104.18.40.18 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 104.18.40.18 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Likely Malicious Host 🟠 60/100

Host and Network Information

  • Mitre ATT&CK IDs: T1027 - Obfuscated Files or Information, T1059 - Command and Scripting Interpreter, T1068 - Exploitation for Privilege Escalation, T1071 - Application Layer Protocol, T1105 - Ingress Tool Transfer, T1176 - Browser Extensions, T1496 - Resource Hijacking, T1497 - Virtualization/Sandbox Evasion

  • Tags: abuse, acint, adload, agent, agenttesla, akamaias, akamaiasn1, alexa, alexa top, amazon02, analysis, andromeda, apple, april, artemis, as15169, as16509, as20940, as3359, as8075, as852, astaroth, august, ave maria, azorult, back, bambernek, bandoo, bank, betabot, blacklist, blacklist http, body, bradesco, brontok, changelog, cisco umbrella, citadel, class, cleaner, click, cloud xcitium, cobalt strike, communicating, conduit, contacted, copy, core, covid19, critical, critical risk, crypt, cuba, cutwail, cyber security, cyber threat, dark power, data, date, detection list, detplock, dnspionage, dns poisoning, domains, domaiq, download, downloader, dropper, emotet, engineering, error, et tor, execution, exploit, facebook, fakealert, falcon sandbox, fareit, file, filetour, floxif, footer, form, formbook, friendly, function, fusioncore, general, generator, generic, geoip, ghost, google, hacktool, header, heur, historical ssl, history first, hotmail, http, hybrid, iframe, indonesia, installcore, installpack, ip summary, ipv4, june, keybase, keygen, kgs0, kiannas law, kls0, known tor, kovter, kryptik, layer, level3, lockbit, main, malicious, malicious site, maltiverse, malware, malware site, march, matsnu, media, meta, mexico, million, mimikatz, miner, mini, monitoring, nanocore, networm, nexus, nircmd, nymaim, occamy, opencandy, outbreak, password, patcher, pattern match, pe resource, phishing, phishing site, pony, presenoker, proton, psexec, public url, pyinstaller, pykspa, radamant, ransomware, redline stealer, referrer, remcos, resolutions, response final, revil, riskware, runescape, safe site, samples, secrisk, service, seznam, simda, site, sodinokibi, sophos sophos, ssl certificate, startpage, stealer, steam, strike, strings, submission, summary, suppobox, team, team phishing, telecom, threat report, tinba, tmobile, tofsee, trojan, trojanx, tsara brashears, twitter, ukraine, united, unknown, unruy, unsafe, url https, urls, url summary, utc http, vawtrak, verdict cloud, virustotal, virut, wacatac, whois record, whois whois, win32, win64, xcitium verdict, xtrat, zbot, zeus, zpevdo

  • View other sources: Spamhaus VirusTotal

  • Contained within other IP sets: hphosts_fsa, hphosts_wrz

  • Country:
  • Network:
  • Noticed: 13 times
  • Protocols Attacked: Anonymous Proxy
  • Countries Attacked: Anguilla, Aruba, Australia, Bahamas, Barbados, Canada, Cayman Islands, Costa Rica, Curaçao, Georgia, Guatemala, Japan, Mexico, Netherlands, Panama, Philippines, Poland, Saint Kitts and Nevis, Saint Martin (French part), Saint Vincent and the Grenadines, Sint Maarten (Dutch part), Tanzania United Republic of, Trinidad and Tobago, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
  • Passive DNS Results: www.pfizerrxtreatment.com pfizeroncologytogether-portal.com cfed-stg-ext.transunion.co.uk stage.cealloys.sandvik y3bet.tw y3bet.co rsgroup.apps.emersondx.com y3y3y3.cc payment.bigtime.cenderivco.co.uk payment.southseas.cenderivco.co.uk heatbleed.us play.bigtime.cenderivco.co.uk workerpoc.cenderivco.co.uk zhu-4871881.x-5-i-a.com y3y3y3y3.com cdnl.iconscout.com y3326.com y3388.com y3355.com y3536.com y3318.com y3306.com y3bet.bet az037rd.com sak523d.com sed74264.com hxr52178.com hx745hy.com mj531te.com majibao36.com mm638yu.com mnc13647.com ios05yy.com y33133.com yyios02.com yyios01.com yy852es.com qkj85210.com y3313.com y33533.com y3316.com yue35425.com y3319.com y3312.com pw851sx.com bd7ed6.com bdl01031.com gre79253.com gfs367f.com ghb84239.com jk528yt.com 635y3k.com 03iosyy.com 04iosyy.com kls85632.com kds35216.com fd8025y.com fg365y3.com payment.games.cenderivco.co.uk fastkey.staging.propertyguru.com www.etnografiskamuseet.se hybris-admin.temp.repco.com.au cdn3d.iconscout.com cdni.iconscout.com iconscout.com cdn.iconscout.com www3.makeyourowncollagen.com unicons.iconscout.com gaming-cd6dc1.bet.cenderivco.co.uk careertrend.com www2.makeyourowncollagen.com makeyourowncollagen.com auth.load.acs.adt.com adt-load.auth0app.com edge.tenants.adt-load.auth0app.com wt.adt-load.auth0app.com developer.markup.io developer.markup.io.cdn.cloudflare.net app.markup.io preprod.everfresh.se sweetwaterstbk.com yalyins100.com semprelivre.com.br 080340.com html-free.com workerpocdb.cenderivco.co.uk www.sweetwaterstbk.com smarterlanguage.com hi-fog.xyz tractorbaazi.com canchabet.mx falabellatienda.com mynbpropertyassessment.ca safestopu.org www.toshin-chugaku.com production.etnografiskamuseet.se integration.etnografiskamuseet.se www.wileycatalog.com app.markup.io.cdn.cloudflare.net api.mykybella.com.cdn.cloudflare.net qa2.mykybella.com.cdn.cloudflare.net www.roulette.ca api.markup.io.cdn.cloudflare.net my.arlo.com.cdn.cloudflare.net roulette.ca api.markup.io www.kitekonnect.fr qa2.mykybella.com api.mykybella.com training.mykybella.com heute-anlegen.de cname1026.com www.sopetoskey.com displate.com c.o0bg.com expatbet.org alpha.secretsresortseu.com flanaganfirst.com beta.secretsresortseu.com betwin247.net bodycountband.com safehomesafebaby.com rufuscasino.com ralongjesen.tk unchopmobibpa.tk pylanmahill.ga ookconda.ga downtime.expert agbarena.com persima.cf mismospts.si ciaplanalocsesme.ga status.shop4trac.com lderunexdaquapo.tk countbirkefi.tk knowwilulo.tk flowecstaticpartner.best prehlepsscanococti.tk www.dentistasmurcia.net rereslosa.tk ningcontcronwhii.tk brakloligh.tk promowins.online vicsucidi.ga denahealthsew.cf quosticesspig.ga talputhetedu.gq www.screwsmel.buzz lagedehoqah.gq trinpostnepe.ml tuzonagamer.gq risicontecaptwith.tk fmasoschifrehydist.tk sotijaser.tk tracabeles.ml www.socialnetworkaccounts.com.cdn.cloudflare.net nitdipocgou.tk virhovare.tk parpilyrottmar.tk www.elovacraft.net www.hokislot77.com thelittlebigco.com bitchesonthetop.com tiotonre.tk happyworld888.com domere.tk ulcohonorb.cf tioticoposusypp.tk sdgefaemgarseusgffpecegodmecujos.xyz www.mobf21.ru chehtowoulmeicoms.ml cendumbrough.tk mobf21.ru typeyourname.com automation.bugbusters.com.br kimtai.info mancoma.tk tour-tournee.de montagpena.ru biopertichitcaser.ml hx888.app www.hx888.app showbreeze.xyz beta.aynetsoft.com.tr newrace.store labahiaec.com hostmaster.hostmaster.hostmaster.rtdesign.xyz download.dorotheelehnen.de shyedea.xyz xn–kapilrkasser-bdb.dk dorotheelehnen.de aimeejouel.com rhllybv.xyz cargocatcafe.com yastlblog.com bahsedeger63.com caesannieux.monster luciboutloperdend.tk rhymvarlindlchecsandter.gq panel.shieldbotlist.tk administrator.zoopix.ir volyn2014.org.ua www.volyn2014.org.ua legal-download-of-the-ghoorbagheh-series.xyz lander.jrwmq0omq1.xyz tioravisanaros.tk hjianching.com www.vedatutorialsindia.com ftp.vedatutorialsindia.com smtp.vedatutorialsindia.com pop.vedatutorialsindia.com vedatutorialsindia.com www.frsreparacoes.pt 7777929.com csgo-giveawaay.gq cpcalendars.paineldj5.com.br cpcontacts.paineldj5.com.br zeboopro.com ufamvp168.com onlinepandit.gq.cdn.cloudflare.net www.onlinepandit.gq.cdn.cloudflare.net wiemirectstatap.tk teyclasotibbrookin.ga talswestrasizi.ml mk-website3.com blacdaihatherla.tk intermezzogroep.nl epmma.net.ru dentistasmurcia.net bhujilunmeatlumat.gq forums.shieldbotlist.tk www.songofgaia.net songofgaia.net overdenmaretin.gq daiwarolandme.tk femog3.com bonusslot.club www.bonusslot.club promogreenpramuka.com pussyxcamsmovie.agency enmarcuchernubi.tk ermadeckchanpho.tk sympmopathpumist.tk flunoftomamsi.tk vishwagokulam.com forexbesthero.com jrwmq0omq1.xyz preorder.com.br www.preorder.com.br elovacraft.net tabvomapoxehurt.tk www.aynetsoft.com.tr aynetsoft.com.tr eticaretv1.aynetsoft.com.tr richardsongill.co.uk shieldbotlist.tk buterya.com wernerelectric.co diefranekerarsi.tk ttt552.com www.ttt552.com exsaroccuberi.tk terleogyutoomesa.tk fallenifceomoling.tk www.raovat.me serves.admin.zcy608.com imorcerperptrom.cf homastyleunaux.com raovat.me grjsvf.online 976539.com vibranthealthyprotectiveskincream.com npsci.com aiolia.org.cdn.cloudflare.net www.keyrm.com ciebdb.com football-predictions.ng voluptatibuseummartine.com many-choices.club www.coffeeatnewlife.com.au www.happytouristz.com happytouristz.com halewholetestimony.top prodonanasmare.ml bravitvamudi.ml degner.cyou www.7winds.school planetblade.com www.aiolia.org.cdn.cloudflare.net coofiltertgasttac.gq www.syakur.nl syakur.nl radsnveserupulde.ml mrbit.xyz www.mrbit.xyz qopty18odrz.tk damani.club thesavingadvisor.work orjifastcarturf.tk hashtagoffer.com bests.n00.ir smashkart.com rotarycacadorsulcontestado.org.br memoryexcuses.top hi.consciouseating.in top5of.us sepasamorin.gq kohlersabag.ch bubalairesq.tk proworrobipa.cf wgsykmqq.top www.musiquelyon.com.cdn.cloudflare.net www.fangzhi4265.com.cn.cdn.cloudflare.net panel.hugohedlund.se 8tab365.com southerncrossflooring.co.uk rmidnakisvewitri.tk halroporich.tk necomnonisle.tk ybuvezupi.gq www.villajoypatmos.com villajoypatmos.com ebtammyapostneeds.cf lanbatalekindmar.cf firshydnacolrigh.ga kbra.app makeappsbetuk.com geodisetwardtack.cf weinetcaycernti.cf vieremolaper.cf dietmarschaffer.de hardnefaspy.tk conqueredrealitieshealth.com lunaticuhc.ml mafattaco.tk zeobyvesphacer.ml benefitstobillionaire.com www.benefitstobillionaire.com cpcontacts.benefitstobillionaire.com cpcalendars.benefitstobillionaire.com qqqq.0542111.com.cdn.cloudflare.net flitefinfracimta.tk phideptunoncamet.ga gishinjima.ga www.trackertoweb.com n00.ir in-a-seniorcommunitiesok.live earthsteel.cf server.dvaexpress.it myfanart.net centraldecumpom.site mingnalcarsvodis.ga ajomsponsentachild.tk preftabecise.gq staurolite.us blancenttertconcompbi.tk liushiyang.online ducimusrepellenduslila.xyz taistublainfelac.tk haurewanandfitri.tk rholhzqi.icu rr693.com colwolflo.gq prasarbharti.online xzmoxtgo.icu ciatoolposucre.gq api.squaddle.co.uk squaddle.co.uk unacunderme.gq mortnewsmufftade.tk cpcalendars.zoopix.ir cpcontacts.zoopix.ir qqjqgykk.icu burtrechtcompfasmo.tk linrejig.gq globopadpihol.tk bipower.cf swiftdocumentonline.com rusliestar.cf prom-invest24.ru mrijgk.top carcasicysto.tk neucumnamegar.ml byvyzosoxe.tk pevato.tk nohoupanome.tk u-dread-life.gq quaverejh.ml trackertoweb.com xiderittu.tk neogexdohand.tk ydinyfawiraz.gq antiobooklily.cf derelahun.tk esuzubyq.cf tabletopcast.com spiropexencomgitt.tk topbabyclothingstore.xyz tatocuzaguwi.ml qdmqwit.tk global-haber.xyz pawasanufefa.ml idysusiwacij.tk steagojterteotab.ga itulakdiacuou.ga metisakutu.gq ogagpemorbarc.gq haladetzd.tk giritygoce.cf www.vianhyeuem.tk yvicicuk.gq lamojucowa.tk ifabidywazol.tk vianhyeuem.tk www.venus-fm.com.tw.cdn.cloudflare.net starpo.gq edewacikyf.tk brothrigantiri.tk nu5w35vq.xyz nunagorestsib.ml www.kino-teatr.biz kislevbeagles.com www.landtrek.co.cdn.cloudflare.net themeltjevzw.be cegitahosu.cf plerchebinbohel.tk 22pp8.com qoqorifege.gq prismahotfix.com.br altertaegroupnig.ml provision.lvtu.in mm.lvtu.in glencippiatatoug.gq recirckettpacdo.gq idikomyho.tk amincytbeltdon.gq riapenrihydmedd.ml 7winds.school mariecizova.tk zckuzrbhe.ga nanndiconreve.tk gbfoodricercasviluppo.com zipai102.rocks img.meirisw.com.cdn.cloudflare.net stabiloaula.es www.insurelineislandliving.com icloudbypass.online proccaratabo.ml admin.dvaexpress.it www.reydetallarines.com reydetallarines.com www.consciouseating.in consciouseating.in candypet.shop indayre.tk nn6x.com www.scutodramaga.com.cdn.cloudflare.net bisugaloro.tk www.railways.africa.cdn.cloudflare.net friv2-online.net split-pty.com www.bsbvagas.com.cdn.cloudflare.net periodent.co fulldancetv.com lp.bugbusters.com.br www.naturalanything.com algarvezonvakantie.com www.ucypisa.pl pubsevent.com hokislot77.com loveni.cz www.shop4trac.com shop4trac.com 1ss4.com morrellsolar.com www.dvaexpress.it globalartikel.com support.orlandina.com livehealy.host kampsrinaguttagnie.cf kolabenterprise.shop zoonafiltculviecon.tk pwgame-phoenix.info www.hepsimarket.site www.fmcloudcertificate.com t.fabrilife.com stage1.fabrilife.com fabrilife.com woo.fabrilife.com www.fabrilife.com hepsimarket.site wigomania.com wattse.com www.biorencontres.com tpsoyuz.ru einettoss.com www.icresponseinfo.com vnvocanotes.live www.taglineph.com.cdn.cloudflare.net portaldosterapeutas.com

