104.21.32.1 Threat Intelligence and Host Information
General
This page contains threat intelligence information for the IPv4 address 104.21.32.1 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.
🟠 Elevated — 60/100
Host and Network Information
- View other sources: Spamhaus VirusTotal Shodan AbuseIPDB
- Noticed: 25 times
- Protocols Attacked: Anonymous Proxy
- Countries Attacked: Australia, Canada, China, Denmark, Finland, Germany, Ireland, Japan, Lithuania, Luxembourg, Norway, Poland, Romania, Spain, Sweden, Taiwan, Ukraine, United Arab Emirates, United States of America
- Open Ports: 2082, 2083, 2086, 2087, 2095, 2096, 443, 80, 8080, 8443, 8880
- Tor Node: No
- Associated Malware Samples: 5834
Tags
- aaaa
- aaaaa
- abxcde
- accept
- accept encoding
- access ta0006
- address
- address google
- address range
- address server
- a domains
- adversaries
- Alberta
- Alberta Doctors
- Alberta Health Services
- Alberta Medical Association
- Alberta NDP
- Alberta UCP
- alerts
- algorithm
- alienvault
- allocation type
- amazon
- Amazon
- amazon rsa
- amazon s3
- analysis date
- analysis ob0001
- analysis ob0002
- Android
- anti
- apache
- apis
- ascii text
- asn15169
- asn46606
- asn as16509
- associated urls
- attack
- august
- auto-generated security
- av detections
- backdoor
- base64uidenc
- bbox
- Berbew
- black
- body
- Botnet
- bq jul
- Browser
- browsing
- c2
- Campaign
- catalog tree
- ca valid
- certificate
- certum code
- checks amount
- ch ua
- cidr
- ciebie
- City of Edmonton
- Civil
- Civilians
- cjutxg
- ck id
- ck matrix
- click
- close
- Cloudflare
- cloudfront
- cname
- cnc beacon
- cnmicrosoft ecc
- cobalt strike
- code
- code signing
- command
- Connect Care
- connection
- contacted
- content
- content type
- control ob0004
- control ta0011
- cookie
- copy
- copy md5
- copy sha1
- copy sha256
- core
- country name
- Covenent Health
- created
- creation date
- Crime
- crlf
- cryptexportkey
- crypto
- cus subject
- d4 portable
- data
- datacrashpad
- data oc0004
- data upload
- date
- date april
- date checked
- defense evasion
- delete
- destination
- detections
- detections none
- DGA
- dll windows
- DNS
- dns resolutions
- dock
- document file
- domain
- domain add
- domain name
- domain related
- domains
- domains show
- drop
- drop or
- drowol type
- drow type
- dynamicloader
- dyndns checkip
- e5 e5
- edge
- Edmonton Police Services
- EduRoam
- ef3ghigj
- eid1338769034
- eid4828312
- email address
- encrypt
- Endgame
- enter sc
- enter sou
- enter source
- enter sourue
- entity
- entity amazon4
- entries
- entries http
- error https
- Espionage
- Europe
- evasion defense
- evasion ta0005
- exchange meta
- exchange og
- exclude
- exclude data
- excluded ous
- executable
- execution
- expiration
- expiration date
- external ip
- extgstate
- extra
- extract
- extraction
- extraction fa
- extra data
- extra window
- extre data
- extr please
- facts otx
- failed
- failure
- false
- february
- filehash
- file score
- files domain
- files ip
- files location
- files related
- file type
- flag united
- flywheel
- footer
- format
- FormBook
- for privacy
- found
- frankfurt
- from
- g2 issuer
- g2 valid
- g4 issuer
- gecko
- general
- germany
- get http
- get https
- global
- globalc
- gmt content
- gmt date
- gmt etag
- gmt ifnonematch
- gmt path
- gmt server
- google llc
- google safe
- google tag
- google team
- Government
- Graphite
- green
- gtmkvjvztk
- gtmkvjvztk dl
- guard
- Hackers
- handle
- hellokitty
- helper
- high
- hio50 c1
- Hookbot
- hostname
- hostname add
- hostname xn
- HP
- html
- html document
- html internet
- html_smuggling
- http
- httponly
- https dane
- http yara
- hybrid
- icmp
- icmp traffic
- ids detections
- iframe tags
- imi i
- impact ta0040
- imphash pehash
- include
- included iocs
- indicator
- info
- informacje
- informative
- insight tag
- intel
- internal
- invalid pointer
- iocs
- iOS
- ip address
- issuer certum
- iwin
- jelenia gra
- jeli masz
- jquery
- june
- keepalive
- key usage
- khtml
- learn
- length
- levelblue
- levelblue open
- lf triid
- libs
- link
- Linux
- llc address
- local
- location united
- lookup
- lowfi
- Lumma
- Mac
- magia dokument
- magic html
- main
- malware
- Malware
- manually add
- media center
- medium
- memcommit
- memory
- memory oc0002
- memreserve
- meta
- meta http
- Microsoft
- Ministry of Advanced Education
- Ministry of Health
- Ministry of Tech & Innovation
- Mirai
- miss x
- mitre att
- Mobileye
- monstroid2
- moved
- mozilla
- msie
- ms visual
- ms windows
- mtb apr
- mtb yara
- mutexes nothing
- name servers
- name tactics
- net3128001
- net3168001
- netherlands
- network name
- network related
- next
- next associated
- nie po
- nie wczeniej
- no expiration
- none google
- none indicator
- none related
- nothing
- nsisdl
- NSO
- NSO Group
- number
- ob0001
- ob0007 impact
- ob0012 file
- oc0006
- oc0008
- odcisk palca
- oid2
- oidrop
- oiprop
- omicrosoft c
- open ports
- open threat
- org domains
- otx telemetry
- ouno sni
- overlay
- Paragon
- passive dns
- path
- path max
- pattern match
- pe32
- pe exe
- Pegasus
- People
- persistence
- Phishing
- please
- please sub
- pm size
- port
- possible
- post http
- post https
- pragma
- present apr
- present dec
- present jul
- present jun
- present may
- present nov
- present sep
- private name
- process
- process32nextw
- process oc0003
- proxy
- public key
- pulse
- pulse pulses
- pulses
- pulses none
- pulse submit
- push
- query
- ransom
- ransomware
- Ransomware
- rats
- read
- read c
- reads
- record value
- referral url
- referrerpolicy
- related nids
- related pulses
- related tags
- request
- resolved ips
- resource
- response
- response ip
- review data
- review io
- review los
- ri falsek
- rlength
- road city
- roboto
- Rogers
- safe browsing
- Samsung
- savbwcd
- scans record
- script domains
- script tags
- script urls
- sc tenn
- search
- sea x
- sec ch
- Security
- se extraction
- serial number
- server
- server ca
- server response
- service
- se source
- set cookie
- sha1
- sha1 sha256
- sha256
- show
- showing
- show technique
- signer
- signing ca
- simda
- Skynet
- slcc2
- solutions
- Sony
- span
- spawns
- Spyware
- ssdeep
- stamping
- status
- stealer
- stop data
- stream
- strings
- stwa lredmond
- submission
- submitted
- subtypeform
- sugges
- suggestealous u
- suspicious
- sweden
- symantec time
- system oc0001
- t1055
- t1114
- ta0004 defense
- ta0009 command
- tag manager
- tags
- tags twitter
- telewizja dami
- Telus
- tenkau
- texurag
- threat exchange
- thumbprint
- thumbprint md5
- tima
- time stamping
- title
- title error
- tls handshake
- tlsv1
- trackers
- Treaty 6
- Treaty 7
- Treaty 8
- trojan
- Trojan
- Trojan Downloader
- trojandropper
- trust
- trusted network
- twitter running
- type
- typ pliku
- ua full
- UAlberta
- ua platform
- unicode
- unicode text
- unifiedlayeras1
- unique
- united
- United Nurses of Alberta
- University of Calgary
- Unix
- unknown
- unknown ns
- unknown soa
- upatre
- update secure
- url add
- url data
- url hostname
- url https
- url or
- urls
- urls show
- url uk
- usage ff
- usa o
- us creation
- u suggested
- utc gcfezl5ynvb
- utc google
- utc gtmkvjvztk
- utc linkedin
- utc na
- utf8
- utf8 text
- v2 document
- v3 numer
- v3 serial
- value
- vary
- vhash
- virtool
- virustotal api
- vis1
- we1 wano
- whasz
- whitelisted
- whois registrar
- whois server
- win32
- win32 exe
- win32qqpass apr
- win64
- window memory
- windows
- Windows
- windows nt
- Wix
- worm
- wow64
- write
- write c
- x amz
- x cache
- xcache error
- xmpg
- xobject
- yara detections
- z bardzo
- zdarzenia
- z dnia
- Zeroday
- zgodnie z
MITRE ATT&CK TTPs
- T1001 - Data Obfuscation
- T1003.004 - LSA Secrets
- T1003 - OS Credential Dumping
- T1005 - Data from Local System
- T1011 - Exfiltration Over Other Network Medium
- T1012 - Query Registry
- T1018 - Remote System Discovery
- T1019 - System Firmware
