcamwallpaper.sourceforge.net pirxx.sourceforge.net extcal.sourceforge.net cuaoffice.sourceforge.net hbasic.sourceforge.net rivus.sourceforge.net mecid.sourceforge.net orte.sourceforge.net jos.sourceforge.net pythonsdl.sourceforge.net winlame.sourceforge.net cdss.sourceforge.net ed2klinkcatch0r.sourceforge.net freemovie.sourceforge.net complearn.sourceforge.net winregsh.sourceforge.net atol.sourceforge.net erfurtwiki.sourceforge.net users.sourceforge.net pyobjc.sourceforge.net nsis.sourceforge.net sflogo.sourceforge.net apps.sourceforge.net tta.sourceforge.net mirandaqq.sourceforge.net krinnicam.sourceforge.net treelayout.sourceforge.net statifier.sourceforge.net pdiff.sourceforge.net bdreader.sourceforge.net pyvisa.sourceforge.net opensquid.sourceforge.net cnsface.sourceforge.net methane.sourceforge.net dcl.sourceforge.net www.sourceforge.net.cdn.cloudflare.net dotfeedlib.sourceforge.net gscope.sourceforge.net qa-gb-ipj-fbmvp-11606-textparsermultiple.az.ssdgws.co.uk rehash.sourceforge.net premisesconnect.hu avidemux.sourceforge.net straightforward.sourceforge.net scard4java.sourceforge.net networkstation.sourceforge.net tdtpd.users.sourceforge.net prunet.sourceforge.net webdeco.sourceforge.net objcryst.sourceforge.net sharpneat.sourceforge.net syslog-win32.sourceforge.net mpio.sourceforge.net nantcontrib.sourceforge.net notepad-plus.sourceforge.net ssldump.sourceforge.net projects.sourceforge.net.cdn.cloudflare.net qa-ie-qo0-fbmvp-11335-connectgraphqltosh.az.ssdgws.co.uk gensler.kr stage-object-data-portal.item24.com project-administration.item24.com stage-project-administration.item24.com work-catalog-data-management.item24.com sa.sandoz.com dev-catalog-data-management.item24.com apidemo.txflare.cf work-translator.item24.com dev-translator.item24.com tt8uilk.org work-object-workbench.item24.com stage-tron.item24.com stage-project-viewer.item24.com dev-project-viewer.item24.com summitmedicalspa.com qa-preview.lawa.org qa-au-6ir-ecrp-9697-fixupserturgent.az.ssdgws.co.uk work-catalog.item24.com stage-catalog.item24.com work-project-administration.item24.com work-project-viewer.item24.com dev-catalog.item24.com qa-gb-qkx-fixfbmvp-9769-big-branch-name.az.ssdgws.co.uk dev-tron.item24.com savemoneywithgates.com object-data-portal.item24.com

Malware Detected on Host

Count: 20 accb40d2dab8e5aab14bea0e57126c929a86c4a4d87edf77a7e161b45b34e863 4cb0004a34c9a43142e6fd21594a1823cfe082e66be63cc347863c395387b2c2 89a93d78d4cde63bcd7be2562695cb4d55e3d87061468441a95f397e3872ae1d 3122fe1a1cfff2fb252d2f4cacef267af0ffe9bb217f47db938149529e5cda46 bec3524b02dd0c8e6b651228c50d4318445c1e33b2ebd8f7a8b48e434e241d7a 380a679e8f012ba81425e615118b6a8b7eb060a62fa6edfb122cc05e9ecb5a93 acbfb666fcb6ebd089320516f5e4b6d74ebae1520677f1119a23b05636781165 cbfd0e838786e9e62ac99d09875e85e43bbf7cc9d704d68f732a1d54144a5075 abdfb1cf32e4d5af0c990f663c1ba21569ad85ee8cb4e0956753dce7e2ff2f63 ae72657f31714cad8270763850c59054afb7edadc02dc2346a64bb4072f2f6a3

Open Ports Detected

2082 2083 2086 2087 2095 443 80 8080 8443 8880

Map

Whois Information

Links to attack logs

anonymous-proxy-ip-list-2025-06-21

Share on: