104.18.13.119 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 104.18.13.119 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Likely Malicious Host 🟠 54/100

Host and Network Information

  • Mitre ATT&CK IDs: T1012 - Query Registry, T1018 - Remote System Discovery, T1027 - Obfuscated Files or Information, T1033 - System Owner/User Discovery, T1043 - Commonly Used Port, T1055 - Process Injection, T1057 - Process Discovery, T1059 - Command and Scripting Interpreter, T1060 - Registry Run Keys / Startup Folder, T1094 - Custom Command and Control Protocol, T1112 - Modify Registry, T1129 - Shared Modules, T1140 - Deobfuscate/Decode Files or Information, T1176 - Browser Extensions, T1215 - Kernel Modules and Extensions, T1449 - Exploit SS7 to Redirect Phone Calls/SMS, T1457 - Malicious Media Content, T1491 - Defacement, T1497 - Virtualization/Sandbox Evasion, T1583 - Acquire Infrastructure, TA0011 - Command and Control, TA0037 - Command and Control

  • Tags: 2nd corintnthians 4:8-9, 707713, active related, activity dns, added active, a domains, aes256gcm, agent tesla, algorithm, all octoseek, all search, all txt, amadey, america asn, analyze, anomalous_deletefile, anomalous file, antidebug_guardpages, antivm_generic_disk, a nxdomain, apple ios, april, as133618, as134175 unit, as16509, as29066 host, as38365 beijing, as393601 state, as397241, as47846, as4837 china, as63949 linode, as6461 zayo, asnone, asyncrat, august, author, awful, azorult, backdoor, backdoor type, banker, beta version, body, brian sabey, brontok, bundled, bypass_firewall, c2, ca1 odigicert, cellbrite, certificate, certsentry, chaos, check in, china, china unknown, click, cmstp, cname, cnc, cobalt strike, code, collections, command, command and control, communicating, components, contacted, contact phone, cookie, copy, core, creation date, critical, crlf line, cryptowall, csc corporate, cus cndigicert, cyber espionage, daisy coleman, dalles, dark, data, date, dcom, default, delete, delete c, delphi, disables_windowsupdate, discovery, dns lookup, dns replication, domain, domain privacy, domains, download, dynamic, dynamic_function_loading, dynamicloader, emails, emotet, encrypt, entries, error, eternalblue, eva reimer, evilnum, execution, expiration date, exploit, facebook, february, fexp24007246, file execution, filehashmd5, filehashsha1, files, floxif, formbook, full name, gecko, germany unknown, get na, global g2, gmt content, go, goldfinder, goldmax, google, guard, hacking apple, hacktool, hallrender, high, historical, historical ssl, hong kong, hostname, hostnames, house.mo.gov, http_request, https://lawlink.com/documents/10935/blackbag-technologies-announ, ieudinit, india, indicator role, info, injection_create_remote_thread, injection_inter_process, iocs, ipv4, june, keepaliveyes, keylogger, khtml, local, location united, lockbit, lokibot, malicious, malware, malware infection, maui ransomware, maze, media center, medium, metro, mhkz, midia-4, minutes ago, missouri, modify_proxy infostealer_cookies, msie, mtb feb, mvi2, name servers, nat32, network_http, next, njrat, november, nsyt, number, nxdomain, observed dns, october, open ports, otx octoseek, parallax rat, parent domain, passive dns, paste, pegasus, pega type, persistence_autorun, playgame, powershell, powershell_download, powershell_request, privateloader, probe ms17010, problems, procmem_yara, pulse pulses, pulses cve, pulse submit, pulses url, push, python, qakbot, qbot, quasar, query, ransom, ransomexx, ransomware, record type, record value, redir, referrer, registrar, registrar abuse, registrar iana, registrar url, registry domain, related pulses, remcos, remcos rat, report spam, resolutions, rgba, role title, roundup, sabey, safebae, sample, samples, scan endpoints, search, september, server, servers, service, sha256, show, showing, sibot, simda, slcc2, ssl certificate, startpage, state, status, studio created, tactics, target, targeting, targeting tsara brashears, taskscheduler, team, threat, threat analyzer, threat network, threat roundup, title added, tls rsa, tracer tool, trojan, trojandropper, tsara brashears, ttl value, tulach, type indicator, type name, types of, typosquatting, unicode text, united, united kingdom, united states, unknown, url analysis, url http, url https, urls, urls http, urls https, ursnif, utah, utf8, v3 serial, veryhigh, virgin islands, wannacry, wc3 rpg, white goldmax, whois record, whois whois, win32, win32 exe, win64, windows nt, wininit, win.trojan, worm, wow64, write, xpcegvo2adsnq, yara detections, yara rule

  • View other sources: Spamhaus VirusTotal

  • Country:
  • Network:
  • Noticed: 2 times
  • Protocols Attacked: Anonymous Proxy
  • Countries Attacked: Australia, China, Hong Kong, United States of America
  • Passive DNS Results: www.foundryusapool.com cyl.mcmc.gov.my fairagree.top www.telegramxr.com tss.mcmc.gov.my vabysmo-live.com msmart.mcmc.gov.my telegramxr.com mcmc.gov.my foundryusapool.com efms.mcmc.gov.my specify.caroma.co.nz www.mcmc.gov.my qa-nz-u1b-apd-4486-uplifttemplates.az.ssdgws.co.uk dxctngnacc7ko62eprod-slot.paastest.epimore.com wscbetdeal.com ocrelizumabinfo.com xn–tl3b08pipj.com dailyhots.com caroma.co.nz fpublic.bnbstatic.com.cdn.cloudflare.net nestfamilymedicine.com wellnesscafe.thebemed.co.za reserveps.dev fpublic.bnbstatic.com www.forskningsraadet.no evw-uk.com www.evw-uk.com www.midtowngrillams.com www.thebemed.co.za docs.arianee.org qa-ie-2gd-fixdsi-2675-pdbluegreenrebuild.az.ssdgws.co.uk verif.arianee.org tools.arianee.org aerogardensupport.com oneshop-tunisia-staging.decathlon.tn edge.tenants.test-aws-dusty-carp-5732.auth0c.com wt.test-aws-dusty-carp-5732.auth0c.com test-aws-dusty-carp-5732.auth0c.com changeagents.info deu345.com edit.stage-int.acquia.finra.org www.holidayclub.nu schwinnbike.com qa-gb-bqx-fixmcl-447-orderhistorysort.az.ssdgws.co.uk thebemed.co.za booking.equair.com.ec api-gateway.ms-ins.com gytsuis.org unileverapi.paradox.ai gkcleanroom.com ocean-inter.com www.stockholmshamnar.se wim-19.auth0c.com cryptofon.com westservicecenterinc.com eflabs.io www.stockholmshamnar.se.cdn.cloudflare.net input.smartcapture.com.au likestat.site t1y1.bet fdabb9bd35caad6b2dff78c103fcd713685b34e8.vercel-workers.com inputqa.smartcapture.com.au qadeepblue2.eflabs.io qa-batman-eu.eflabs.io qadeepblue3.eflabs.io qv1.eflabs.io qa-aem.eflabs.io qv.eflabs.io qlikview.eflabs.io qa-axis.eflabs.io mds.eflabs.io deepblue3.eflabs.io cube.eflabs.io reports.eflabs.io bic.eflabs.io aem.eflabs.io zabbix-aws.eflabs.io stg-aem.eflabs.io stg-batman-eu.eflabs.io stg-axis.eflabs.io stagingdeepblue2.eflabs.io stagingdeepblue3.eflabs.io nexus3.eflabs.io jira.eflabs.io nv1k8s-devops-f-devops-public.eflabs.io nexus3-public.eflabs.io 1a8f28d8dde5714d021d8079a4850c5b2c5f0450.vercel-workers.com reactive.lovingbet.it privacy.collegeboard.org my-api.hometogo.com sso.hometogo.com my.hometogo.com www.erasearch.co hertaland.de erasearch.co prep.stockholmshamnar.se prod.stockholmshamnar.se www.lovingbet.it contents.lovingbet.it play.lovingbet.it creditsclown.com inte.stockholmshamnar.se jobsindice.com renkaatvaihtoon.fi www.renkaatvaihtoon.fi intego.com bio-organicfarming.com offer.intego.com www.intego.com podcast.intego.com site.intego.com.cdn.cloudflare.net brakeout.me ho-app.intego.com.cdn.cloudflare.net podcast.intego.com.cdn.cloudflare.net feedback.intego.com.cdn.cloudflare.net safe.intego.com.cdn.cloudflare.net antivirus.intego.com.cdn.cloudflare.net islesports.com store.intego.com.cdn.cloudflare.net offer.intego.com.cdn.cloudflare.net patrickbruel.com salesforce.intego.com.cdn.cloudflare.net staging.intego.com.cdn.cloudflare.net blog.staging.intego.com.cdn.cloudflare.net staging-blog.intego.com.cdn.cloudflare.net sub.mgrdxctngnadxcp224bprod.paastest.co.uk.cdn.cloudflare.net stavka-na-vulcane.club timtest.intego.com.cdn.cloudflare.net lb-lovingbet-vip.lovingbet.it.cdn.cloudflare.net casino.lovingbet.it.cdn.cloudflare.net 9444hu.com www.9444hu.com 839cf.com www.rosebikes.ch.cdn.cloudflare.net ccc822.com www.expatforum.com.cdn.cloudflare.net betwego28.com

Malware Detected on Host

Count: 3 75825d834473573abc2ea690b9bee8eaa33bdb797ec666addc6c16abdb2378cd 48e6c0ba50c6dc2a16863db2544edbcdf587cf020239d42124edadde2e83d2a1 cac1056ef61f3fdff3fbd49c6f1151e59a8d9c5f18e640f9e26a4c7d13f6dc8f

Open Ports Detected

2082 2083 2086 2087 2096 443 80 8080 8443 8880

Map

Whois Information

Links to attack logs

anonymous-proxy-ip-list-2025-06-23 anonymous-proxy-ip-list-2025-06-22

Share on: