104.47.5.36 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 104.47.5.36 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

🟠 Elevated — 60/100

Geographic Location

Host and Network Information

  • View other sources: Spamhaus VirusTotal Shodan AbuseIPDB
  • Country: Finland
  • Network: AS8075 microsoft corporation
  • Noticed: 9 times
  • Countries Attacked: Canada, United States of America
  • Tor Node: No
  • Associated Malware Samples: 10

Tags

  • aaaa
  • abuse contact
  • accept
  • a checkin
  • address
  • admin
  • a domains
  • agent
  • aig
  • akamaias
  • alexa top
  • algorithm
  • alibaba cloud
  • all octoseek
  • all search
  • amazon 02
  • amazon02
  • amazonaes
  • analyze
  • android
  • anomalous file
  • appdata
  • apple
  • apple ios
  • apple phone
  • apple private
  • april
  • argon data
  • artemis
  • artro
  • as14061
  • as16625 akamai
  • as20940
  • as25577 ide
  • as2914 ntt
  • as35994 akamai
  • as4134 chinanet
  • as63949 linode
  • as8068
  • as8075
  • as9009 m247
  • ascii text
  • asnone united
  • assaulter
  • att
  • attack
  • august
  • authority
  • autoit
  • autoit windows
  • automation tool
  • autorun
  • available from
  • awful
  • azorult
  • backdoor
  • bangladesh
  • bank
  • banker
  • beijing
  • binary
  • blacklist
  • body
  • body doctype
  • body length
  • brian sabey
  • capture
  • cascade
  • cayman
  • cdata
  • cellbrite
  • cellebrite
  • cellebrite ufed
  • certificate
  • china telecom
  • china unknown
  • cisco umbrella
  • civicaIg
  • ck id
  • ck matrix
  • class
  • cleaner
  • click
  • closewait tcp
  • cloudflarenet
  • cname
  • code
  • communicating
  • communication
  • computing
  • comspec
  • conduit
  • contact
  • contacted
  • contacted ip
  • contentencoding
  • copy
  • country
  • crack
  • create c
  • create new
  • creation date
  • critical
  • crypto
  • csc corporate
  • cus cnr3
  • cybercrime
  • cyber stalking
  • darpa
  • data
  • data collection
  • date
  • december
  • delete c
  • detection list
  • detections file
  • detections type
  • digitaloceanasn
  • discovery
  • dnssec
  • domain
  • domain name
  • domain related
  • domain robot
  • domains
  • domainsite
  • download
  • dropbox
  • dropped
  • dtrack
  • dynadot
  • dynadot inc
  • dynadot llc
  • dynamicloader
  • email
  • emails
  • encrypt
  • entries
  • error
  • established
  • established tcp
  • et tor
  • et trojan
  • execution
  • exodus
  • expiration date
  • expiressun
  • expiro
  • facebook
  • factory
  • falcon sandbox
  • feeds ioc
  • file
  • filehashmd5
  • filehashsha1
  • filehashsha256
  • files
  • files location
  • final url
  • findwindowa
  • first
  • fjlsedauv
  • forbidden
  • form
  • for privacy
  • full name
  • fusioncore
  • gandi sas
  • gecko
  • general
  • generator
  • get autoit
  • getprocaddress
  • gmo internet
  • gmt connection
  • gmt content
  • gmt contenttype
  • godaddy online
  • goldfinder
  • google
  • google llc
  • gootloader
  • go.sabey
  • graph community
  • group
  • hacktool
  • hashes c2ae
  • headers
  • headers nel
  • header target
  • heur
  • hidden privacy
  • high
  • high process
  • historical
  • historical ssl
  • hostile
  • hostname
  • hostnames
  • html
  • html info
  • http
  • http request
  • http response
  • hughesnet
  • hybrid
  • iana id
  • identifier
  • identity theft
  • iframe
  • incapsula
  • indicator
  • infected
  • info
  • info compiler
  • injection t1055
  • installer
  • installpack
  • intel
  • internal
  • internet se
  • iocs
  • ioc search
  • ionos se
  • ios
  • ip address
  • ip detections
  • ipv4
  • issuer
  • javascript
  • jekyll
  • jfif
  • jpeg image
  • june
  • kb body
  • key algorithm
  • key identifier
  • key info
  • keylogger
  • khtml
  • kimsuky
  • known tor
