104.47.4.36 Threat Intelligence and Host Information
General
This page contains threat intelligence information for the IPv4 address 104.47.4.36 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.
Likely Malicious Host 🟠 60/100
Host and Network Information
-
Mitre ATT&CK IDs: T1027 - Obfuscated Files or Information, T1031 - Modify Existing Service, T1036 - Masquerading, T1040 - Network Sniffing, T1045 - Software Packing, T1053 - Scheduled Task/Job, T1055 - Process Injection, T1056.001 - Keylogging, T1057 - Process Discovery, T1059.007 - JavaScript, T1059 - Command and Scripting Interpreter, T1060 - Registry Run Keys / Startup Folder, T1063 - Security Software Discovery, T1068 - Exploitation for Privilege Escalation, T1071.003 - Mail Protocols, T1071 - Application Layer Protocol, T1082 - System Information Discovery, T1083 - File and Directory Discovery, T1100 - Web Shell, T1105 - Ingress Tool Transfer, T1106 - Native API, T1112 - Modify Registry, T1114 - Email Collection, T1119 - Automated Collection, T1122 - Component Object Model Hijacking, T1129 - Shared Modules, T1140 - Deobfuscate/Decode Files or Information, T1184 - SSH Hijacking, T1210 - Exploitation of Remote Services, T1415 - URL Scheme Hijacking, T1416 - URI Hijacking, T1460 - Biometric Spoofing, T1546.015 - Component Object Model Hijacking, T1546 - Event Triggered Execution, T1560 - Archive Collected Data, T1566 - Phishing, T1583.005 - Botnet, T1588.004 - Digital Certificates, T1588 - Obtain Capabilities
-
Tags: aaaa, abuse contact, accept, a checkin, address, admin, a domains, akamaias, algorithm, alibaba cloud, all octoseek, all search, amazon 02, amazon02, amazonaes, analyze, android, anomalous file, antivirus, appdata, apple, apple phone, apple private, april, argon data, artro, as14061, as16625 akamai, as20940, as25577 ide, as2914 ntt, as35994 akamai, as4134 chinanet, as63949 linode, as8068, as8075, as9009 m247, ascii text, asnone united, assaulter, attack, august, autoit, autoit windows, automation tool, autorun, available from, av scan, awful, backdoor, bangladesh, banker, beijing, binary, body, body doctype, body length, brian sabey, capture, cascade, cayman, cdata, cellbrite, cellebrite, cellebrite ufed, certificate, china telecom, china unknown, ck id, ck matrix, class, click, cloudflarenet, cname, cobalt strike, code, communicating, communication, computing, comspec, contact, contacted, contacted ip, contentencoding, copy, copy md5, copy sha1, copy sha256, country, create c, create new, creation date, crimson apple, critical, crypto, csc corporate, cus cnr3, cyber stalking, darpa, data, data collection, date, dead, december, delete c, detections file, detections type, digitaloceanasn, discovery, d mmmm, dnssec, domain, domain name, domain related, domain robot, domains, domainsite, dropbox, drops, dtrack, dynadot, dynadot inc, dynadot llc, dynamicloader, email, emails, encrypt, entries, error, et tor, et trojan, execution, exit, exodus, expiration date, expiro, facebook, factory, falcon sandbox, feeds ioc, file, filehashmd5, filehashsha1, filehashsha256, files, files location, final url, findwindowa, first, fjlsedauv, flag, forbidden, form, for privacy, full name, gandi sas, gecko, general, generator, get autoit, getprocaddress, gmo internet, gmt connection, gmt content, gmt contenttype, godaddy online, goldfinder, google, google llc, gootloader, go.sabey, graph community, group, hacktool, hashes c2ae, hashtablemutex, headers, headers nel, header target, hidden privacy, high, high process, historical, historical ssl, hostile, hostname, hostnames, html, http, http request, http response, hybrid, hybrid analysis, iana id, identifier, identity theft, incapsula, indicator, infected, info, info compiler, injection t1055, installer, intel, internal, internet se, iocs, ioc search, ionos se, ip address, ip detections, ipv4, issuer, javascript, jekyll, jfif, jfif standard, jpeg image, june, kb body, key algorithm, key identifier, key info, keylogger, khtml, kimsuky, known tor, latest, less see, limited, llll, local, localappdata, location canada, machine intel, malicious, maltiverse, malvertizing, malware, malware beacon, march, markmonitor, media center, media player, medium, metro, mirai malware, misc attack, mitre att, model, module load, msie, ms windows, mtb dec, mtb jan, mtb oct, music, mutex, name, namecheapnet, name server, name servers, namesilo, name verdict, netherlands, netherlands asn, net technology, network, new ioc, next, node traffic, no expiration, no relevant, number, observed email, october, office open, olet, ollydbg, open, openurl c, organization, otx octoseek, page, parent referrer, parking crew, passive dns, paste, patch, path, pattern match, pcap, pdf cellebrite, pdf community, pdf report, pe32, pegasus, persistence, phishing, pictures, png image, point, possible, postal code, prefetch2, prefetch8, privacy admin, privacy tech, privilege https, process32nextw, products, prynt, prynt stealer, psiusa, pty ltd, public folder, pulse pulses, pulse submit, pulse use, qakbot, quasar, query, quoth, raven, rdds service, read c, record, record value, redacted for, redline stealer, referrer, regbinary, regdword, registrant, registrar, registrar abuse, registrarsafe, registrar url, registrar whois, registry domain, regsetvalueexa, related nids, relayrouter, remote, remote attack, resolutions, responder, result, reverse dns, runtime process, rwi dtools, sabey, sameorigin, sample, samples, sa victim, scammer, scan endpoints, screenshot, script, script urls, search, searchmeup, sections, september, server, servers, service, serving ip, session details, setup, severity, sha1, sha256, shell code, show, showing, show technique, siblings, sibot, simda, sinkhole cookie, size, skynet, slcc2, social engineering, spammer, spying, ssl certificate, startpage, stateprovince, status, status code, strings, subdomains, subject key, subject public, submitters, summary iocs, suricata alerts, survivor, susp, suspicious, system46606, t1055, t1129, targets sa, teams api, tech contact, template, text, threat, threat analyzer, threat roundup, title, tjprojmain, tofsee, trident, trojanspy, tsara brashears, tucows, tulach, twitter, type, type data, type name, ufed4pc, ufed iphone, ufed release, unclejohn, unicode text, unified layer, unique, united, united kingdom, unknown, unlocker, url analysis, url http, url https, urls, urls http, urls https, urls latest, usage, us autonomous, useragent, utc entry, utc submissions, v3 serial, value snkz, vary, verified, videos, virtool, virustotal, vs2008, vs2008 sp1, vs2010, vt graph, whitelisted, whois, whois record, whois service, whois whois, win32, win32 dll, win32 exe, win64, windir, windows nt, worm, wow64, write, write c, writeconsolea, x509v3 extended, x509v3 key, x8bxe5, xml document, xml spreadsheet, xpire.info, yara detections, yara rule, yyyy, zenbox, zeppelin
-
View other sources: Spamhaus VirusTotal
- Country: Netherlands
- Network: AS8075 microsoft corporation
- Noticed: 28 times
- Protcols Attacked: SSH
- Countries Attacked: Canada, United States of America
Malware Detected on Host
Count: 13 48e86e34938d51adb58ccf1f2665ad5f552c5c81078aeba7941779564f1d0746 35e1fadafb027d15dff4b41344a6a7b07b4c1ab65fac7cfc43ef4243bfe6ad34 6953a51b9b5be7ef39beef0ad27454af782e6333159f48b0a07ed54a3530759c 54a2604b712b78287d3edf1752965272d93395977b712bb32df8e96e8fce3cee 52db4b95607e0654a0e0fbab15240eece9899810dd1b54ecdbe4ae239ecf542c 0256149201612989ce77d01688389d6a727872e69c826850011448119cf7cef3 8a5521ef20e86e7d1f5383da4ad0a4a5ebdb5d8274ec7f03685bff950d737c41 f0019a1d2a8f40d7a75551e9b71747de6414c51a1f8fb0d23db28af5d04d2fe6 c7911dd3402d28ceba9c5438d1950627f90d15d669a6e89254659cb8a678da09 520fea60613b21adf8b0562757b02f1f0fade1f87896809480bd00a335c7d98e
Map
Whois Information
- NetRange: 104.40.0.0 - 104.47.255.255
- CIDR: 104.40.0.0/13
- NetName: MSFT
- NetHandle: NET-104-40-0-0-1
- Parent: NET104 (NET-104-0-0-0-0)
- NetType: Direct Allocation
- OriginAS:
- Organization: Microsoft Corporation (MSFT)
- RegDate: 2014-05-07
- Updated: 2021-12-14
- Ref: https://rdap.arin.net/registry/ip/104.40.0.0
- OrgName: Microsoft Corporation
- OrgId: MSFT
- Address: One Microsoft Way
- City: Redmond
- StateProv: WA
- PostalCode: 98052
- Country: US
- RegDate: 1998-07-10
- Updated: 2023-11-17
- Comment: To report suspected security issues specific to traffic emanating from Microsoft online services, including the distribution of malicious content or other illicit or illegal material through a Microsoft online service, please submit reports to:
- Comment: * https://cert.microsoft.com.
- Comment:
- Comment: For SPAM and other abuse issues, such as Microsoft Accounts, please contact:
- Comment: * abuse@microsoft.com.
- Comment:
- Comment: To report security vulnerabilities in Microsoft products and services, please contact:
- Comment: * secure@microsoft.com.
- Comment:
- Comment: For legal and law enforcement-related requests, please contact:
- Comment: * msndcc@microsoft.com
- Comment:
- Comment: For routing, peering or DNS issues, please
- Comment: contact:
- Comment: * IOC@microsoft.com
- Ref: https://rdap.arin.net/registry/entity/MSFT
- OrgAbuseHandle: MAC74-ARIN
- OrgAbuseName: Microsoft Abuse Contact
- OrgAbusePhone: +1-425-882-8080
- OrgAbuseEmail: abuse@microsoft.com
- OrgAbuseRef: https://rdap.arin.net/registry/entity/MAC74-ARIN
- OrgTechHandle: BEDAR6-ARIN
- OrgTechName: Bedard, Dawn
- OrgTechPhone: +1-425-538-6637
- OrgTechEmail: dabedard@microsoft.com
- OrgTechRef: https://rdap.arin.net/registry/entity/BEDAR6-ARIN
- OrgRoutingHandle: CHATU3-ARIN
- OrgRoutingName: Chaturmohta, Somesh
- OrgRoutingPhone: +1-425-882-8080
- OrgRoutingEmail: someshch@microsoft.com
- OrgRoutingRef: https://rdap.arin.net/registry/entity/CHATU3-ARIN
- OrgTechHandle: MRPD-ARIN
- OrgTechName: Microsoft Routing, Peering, and DNS
- OrgTechPhone: +1-425-882-8080
- OrgTechEmail: IOC@microsoft.com
- OrgTechRef: https://rdap.arin.net/registry/entity/MRPD-ARIN
- OrgTechHandle: SINGH683-ARIN
- OrgTechName: Singh, Prachi
- OrgTechPhone: +1-425-707-5601
- OrgTechEmail: pracsin@microsoft.com
- OrgTechRef: https://rdap.arin.net/registry/entity/SINGH683-ARIN
- OrgTechHandle: IPHOS5-ARIN
- OrgTechName: IPHostmaster, IPHostmaster
- OrgTechPhone: +1-425-538-6637
- OrgTechEmail: iphostmaster@microsoft.com
- OrgTechRef: https://rdap.arin.net/registry/entity/IPHOS5-ARIN