Open Ports Detected

2052 2082 2083 2086 2087 2096 443 80 8080 8443 8880

Map

Whois Information

Links to attack logs

anonymous-proxy-ip-list-2025-08-22 anonymous-proxy-ip-list-2025-09-16 anonymous-proxy-ip-list-2025-09-21 anonymous-proxy-ip-list-2025-09-27 anonymous-proxy-ip-list-2025-06-30 anonymous-proxy-ip-list-2025-07-02 anonymous-proxy-ip-list-2025-08-12 anonymous-proxy-ip-list-2025-08-13 anonymous-proxy-ip-list-2025-07-18 anonymous-proxy-ip-list-2025-08-26 anonymous-proxy-ip-list-2025-08-31 anonymous-proxy-ip-list-2025-09-01 anonymous-proxy-ip-list-2025-09-02 anonymous-proxy-ip-list-2025-10-06 anonymous-proxy-ip-list-2025-06-26 anonymous-proxy-ip-list-2025-06-27 anonymous-proxy-ip-list-2025-08-03 anonymous-proxy-ip-list-2025-08-23 anonymous-proxy-ip-list-2025-09-05 anonymous-proxy-ip-list-2025-10-03 anonymous-proxy-ip-list-2025-10-04 anonymous-proxy-ip-list-2025-06-23 anonymous-proxy-ip-list-2025-07-13 anonymous-proxy-ip-list-2025-09-11 anonymous-proxy-ip-list-2025-10-20 anonymous-proxy-ip-list-2025-07-11 anonymous-proxy-ip-list-2025-07-15 anonymous-proxy-ip-list-2025-07-30 anonymous-proxy-ip-list-2025-08-10 anonymous-proxy-ip-list-2025-08-14 anonymous-proxy-ip-list-2025-08-21 anonymous-proxy-ip-list-2025-08-27 anonymous-proxy-ip-list-2025-08-30 anonymous-proxy-ip-list-2025-09-04 anonymous-proxy-ip-list-2025-10-02 anonymous-proxy-ip-list-2025-10-07 anonymous-proxy-ip-list-2025-07-01 anonymous-proxy-ip-list-2025-07-06 anonymous-proxy-ip-list-2025-07-24 anonymous-proxy-ip-list-2025-08-11 anonymous-proxy-ip-list-2025-09-15 anonymous-proxy-ip-list-2025-06-22 anonymous-proxy-ip-list-2025-07-07 anonymous-proxy-ip-list-2025-07-14 anonymous-proxy-ip-list-2025-07-23 anonymous-proxy-ip-list-2025-08-28 anonymous-proxy-ip-list-2025-10-05 anonymous-proxy-ip-list-2025-06-28 anonymous-proxy-ip-list-2025-06-29 anonymous-proxy-ip-list-2025-07-05 anonymous-proxy-ip-list-2025-08-25 anonymous-proxy-ip-list-2025-09-07 anonymous-proxy-ip-list-2025-09-20 anonymous-proxy-ip-list-2025-09-22 anonymous-proxy-ip-list-2025-09-25 anonymous-proxy-ip-list-2025-10-10 anonymous-proxy-ip-list-2025-06-24 anonymous-proxy-ip-list-2025-07-27 anonymous-proxy-ip-list-2025-08-08 anonymous-proxy-ip-list-2025-08-29 anonymous-proxy-ip-list-2025-09-08 anonymous-proxy-ip-list-2025-09-18 anonymous-proxy-ip-list-2025-09-30 anonymous-proxy-ip-list-2025-10-12 anonymous-proxy-ip-list-2025-07-12 anonymous-proxy-ip-list-2025-08-15 anonymous-proxy-ip-list-2025-08-17 anonymous-proxy-ip-list-2025-08-24 anonymous-proxy-ip-list-2025-09-10 anonymous-proxy-ip-list-2025-07-17 anonymous-proxy-ip-list-2025-10-16 anonymous-proxy-ip-list-2025-09-28 anonymous-proxy-ip-list-2025-07-22 anonymous-proxy-ip-list-2025-08-18 anonymous-proxy-ip-list-2025-10-17 anonymous-proxy-ip-list-2025-09-19 anonymous-proxy-ip-list-2025-10-13 anonymous-proxy-ip-list-2025-07-28 anonymous-proxy-ip-list-2025-07-31 anonymous-proxy-ip-list-2025-08-01 anonymous-proxy-ip-list-2025-08-05 anonymous-proxy-ip-list-2025-10-19 anonymous-proxy-ip-list-2025-09-06 anonymous-proxy-ip-list-2025-10-09 anonymous-proxy-ip-list-2025-07-19 anonymous-proxy-ip-list-2025-08-02 anonymous-proxy-ip-list-2025-09-12 anonymous-proxy-ip-list-2025-09-23 anonymous-proxy-ip-list-2025-10-11 anonymous-proxy-ip-list-2025-07-09 anonymous-proxy-ip-list-2025-07-10 anonymous-proxy-ip-list-2025-08-19 anonymous-proxy-ip-list-2025-09-09 anonymous-proxy-ip-list-2025-09-26 anonymous-proxy-ip-list-2025-09-29 anonymous-proxy-ip-list-2025-07-03 anonymous-proxy-ip-list-2025-07-04 anonymous-proxy-ip-list-2025-07-08 anonymous-proxy-ip-list-2025-07-29 anonymous-proxy-ip-list-2025-08-04 anonymous-proxy-ip-list-2025-08-07 anonymous-proxy-ip-list-2025-08-09 anonymous-proxy-ip-list-2025-09-03 anonymous-proxy-ip-list-2025-07-16 anonymous-proxy-ip-list-2025-07-25 anonymous-proxy-ip-list-2025-08-06 anonymous-proxy-ip-list-2025-09-13 anonymous-proxy-ip-list-2025-09-17 anonymous-proxy-ip-list-2025-10-08 anonymous-proxy-ip-list-2025-10-15 anonymous-proxy-ip-list-2025-06-25 anonymous-proxy-ip-list-2025-07-20 anonymous-proxy-ip-list-2025-07-26 anonymous-proxy-ip-list-2025-08-16 anonymous-proxy-ip-list-2025-08-20 anonymous-proxy-ip-list-2025-10-18 anonymous-proxy-ip-list-2025-09-14 anonymous-proxy-ip-list-2025-09-24 anonymous-proxy-ip-list-2025-10-01 anonymous-proxy-ip-list-2025-10-14 anonymous-proxy-ip-list-2025-07-21

Share on: