104.21.95.21 Threat Intelligence and Host Information
Jan 11, 2024
ipinfopage
General
IP Address
104.21.95.21
Location
Unknown
Network
AS13335
Threat Score
49/100
Attack Intelligence
MITRE ATT&CK Techniques
T1005 - Data from Local System, T1016 - System Network Configuration Discovery, T1020 - Automated Exfiltration, T1021 - Remote Services, T1025 - Data from Removable Media, T1027 - Obfuscated Files or Information, T1033 - System Owner/User Discovery, T1036 - Masquerading, T1039 - Data from Network Shared Drive, T1041 - Exfiltration Over C2 Channel, T1047 - Windows Management Instrumentation, T1053 - Scheduled Task/Job, T1057 - Process Discovery, T1059 - Command and Scripting Interpreter, T1070 - Indicator Removal on Host, T1071 - Application Layer Protocol, T1080 - Taint Shared Content, T1082 - System Information Discovery, T1083 - File and Directory Discovery, T1102 - Web Service, T1105 - Ingress Tool Transfer, T1106 - Native API, T1112 - Modify Registry, T1113 - Screen Capture, T1119 - Automated Collection, T1120 - Peripheral Device Discovery, T1137 - Office Application Startup, T1140 - Deobfuscate/Decode Files or Information, T1204 - User Execution, T1218 - Signed Binary Proxy Execution, T1221 - Template Injection, T1485 - Data Destruction, T1491 - Defacement, T1498 - Network Denial of Service, T1534 - Internal Spearphishing, T1547 - Boot or Logon Autostart Execution, T1559 - Inter-Process Communication, T1562 - Impair Defenses, T1564 - Hide Artifacts, T1566 - Phishing, T1568 - Dynamic Resolution, T1583 - Acquire Infrastructure, T1608 - Stage Capabilities
Open Ports Detected
2052
Geographic Location
Country
Unknown
City
Unknown
Region
Unknown
Coordinates
0.0000, 0.0000
Geographic coordinates not available for this IP.
Network Information
ASN
AS13335
Organization
CLOUDFLARENET
Network
AS13335 CLOUDFLARENET
WHOIS Information
NetRange
104.16.0.0 - 104.31.255.255
CIDR
104.16.0.0/12
NetName
CLOUDFLARENET
NetHandle
NET-104-16-0-0-1
Parent
NET104 (NET-104-0-0-0-0)
NetType
Direct Allocation
OriginAS
AS13335
Organization
Cloudflare, Inc. (CLOUD14)
RegDate
2010-07-09
Updated
2021-07-01
Comment
All Cloudflare abuse reporting can be done via https://www.cloudflare.com/abuse
Ref
https://rdap.arin.net/registry/entity/CLOUD14
OrgName
Cloudflare, Inc.
OrgId
CLOUD14
Address
101 Townsend Street
City
San Francisco
StateProv
CA
PostalCode
94107
Country
US
OrgTechHandle
ADMIN2521-ARIN
OrgTechName
Admin
OrgTechPhone
+1-650-319-8930
OrgTechEmail
rir@cloudflare.com
OrgTechRef
https://rdap.arin.net/registry/entity/ADMIN2521-ARIN
- Country:
- Network: AS13335 cloudflare
- Noticed: 1 times
- Protcols Attacked: SSH
- Countries Attacked: China, Finland, Georgia, Germany, Japan, Russian Federation, United States of America
- Passive DNS Results: covinainsulationservice.us missionaryparenting.com lesvareper.tk xsoldiers.tk teddy-passport.online wor89.amir1982sardasht.workers.dev 6n5bdf.com puuhome.cn cf.idnsportal.eu.org gilsanderbreda.online stefospito.com pglike641.com bwww2.com theoakmontdentist.com face.rootfloor.za.com agenda.rootfloor.za.com 183614.xyz plainfieldgaragedoorrepair.us searahdigital.com aliaslan.az loginams88.site acaunti-dcru.com chimacumdryerventcleaning.us recrutingmaster.com jeelywu.com betgarli.com iloka88.pro ignizo.cfd fuzetube.online espressodolceca.com koreantv64.store detol.nwdna-09wt.live btc-remitano.com 2024-credit-card-approva.today bigbet58.com foxmindz.com bklynheights.info sflcorporateheadshots.com ct3.daughiewtyberneice.workers.dev takei-deal.site psoghook.top terrasense.in leahbchan.icu toysmore24.shop vegasjogo88.com s838kuy.com careys.shop acatod.biz tierracrystals.com tsxinlan.com evandersushi.com neckuse.com fitnes-free.cfd onlineschoolsforbusinessmanagement650686.life onlinetraderu.com vv.link.to hxc362.xyz lestempesgrises.com at52ds6uxvty.xyz auto-lux.pl kudsen.link bb9yv7dlzl.com avtomasteraz.com wqurhm.com 592996.xyz korsetcourbe.com tracktai.online 88008pt.com zippercosy.top pricepointtreasures.cfd cpatexs.com myhomelub.com mysamiverse.com zg05xuaneyzha0.top tohealthassured.com relivedp999.com hhgame365.com www.gamepgresmi.life srfwvlv.com zeroglobal.pics finuars247.click haughtierdisembowelled.click lampuslot.xyz trophywin.net birchwoodmart.com gemoygacor.com mugo.link.to enterversatile.top anybesk-get.online kafe777ku.com lygcgozg.com member.equinoxmarkets.com vpn-free.download exipurepurchase.shop andmilesbeforeigotosleep.com.tw slmcdnserieb66.shop mmajp3yis.monster cheapflightsfast.com dbs.ibaankiing-diiggital-onliine-interrnet-logiin.com dubaipropertypage.com domainapanih.com bankid-secure.com arfeenawan.site turkbtilp.click link.to xirte.com derkesparkplugs.com invchatnr.site fivskm.com timonkriek.online oomfkq.com x88a893.xyz duatotojp.com play9inspace.space award-get.com danieldegirolami.online dealsinfosite.online latestwoman.com whereintozas.buzz uujijeu.shop gladjourney.com haoxianggow84.com blanshop.com haoxianggw76.com cheapestcarinsurancequotes-b-215.today sunderland.work gamepgresmi.life 20bet-denmark.com www.ambitioussinglemom.com ambitioussinglemom.com hizlisokaklar.net two.rootfloor.za.com 3296h8.com nabidoll.com yitacadsi2915.com xgppxpg015.top ufabet168info.net ttbot.pro 50t8y8.cyou minhaprofissaoagora.online fltzhkjffbuekfca.com password.medi-cloud.net dev.villae.studio tensegiri.pw changbosh.cn iocdjkkv.tk www.playchan.click www.nhdmxm.shop jewellery-salesstore.com 9a46wsq7m.com avtakipicra.com imager.habboworld.be r2jiabeifen.sviplk.cn 1358vip.cc strikehacking.com hello-world-wild-voice-5678.amir1982sardasht.workers.dev freebounties.xyz smart4ever-b26.com resolutenaturalresources.com riduzione-del-debito.today keijzlvy.sbs fan.amir1982sardasht.workers.dev charteroakfcu.info proud-shadow-a14e.gihasem953756.workers.dev wings8.me mhegl.xyz pinlnktr.click guavabejdk.site violinflare.top www.loppstarr.com loppstarr.com microfiorealista.online galxeliinea.buzz br.amir1982sardasht.workers.dev birsvu.com dongyangzhaopin.com www.redecanais.football peonimareastipe.cf nursemates.co.kr magoreal.casa www.blankworldmaps.com houston48hfp.com ijmvbzjwgvpiqa.com in-anxietytreatmentinmexico.today redecanais.football promotivepromosyon.com soofunpottsville.com www.kds27.haf45.my.id kds27.haf45.my.id www.kds22.haf45.my.id kds22.haf45.my.id www.kds19.haf45.my.id kds19.haf45.my.id kds18.haf45.my.id www.kds18.haf45.my.id dwwuf.top kds11.haf45.my.id www.kds11.haf45.my.id www.kds9.haf45.my.id kds9.haf45.my.id www.kds4.haf45.my.id kds4.haf45.my.id haf45.my.id dinovitae.com www.etoile-beauty.de fairburyfirst.com sumanamitra.com eminateslsiamic.com snackverse.com gamers-company-auth.com w3lkp.me taloley.vycewao.live embmoc.com vless.amir1982sardasht.workers.dev www.sciphipod.org kinderzimmer.store angelxdh777.buzz caregiver-work-au-3.today yyav691.top margaritashanela.shop bgfequitation.uk icy-rain-6ef8.gihasem953756.workers.dev www.coinbaysfx.pro coinbaysfx.pro playchan.click mkt-chat.com burritodays.com nhdmxm.shop www.youlala01.cc youlala01.cc m.youlala01.cc f5d0.com tropheedesvolcans.com gf.amir1982sardasht.workers.dev kwee.co bitcoin.org.vc amberenmm.biogix-cloudflare.workers.dev couetteimprime220x240.life ancient-recipe-6ab4.gihasem953756.workers.dev steep-darkness-dd24.gihasem953756.workers.dev deemoverride.top leshosubsu.tk sexindrag.ru 6a2d.es cr.amir1982sardasht.workers.dev bbin909.com 711ld.com m.amir1982sardasht.workers.dev matthayomnayao.com www.omni-revsolutions.com ketofizik.fun omni-revsolutions.com yo.amir1982sardasht.workers.dev kingdiamond88.net rpg.amir1982sardasht.workers.dev bl.amir1982sardasht.workers.dev 2o6z.us www.sofyee.shop sofyee.shop vneshurburo.ru toopmoosttrrusst.site fire.amir1982sardasht.workers.dev cristhiandeep.com vacancies-for-caregivers-au.life lorrie-julia.com lingering-forest-f39b.amir1982sardasht.workers.dev blogeerstore.store wandering-forest-56a6.amir1982sardasht.workers.dev amir-12dfgt.amir1982sardasht.workers.dev wandering-truth-d1ab.amir1982sardasht.workers.dev saohutv111.com lucky-wave-662a.rpxfmvqyhg4911.workers.dev integratedlabtesting.net onlinecasinoswithrealmoney.icu thep322.xyz jolly-paper-2b41.amir1982sardasht.workers.dev super-smoke-2aa8.amir1982sardasht.workers.dev getafreenodecom.amir1982sardasht.workers.dev polished-sun-615c.amir1982sardasht.workers.dev shiny-river-2d1b.amir1982sardasht.workers.dev amycooper.top free2.amir1982sardasht.workers.dev goltoken.exchange theeve.site businessdiva.de joshua-higgins.co.uk meinbosenheim.de 8g82m.xyz freenod.amir1982sardasht.workers.dev quantumpro.autos wil.amir1982sardasht.workers.dev idura.ai wandering-tree-2f67.amir1982sardasht.workers.dev berkleycapital.co.uk gclubroyal888.info wi.amir1982sardasht.workers.dev fronualretliftcourtbom.tk site.amir1982sardasht.workers.dev thecommercialpost.com aviator-coverrugwjdy.site ivermectinxltab.com round-recipe-dd93.amir1982sardasht.workers.dev www.snowhookadventures.com snowhookadventures.com go.thedailyupdate.co yenigiris17255.site solitude.solutions fycunoy.vycewao.live bamicyi.vycewao.live dankentee.com frf666.com markets-payumennts.store hello.aef.workers.dev ivnofg.xyz lively-dust-b5f6.amir1982sardasht.workers.dev new2.amir1982sardasht.workers.dev amepromocoes2023.com kookhi.com businessbankinguk.com safecare.tw www.safecare.tw tg88.co cafehans.net keymerkez.com mwax.ru young-cherry-ff0f.amir1982sardasht.workers.dev coin-speed.com plumbing-near-me.net new.amir1982sardasht.workers.dev txt.amir1982sardasht.workers.dev club.amir1982sardasht.workers.dev lne5n84094q.shop arbitrumcrypt.live www.803areacode.com 803areacode.com meblestylowe24.eu drop.amir1982sardasht.workers.dev www.infertility-net.com v5928.com www.furnitureexpertsco.com furnitureexpertsco.com diorftnaypk.site tsinterresults2019.xyz 24hourprinting.net for.amir1982sardasht.workers.dev 4.amir1982sardasht.workers.dev learningways.ai dibdib.homes www.kaltesterne.ml vvv.kaltesterne.ml empeor.eu.org amarentalmobiljogja.com ovacpredipfi.gq 3.amir1982sardasht.workers.dev www.maximatecnologia.tech maximatecnologia.tech hypergloss.com btg88.org originaltonyspizzarestaurant.com yogahealth.club www.yogahealth.club two.amir1982sardasht.workers.dev cizgvi.xyz so141.com vray.amir1982sardasht.workers.dev www.ivermectinqtabs.com ivermectinqtabs.com ningpernu.tk snattildicon.cf fjkqk.com nameless-darkness-2d80.amir1982sardasht.workers.dev free.amir1982sardasht.workers.dev urmoms.gay hbracmgosq.com noisy-mud-10f7.amir1982sardasht.workers.dev advicfinanciq.com nepalhomesearch.com defi-initiative.club freenod1.amir1982sardasht.workers.dev j2hak4pa.top voterregistration.txdemocrats.org fortunat.uw.to shiny-wildflower-a550.amir1982sardasht.workers.dev amir.amir1982sardasht.workers.dev android.mmdsnkii.me ws.meclee.com cembayraktutan.com broad-thunder-0a6c.kdsd.workers.dev rapid-frost-dcaf.kdsd.workers.dev weathered-thunder-5ec7.kdsd.workers.dev suzhq.top sl2.kaee83cs.ga nameless-limit-c210.kdsd.workers.dev anitsa.amir1982sardasht.workers.dev beekleyglobal.com divine-boat-7713.amir1982sardasht.workers.dev frosty-base-3ef3.amir1982sardasht.workers.dev round-term-d642.amir1982sardasht.workers.dev patient-darkness-2293.amir1982sardasht.workers.dev altairallohaa.shop recipes-2u.com dyndns.rizsanyi.workers.dev small-math-a49c.amir1982sardasht.workers.dev chalelapti.com www.chalelapti.com zoo.club steep-sunset-f59e.amir1982sardasht.workers.dev situs-mposlot.org yellow-fog-25ed.amir1982sardasht.workers.dev ammjhgf.amir1982sardasht.workers.dev delicate-sound-511d.amir1982sardasht.workers.dev morning-pond-9353.amir1982sardasht.workers.dev combunitysurgical.com broninorcuvo.tk obzomo.tk karkon.marzi-gadfly.workers.dev shiny-credit-5649.amir1982sardasht.workers.dev solitary-dew-76e0.amir1982sardasht.workers.dev website.chayenu.dev cxabax.com fancy-morning-1aca.amir1982sardasht.workers.dev flat-thunder-9663.amir1982sardasht.workers.dev yeganehali999.yeganehali999.workers.dev amirvpnv2ray.amir1982sardasht.workers.dev freegatev2ray.amir1982sardasht.workers.dev round-hall-ba9c.amir1982sardasht.workers.dev sweet-star-3bae.amir1982sardasht.workers.dev hidden-lake-f741.amir1982sardasht.workers.dev alaahad.com cool-grass-09ea.amir1982sardasht.workers.dev blue-union-0dfw2.amir1982sardasht.workers.dev hidden-sea-6afb.amir1982sardasht.workers.dev delicghj.amir1982sardasht.workers.dev polar-capital.co chengziguanwang888.com admin.3scorporation.com anzumsfashion.com divine-night-299c.amir1982sardasht.workers.dev square-cloud-8fdd.amir1982sardasht.workers.dev white-wildflower-8dfe.amir1982sardasht.workers.dev sl1.kaee83cs.ga kaee83cs.ga broken-sun-7442.amir1982sardasht.workers.dev amirvopn.amir1982sardasht.workers.dev amirvpn.amir1982sardasht.workers.dev patient-hill-07c3.amir1982sardasht.workers.dev kitzmedia.co.uk ftp.xxxteenvideo.eu pop.xxxteenvideo.eu smtp.xxxteenvideo.eu www.xxxteenvideo.eu bijouxdupointdujour.fr naturalhealing-usa.com outatedconic.cf newfreenode.marzi-gadfly.workers.dev youla.ld44150.ru staging-api-algo-marketplace.nftdeals.io www.cryptohunterspro.com pawyqia.vycewao.live tawipoa.vycewao.live haqaciy.vycewao.live myzawie.vycewao.live vijamoy.vycewao.live asedmaadi.marzi-gadfly.workers.dev hylozoism.com freeslotswithbonus.icu yourcorazoninc.com lacasagratis.shop aroundboston.com vycewao.live start-trw.com aiclassifier.co jikojitugen.jp vipfoodcosmetic.com nestsubscribe.chayenu.dev tomandmonica.com polished-pond-738f.oychldpfrv.workers.dev askio.ml misinictu.ml floristselden.com ru-clickpay.online irenelmize.icu freemandevonwy.cyou inulerinic.ml ha.hugoetcloe.fr yuksalishbot.makhmudov-b.workers.dev healthytime.fr derilorus.cf recetasparabebes.net v2v2.ml cecsocialist.shop loginfastweplay.com prettybyouti.fi 404ae.com justanexample.xyz polask5.com www.cangjiaosp.buzz usdt-bot.org majbudarindia.com ngaycongdong.com
Disclaimer
This page contains threat intelligence information for the IPv4 address 104.21.95.21 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.