104.18.21.161 Threat Intelligence and Host Information
General
This page contains threat intelligence information for the IPv4 address 104.18.21.161 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.
Likely Malicious Host 🟠 54/100
Host and Network Information
-
Mitre ATT&CK IDs: T1012 - Query Registry, T1023 - Shortcut Modification, T1027 - Obfuscated Files or Information, T1031 - Modify Existing Service, T1036 - Masquerading, T1040 - Network Sniffing, T1047 - Windows Management Instrumentation, T1053 - Scheduled Task/Job, T1054 - Indicator Blocking, T1055 - Process Injection, T1056 - Input Capture, T1057 - Process Discovery, T1060 - Registry Run Keys / Startup Folder, T1089 - Disabling Security Tools, T1106 - Native API, T1112 - Modify Registry, T1119 - Automated Collection, T1129 - Shared Modules, T1158 - Hidden Files and Directories, T1189 - Drive-by Compromise, T1204 - User Execution, T1562 - Impair Defenses
-
Tags: aaaa, access, a dd, address, a div, admin city, alerts, alexa, alexa top, all scoreblue, analysis date, analyzer paste, apple, april, artemis, as46606, as54600 peg, as8075, asn as13335, avast avg, av detections, bank, bits, bluehost, body, capture, centos, checking, china, ch ua, cisco umbrella, cname, code, content type, copy, count blacklist, country, covid19, creation date, cryptowall, cyber threat, date, date hash, delphi, detection list, div div, domain, domain status, download, dynamicloader, e emeseieee, e eue, engineering, entries, execution, explorer, filehash, filerepmalware, files ip, form, free, gmt content, gmt server, goatsinacoat, graph, h3 p, heur, hostname, ids detections, infrastructure, installer, intel, iocs, ios, ipv4, jid960554243, june, keybase, keys, li ol, local, location united, mail spammer, malicious, malicious site, malicious url, malware, malware beacon, media center, medium, memcommit, meta, million, module load, monitoring, moved, msie, ms windows, mtb dec, next, no data, observer, passive dns, password bypass, p div, pe32, pe32 executable, persistence, phishing, phishing site, problems, process32nextw, pulse pulses, pulses, push, qt translation, ransom, read c, record value, redmond admin, registrar, registrar abuse, registry, registry run, regsetvalueexa, relic, sample29, samples, samsung, scan endpoints, script domains, script script, script urls, search, sec ch, server, service, show, showing, site, slcc2, slfrd1, status, stream, suspicious, t1060, t1129, tag count, tag tag, team alexa, threat network, tools, tracking, trojan, tsara brashears, typeof, ua full, ua platform, uiebaae, united, unknown, urls, urls http, virtool, vj83, whois, whois lookup, whois registrar, win32, window, windows nt, wizard, wow64, write, write c, xml base64, yara detections, z1277946686, z1767086795, zeus
-
View other sources: Spamhaus VirusTotal
- Country:
- Network:
- Noticed: 2 times
- Protocols Attacked: Anonymous Proxy
- Countries Attacked: United States of America
- Passive DNS Results: www.cityofhughsonca.gov.cdn.cloudflare.net www.og777.link steinbacherrani.de og777.link netz-nebeneinkommen.de daytimelight.jp maidstone-jobs.co.uk www.cityofhughsonca.gov ext.prime.finra.org slpceuonline.com hbkidsdentistry.com app-slot.maplesapps.com atlashydraulics.net aghippo168.com www.oberoncapcorp.com.cdn.cloudflare.net mercedesbenzcommercial.africa www.promeai.pro 1451.app api.nprd.maplesapps.com digitalhumans.roche.com www.oberoncapcorp.com bancoagricola.gob.do blog.cyvi.io www.blog.cyvi.io api.digitalhumans.roche.com ana-esmo.digitalhumans.roche.com vision-dev-keycloak.acceo.com www.yoa.st aptivepestremoval.com ai-staging.yoa.st qa-es-to7-apd-3332-storagetabletomain.az.ssdgws.co.uk dxctrunnert1ec56inte.paastest.epimore.com dxctrunnert1ec56inte-slot.paastest.epimore.com dxctrunnert1ec56.dxptest.optimizely.com static.digitalhumans.roche.com srenht.com raddasynen.se qa9.asacolhdhcp.com www.promenademall.co.za edge.tenants.test-aws-boring-lizard-3482.auth0c.com wt.test-aws-boring-lizard-3482.auth0c.com test-aws-boring-lizard-3482.auth0c.com de-ie-9yi-apd-2045-keyvaultssmoketest.socrates.ssdgws.co.uk www.visa.ky www.ibranceinsights.com qa1-learning-scentre.yankeecandle.co.uk www.og21.no beta.og21.no polygon-test.dennis.ctm-demo.com akalinautos.nl prod.midsonafoodservice.se inte.midsonafoodservice.se testagentportal.argolimited.com pas2.partitionwizard.com automatedtest-qa6.ps-domain-dev.net mga-automated-tests-qa6.ps-domain-dev.net partitionwizard.com www.partitionwizard.com aida-qa6.ps-domain-dev.net derek-qa6.ps-domain-dev.net derek-qa6-pw.ps-domain-dev.net wt.plf-multi-atlas-cat9.auth0sbx.com edge.tenants.plf-multi-atlas-cat9.auth0sbx.com plf-multi-atlas-cat9.auth0sbx.com foundationmedicine.ee bs.all-lb.ssl4saas.com api.agentportal.argolimited.com qa-dk-2dh-caecom-4965-remove-socket-acti.az.ssdgws.co.uk qa-no-ctu-fbmvp-11543-preventexceptionsb.az.ssdgws.co.uk qa-gb-d3h-fbmvp-11369-addcheckstyletovue.az.ssdgws.co.uk widget-querylayer.flywire.tech querylayer.flywire.tech api-querylayer.flywire.tech qa-ie-vlp-fbmvp-11033-mappmsvaluefromyex.az.ssdgws.co.uk sve-images-dev.forward-publishing.io wt.sofi-us-prod-1.auth0app.com sofi-us-prod-1.auth0app.com edge.tenants.sofi-us-prod-1.auth0app.com fp-website-images.forward-publishing.io ref-images-staging.forward-publishing.io qa-gb-ukv-caecom-3542-autologout.az.ssdgws.co.uk ref-images-local.forward-publishing.io servicing-data-api-ext.saas.rate.com ref-images-dev.forward-publishing.io bmg-images.forward-publishing.io whothatgirl.com sve-images-staging.forward-publishing.io sve-images-development.forward-publishing.io bmg-images-production.forward-publishing.io bmg-images-staging.forward-publishing.io bmg-images-dev.forward-publishing.io asc-images.forward-publishing.io forward-publishing.io asc-images-dev.forward-publishing.io us-south.wh-awb.watson-health.ibm.com agent.goldenbat777.com app.goldenbat777.com 85jj.net levelfielddigital.com dennis.ctm-demo.com tuborg.com www.tuborg.com uatvalidate.transunion.com.ph spotcoolerlocations.com esg.argolimited.com signage.argolimited.com agentportal.argolimited.com argolimited.com www.goldenbat777.com m.goldenbat777.com de-de.stage.senetic.com testportal.argolimited.com staffshop-uat.loreal.sg staffshop.loreal.sg rundeck.flywire.tech www.minami-nutrition.dk www.argolimited.com phidirect.com jira.flywire.tech neutrogenanaturals.com zoominternalmail.com loreal.sg www.lcprofiles.net itsfs.com goldenbat777.com test.theuniverse.cf www.imlytahcp.com surety.itsfs.com iransanj.org portal.argolimited.com portal-train.argolimited.com argopi-train.argolimited.com www.penaten.ru penaten.ru uat.argolimited.com 4hux99.com cloudmigrator.flywire.tech cpr360.org biostar.flywire.tech 1.gall-gif.com www.argolimited.com.cdn.cloudflare.net portal.argolimited.com.cdn.cloudflare.net wh-awb.watson-health.ibm.com portal-train.argolimited.com.cdn.cloudflare.net argopi-train.argolimited.com.cdn.cloudflare.net