- T1021.001 - Remote Desktop Protocol
- T1021.006 - Windows Remote Management
- T1027 - Obfuscated Files or Information
- T1036 - Masquerading
- T1038 - DLL Search Order Hijacking
- T1045 - Software Packing
- T1047 - Windows Management Instrumentation
- T1048.003 - Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
- T1053 - Scheduled Task/Job
- T1055.001 - Dynamic-link Library Injection
- T1055.003 - Thread Execution Hijacking
- T1055 - Process Injection
- T1057 - Process Discovery
- T1059.001 - PowerShell
- T1059.004 - Unix Shell
- T1059.007 - JavaScript
- T1060 - Registry Run Keys / Startup Folder
- T1063 - Security Software Discovery
- T1068 - Exploitation for Privilege Escalation
- T1069.001 - Local Groups
- T1071.004 - DNS
- T1071 - Application Layer Protocol
- T1076 - Remote Desktop Protocol
- T1078.004 - Cloud Accounts
- T1081 - Credentials in Files
- T1082 - System Information Discovery
- T1088 - Bypass User Account Control
- T1090 - Proxy
- T1094 - Custom Command and Control Protocol
- T1105 - Ingress Tool Transfer
- T1112 - Modify Registry
- T1114.002 - Remote Email Collection
- T1114 - Email Collection
- T1119 - Automated Collection
- T1129 - Shared Modules
- T1143 - Hidden Window
- T1184 - SSH Hijacking
- T1185 - Man in the Browser
- T1192 - Spearphishing Link
- T1202 - Indirect Command Execution
- T1203 - Exploitation for Client Execution
- T1204.001 - Malicious Link
- T1210 - Exploitation of Remote Services
- T1211 - Exploitation for Defense Evasion
- T1218.001 - Compiled HTML File
- T1404 - Exploit OS Vulnerability
- T1449 - Exploit SS7 to Redirect Phone Calls/SMS
- T1454 - Malicious SMS Message
- T1476 - Deliver Malicious App via Other Means
- T1480 - Execution Guardrails
- T1489 - Service Stop
- T1491 - Defacement
- T1497 - Virtualization/Sandbox Evasion
- T1530 - Data from Cloud Storage Object
- T1553.004 - Install Root Certificate
- T1553 - Subvert Trust Controls
- T1557 - Man-in-the-Middle
- T1560 - Archive Collected Data
- T1562.004 - Disable or Modify System Firewall
- T1562 - Impair Defenses
- T1563.002 - RDP Hijacking
- T1566.001 - Spearphishing Attachment
- T1566 - Phishing
- T1568.001 - Fast Flux DNS
- T1568 - Dynamic Resolution
- T1573 - Encrypted Channel
- T1583 - Acquire Infrastructure
- T1590.002 - DNS
- T1590 - Gather Victim Network Information
- T1596.001 - DNS/Passive DNS
- T1596.004 - CDNs
Passive DNS
- ecmo.ru
Attack Log References
- anonymous-proxy-ip-list-2025-06-30
- anonymous-proxy-ip-list-2025-07-02
- anonymous-proxy-ip-list-2025-07-18
- anonymous-proxy-ip-list-2025-06-23
- anonymous-proxy-ip-list-2025-06-26
- anonymous-proxy-ip-list-2025-06-27
- anonymous-proxy-ip-list-2025-07-13
- anonymous-proxy-ip-list-2025-07-11
- anonymous-proxy-ip-list-2025-07-15
- anonymous-proxy-ip-list-2025-07-30
- anonymous-proxy-ip-list-2025-07-01
- anonymous-proxy-ip-list-2025-07-06
- anonymous-proxy-ip-list-2025-07-24
- anonymous-proxy-ip-list-2025-07-07
- anonymous-proxy-ip-list-2025-07-14
- anonymous-proxy-ip-list-2025-07-23
- anonymous-proxy-ip-list-2025-06-22
- anonymous-proxy-ip-list-2025-06-28
- anonymous-proxy-ip-list-2025-06-29
- anonymous-proxy-ip-list-2025-07-05
- anonymous-proxy-ip-list-2025-06-24
- anonymous-proxy-ip-list-2025-07-27
- anonymous-proxy-ip-list-2025-07-12
- anonymous-proxy-ip-list-2025-07-17
- anonymous-proxy-ip-list-2025-07-22
- anonymous-proxy-ip-list-2025-07-28
- anonymous-proxy-ip-list-2025-07-31
- anonymous-proxy-ip-list-2025-08-01
- anonymous-proxy-ip-list-2025-08-02
- anonymous-proxy-ip-list-2025-07-09
- anonymous-proxy-ip-list-2025-07-19
- anonymous-proxy-ip-list-2025-07-04
- anonymous-proxy-ip-list-2025-07-08
- anonymous-proxy-ip-list-2025-07-10
- anonymous-proxy-ip-list-2025-07-29
- anonymous-proxy-ip-list-2025-07-03
- anonymous-proxy-ip-list-2025-07-25
- anonymous-proxy-ip-list-2025-07-16
- anonymous-proxy-ip-list-2025-07-20
- anonymous-proxy-ip-list-2025-07-26
- anonymous-proxy-ip-list-2025-06-25
- anonymous-proxy-ip-list-2025-07-21