  • latest
  • less see
  • limited
  • local
  • localappdata
  • location canada
  • machine intel
  • mail spammer
  • malicious
  • malicious site
  • maltiverse
  • malvertizing
  • malware
  • malware beacon
  • malware site
  • march
  • media center
  • media player
  • medium
  • meta
  • meta tags
  • metro
  • million
  • mirai malware
  • mitre att
  • model
  • module load
  • monitoring
  • movies
  • msie
  • ms windows
  • mtb dec
  • mtb jan
  • mtb oct
  • music
  • name
  • namecheapnet
  • name servers
  • namesilo
  • name verdict
  • netherlands
  • netherlands asn
  • net technology
  • network
  • new ioc
  • next
  • no expiration
  • number
  • observed email
  • october
  • office open
  • olet
  • ollydbg
  • open
  • opencandy
  • organization
  • otx octoseek
  • page
  • parent referrer
  • parking crew
  • passive dns
  • password crack
  • paste
  • patch
  • path
  • pattern match
  • pcap
  • pdf cellebrite
  • pdf community
  • pdf report
  • pe32
  • pegasus
  • persistence
  • phishing
  • phishing site
  • pictures
  • point
  • porn
  • pornhub
  • possible
  • postal code
  • prefetch8
  • presenoker
  • privacy admin
  • privacy tech
  • privilege https
  • process32nextw
  • products
  • prynt
  • prynt stealer
  • psiusa
  • pt3rc1
  • pt3uc1
  • pty ltd
  • public folder
  • pulse pulses
  • pulse submit
  • pulse use
  • qakbot
  • quasar
  • query
  • quoth
  • raven
  • rdds service
  • read c
  • record
  • record value
  • redacted for
  • redline stealer
  • referrer
  • regbinary
  • regdword
  • registrant
  • registrar
  • registrar abuse
  • registrarsafe
  • registrar url
  • registrar whois
  • registry domain
  • regsetvalueexa
  • related nids
  • remote
  • remote attack
  • resolutions
  • responder
  • reverse dns
  • riskware
  • root ca
  • runescape
  • rwi dtools
  • sabey
  • safe site
  • sameorigin
  • samples
  • sa victim
  • scammer
  • scan endpoints
  • screenshot
  • script
  • script urls
  • search
  • searchmeup
  • sections
  • september
  • server
  • servers
  • service
  • serving ip
  • setup
  • sha256
  • shell code
  • show
  • showing
  • show technique
  • siblings
  • sibot
  • simda
  • sinkhole cookie
  • site
  • skynet
  • slcc2
  • social engineering
  • softcnapp
  • spammer
  • spying
  • spyware
  • ssl certificate
  • startpage
  • stateprovince
  • status
  • status code
  • strings
  • subdomains
  • subject key
  • subject public
  • submitters
  • suddenlink tv
  • summary iocs
  • survivor
  • susp
  • suspicious
  • system46606
  • t1055
  • t1129
  • targets sa
  • target tsara brashears
  • team
  • teams api
  • tech contact
  • temp
  • template
  • text
  • threat
  • threat analyzer
  • threat roundup
  • tiggre
  • timewait tcp
  • title
  • tjprojmain
  • tofsee
  • toshiba
  • trackers amazon
  • tracking
  • trident
  • trojanspy
  • tsara brashears
  • tucows
  • tulach
  • twitter
  • tylerknott
  • type
  • type name
  • ufed4pc
  • ufed iphone
  • ufed release
  • unclejohn
  • unified layer
  • unique
  • united
  • united kingdom
  • unknown
  • unlocker
  • unsafe
  • url analysis
  • url http
  • url https
  • urls
  • urls http
  • urls https
  • urls latest
  • usage
  • us autonomous
  • useragent
  • utc entry
  • utc submissions
  • v3 serial
  • value snkz
  • vary
  • verified
  • videos
  • virtool
  • virustotal
  • vs2008
  • vs2008 sp1
  • vs2010
  • vt graph
  • wacatac
  • watch
  • whitelisted
  • whois
  • whois record
  • whois service
  • whois whois
  • win32
  • win32 dll
  • win32 exe
  • win64
  • windows nt
  • worm
  • wow64
  • write
  • write c
  • writeconsolea
  • x509v3 extended
  • x509v3 key
  • x8bxe5
  • xml document
  • xml spreadsheet
  • xpire.info
  • xrat
  • xtrat
  • yara detections
  • yara rule
  • zenbox
  • zeppelin

MITRE ATT&CK TTPs

  • T1027 - Obfuscated Files or Information
  • T1031 - Modify Existing Service
  • T1036 - Masquerading
  • T1040 - Network Sniffing
  • T1045 - Software Packing
  • T1053 - Scheduled Task/Job
  • T1055 - Process Injection
  • T1056.001 - Keylogging
  • T1057 - Process Discovery
  • T1059.007 - JavaScript
  • T1059 - Command and Scripting Interpreter
  • T1060 - Registry Run Keys / Startup Folder
  • T1063 - Security Software Discovery
  • T1068 - Exploitation for Privilege Escalation
  • T1071.001 - Web Protocols
  • T1071.003 - Mail Protocols
  • T1071.004 - DNS
  • T1071 - Application Layer Protocol
  • T1082 - System Information Discovery
  • T1083 - File and Directory Discovery
  • T1100 - Web Shell
  • T1105 - Ingress Tool Transfer
  • T1106 - Native API
  • T1112 - Modify Registry
  • T1114 - Email Collection
  • T1119 - Automated Collection
  • T1122 - Component Object Model Hijacking
  • T1129 - Shared Modules
  • T1140 - Deobfuscate/Decode Files or Information
  • T1184 - SSH Hijacking
  • T1210 - Exploitation of Remote Services
  • T1415 - URL Scheme Hijacking
  • T1416 - URI Hijacking
  • T1460 - Biometric Spoofing
  • T1546.015 - Component Object Model Hijacking
  • T1546 - Event Triggered Execution
  • T1560 - Archive Collected Data
  • T1566 - Phishing
  • T1583.005 - Botnet
  • T1588.004 - Digital Certificates
  • T1588 - Obtain Capabilities

Passive DNS

  • tvtc.edu.sa

Attack Log References

Whois Information

NetRange: 104.40.0.0 - 104.47.255.255 CIDR: 104.40.0.0/13 NetName: MSFT NetHandle: NET-104-40-0-0-1 Parent: NET104 (NET-104-0-0-0-0) NetType: Direct Allocation OriginAS: Organization: Microsoft Corporation (MSFT) RegDate: 2014-05-07 Updated: 2021-12-14 Ref: https://rdap.arin.net/registry/ip/104.40.0.0 OrgName: Microsoft Corporation OrgId: MSFT Address: One Microsoft Way City: Redmond StateProv: WA PostalCode: 98052 Country: US RegDate: 1998-07-10 Updated: 2023-11-17 Comment: To report suspected security issues specific to traffic emanating from Microsoft online services, including the distribution of malicious content or other illicit or illegal material through a Microsoft online service, please submit reports to: Comment: * https://cert.microsoft.com. Comment: Comment: For SPAM and other abuse issues, such as Microsoft Accounts, please contact: Comment: * abuse@microsoft.com. Comment: Comment: To report security vulnerabilities in Microsoft products and services, please contact: Comment: * secure@microsoft.com. Comment: Comment: For legal and law enforcement-related requests, please contact: Comment: * msndcc@microsoft.com Comment: Comment: For routing, peering or DNS issues, please Comment: contact: Comment: * IOC@microsoft.com Ref: https://rdap.arin.net/registry/entity/MSFT OrgRoutingHandle: CHATU3-ARIN OrgRoutingName: Chaturmohta, Somesh OrgRoutingPhone: +1-425-882-8080 OrgRoutingEmail: someshch@microsoft.com OrgRoutingRef: https://rdap.arin.net/registry/entity/CHATU3-ARIN OrgTechHandle: MRPD-ARIN OrgTechName: Microsoft Routing, Peering, and DNS OrgTechPhone: +1-425-882-8080 OrgTechEmail: IOC@microsoft.com OrgTechRef: https://rdap.arin.net/registry/entity/MRPD-ARIN OrgAbuseHandle: MAC74-ARIN OrgAbuseName: Microsoft Abuse Contact OrgAbusePhone: +1-425-882-8080 OrgAbuseEmail: abuse@microsoft.com OrgAbuseRef: https://rdap.arin.net/registry/entity/MAC74-ARIN OrgTechHandle: SINGH683-ARIN OrgTechName: Singh, Prachi OrgTechPhone: +1-425-707-5601 OrgTechEmail: pracsin@microsoft.com OrgTechRef: https://rdap.arin.net/registry/entity/SINGH683-ARIN OrgTechHandle: BEDAR6-ARIN OrgTechName: Bedard, Dawn OrgTechPhone: +1-425-538-6637 OrgTechEmail: dabedard@microsoft.com OrgTechRef: https://rdap.arin.net/registry/entity/BEDAR6-ARIN OrgTechHandle: IPHOS5-ARIN OrgTechName: IPHostmaster, IPHostmaster OrgTechPhone: +1-425-538-6637 OrgTechEmail: iphostmaster@microsoft.com OrgTechRef: https://rdap.arin.net/registry/entity/IPHOS5-ARIN