uat.argolimited.com.cdn.cloudflare.net www.goldenbat777.com.cdn.cloudflare.net m.goldenbat777.com.cdn.cloudflare.net regus-shareplans.com africa.visa.com confluence.flywire.tech gall-gif.com imlytahcp.com thomsfourwheeldrive.com gitlab.flywire.tech symplycatfood.jp penaten.ru.cdn.cloudflare.net www.penaten.ru.cdn.cloudflare.net africa.visa.com.cdn.cloudflare.net tertwronletarfi.pro yoa.st www.zlsjai.live zlsjai.live l3cq.tertwronletarfi.pro lcprofiles.net cv6v.tertwronletarfi.pro xmkf.tertwronletarfi.pro theuniverse.cf www.grantthornton.jp.cdn.cloudflare.net
Malware Detected on Host
Count: 11 c8c0fd7eda42e5fb56855a043eea0214299da90bbf75f8c2072b1a5855569d3b f6ba59bf748af70466b41c4ab07dd2b958c2ff860bddca584eb0667e7457d490 b647deb19c18a5fc777d95b552b13defc6922f2d4d538e747dfb75d9394aeb4c bff489d09ea3b806463f01bd65acc762556c0f7ed5192b2d0ec50c021711149d e1051744361f921d186da488d98c71eacd8de54c5bcaff18969045ab88b95b68 3a4184806d633c733034caa49fa2050752fc1401adf19b3ffea9f854844f79f9 8efa31eecec50d5cfd66e4a263b122fe4563234c0a850aa55eba5fe28668757c 80a2a96549bb8201fe0949429ea0fd01c86bac228438154824d1392a294a50d4 6712b25c966ea060432d3a72e0d0f4f63355b0a381b042de1f4dbabb8efdf812 d7766610ebb800221b26db0868bfd2b3db342934cb6c3b5c4d35e9730860c17c
Open Ports Detected
2082 2083 2086 2087 2095 443 80 8080 8443 8880
Map
Whois Information
- NetRange: 104.16.0.0 - 104.31.255.255
- CIDR: 104.16.0.0/12
- NetName: CLOUDFLARENET
- NetHandle: NET-104-16-0-0-1
- Parent: NET104 (NET-104-0-0-0-0)
- NetType: Direct Allocation
- OriginAS: AS13335
- Organization: Cloudflare, Inc. (CLOUD14)
- RegDate: 2014-03-28
- Updated: 2024-09-04
- Comment: All Cloudflare abuse reporting can be done via https://www.cloudflare.com/abuse
- Comment: Geofeed: https://api.cloudflare.com/local-ip-ranges.csv
- Ref: https://rdap.arin.net/registry/ip/104.16.0.0
- OrgName: Cloudflare, Inc.
- OrgId: CLOUD14
- Address: 101 Townsend Street
- City: San Francisco
- StateProv: CA
- PostalCode: 94107
- Country: US
- RegDate: 2010-07-09
- Updated: 2024-11-25
- Ref: https://rdap.arin.net/registry/entity/CLOUD14
- OrgNOCHandle: CLOUD146-ARIN
- OrgNOCName: Cloudflare-NOC
- OrgNOCPhone: +1-650-319-8930
- OrgNOCEmail: noc@cloudflare.com
- OrgNOCRef: https://rdap.arin.net/registry/entity/CLOUD146-ARIN
- OrgAbuseHandle: ABUSE2916-ARIN
- OrgAbuseName: Abuse
- OrgAbusePhone: +1-650-319-8930
- OrgAbuseEmail: abuse@cloudflare.com
- OrgAbuseRef: https://rdap.arin.net/registry/entity/ABUSE2916-ARIN
- OrgRoutingHandle: CLOUD146-ARIN
- OrgRoutingName: Cloudflare-NOC
- OrgRoutingPhone: +1-650-319-8930
- OrgRoutingEmail: noc@cloudflare.com
- OrgRoutingRef: https://rdap.arin.net/registry/entity/CLOUD146-ARIN
- OrgTechHandle: ADMIN2521-ARIN
- OrgTechName: Admin
- OrgTechPhone: +1-650-319-8930
- OrgTechEmail: rir@cloudflare.com
- OrgTechRef: https://rdap.arin.net/registry/entity/ADMIN2521-ARIN
- RNOCHandle: NOC11962-ARIN
- RNOCName: NOC
- RNOCPhone: +1-650-319-8930
- RNOCEmail: noc@cloudflare.com
- RNOCRef: https://rdap.arin.net/registry/entity/NOC11962-ARIN
- RAbuseHandle: ABUSE2916-ARIN
- RAbuseName: Abuse
- RAbusePhone: +1-650-319-8930
- RAbuseEmail: abuse@cloudflare.com
- RAbuseRef: https://rdap.arin.net/registry/entity/ABUSE2916-ARIN
- RTechHandle: ADMIN2521-ARIN
- RTechName: Admin
- RTechPhone: +1-650-319-8930
- RTechEmail: rir@cloudflare.com
- RTechRef: https://rdap.arin.net/registry/entity/ADMIN2521-ARIN
Links to attack logs
anonymous-proxy-ip-list-2025-06-23 anonymous-proxy-ip-list-2025-06-22
Share on: