104.47.55.110 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 104.47.55.110 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

🟠 Elevated — 60/100

Geographic Location

Host and Network Information

  • View other sources: Spamhaus VirusTotal Shodan AbuseIPDB
  • Country: United States
  • Network: AS8075 microsoft corporation
  • Noticed: 8 times
  • Countries Attacked: Canada, Netherlands, United States of America
  • Open Ports: 25
  • Tor Node: No
  • Associated Malware Samples: 3

Tags

  • aaaa
  • accept
  • a checkin
  • active
  • active threat
  • address
  • admin
  • a domains
  • agent
  • aig
  • akamai
  • akamaias
  • alexa top
  • algorithm
  • alibaba cloud
  • all octoseek
  • all search
  • amazon 02
  • amazonaes
  • android
  • anomalous file
  • a nxdomain
  • a poster
  • aposter
  • appdata
  • apple
  • apple attack
  • apple engineering
  • apple id
  • apple ios
  • applenoc
  • apple phone
  • apple private
  • april
  • argon data
  • artemis
  • artro
  • as14061
  • as16625
  • as16625 akamai
  • as20940
  • as24940 hetzner
  • as25577 ide
  • as2914 ntt
  • as35994 akamai
  • as58061 scalaxy
  • as63949 linode
  • as714
  • as8068
  • as9009 m247
  • ascii text
  • att
  • attack
  • august
  • authority
  • autoit
  • autoit windows
  • automation tool
  • autorun
  • awful
  • azorult
  • backdoor
  • bahamut
  • bangladesh
  • bank
  • banker
  • beijing
  • bell south
  • bellsouth
  • binary
  • blacklist
  • body
  • body length
  • brian
  • brian sabey
  • briansabey
  • browse scan
  • brute force passwords
  • bundled
  • ca
  • canvas
  • cascade
  • cayman
  • cdata
  • cellbrite
  • certificate
  • china
  • china telecom
  • cidr
  • cisco umbrella
  • civicaIg
  • ck id
  • ck matrix
  • class
  • cleaner
  • click
  • cloudflarenet
  • cmd
  • cname
  • cobalt strike
  • code
  • communicating
  • communication
  • computing
  • conduit
  • config
  • contact
  • contacted
  • contacted ip
  • contentencoding
  • contextualizing
  • copy
  • country
  • crack
  • create c
  • create new
  • creation date
  • critical
  • crypto
  • cus cnr3
  • cybercrime
  • cyber stalking
  • darpa
  • dashboard
  • data
  • data collection
  • date
  • delete c
  • detection list
  • detections file
  • detections type
  • digitaloceanasn
  • discovery
  • dns replication
  • dnssec
  • domain
  • domain entries
  • domain robot
  • domains
  • domainsite
  • download
  • dropbox
  • dropped
  • dtrack
  • dynadot
  • dynadot inc
  • dynamicloader
  • emails
  • encrypt
  • endpoints all
  • entries
  • error
  • et
  • et cins
  • et tor
  • et trojan
  • execution
  • expiration
  • expiration date
  • expiressun
  • expiro
  • facebook
  • falcon sandbox
  • false
  • fear
  • file
  • filehashmd5
  • filehashsha1
  • filehashsha256
  • files
  • final url
  • final url summary
  • findwindowa
  • first
  • fjlsedauv
  • forbidden
  • form
  • formbook
  • for privacy
  • full name
  • fusioncore
  • gandi sas
  • gecko
  • general
  • generator
  • germany
  • germany unknown
  • get autoit
  • gmt connection
  • gmt contenttype
  • godaddy online
  • goldfinder
  • gootloader
  • graph
  • graph community
  • group
  • hacktool
  • hallrender
  • hashes c2ae
  • hashes files
  • headers
  • headers nel
  • header target
  • heur
  • hidden privacy
  • high
  • high process
  • historical
  • historical ssl
  • hostile
  • hostname
  • hostnames
  • html
  • html info
  • http
  • http request
  • http response
  • https
  • hughesnet
  • hybrid
  • icefog
  • icloud
  • identifier
  • identity theft
  • iframe
  • indicator
  • infected
  • info
  • info compiler
  • injection t1055
  • install
  • installer
  • installpack
  • intel
  • internal
  • internet se
  • iocs
  • ioc search
  • iocs kb
  • ionos se
  • ios
  • ip address
  • ip detections
  • ipv4
  • ipv6
  • issuer
  • japan national police agency
  • javascript
  • jekyll
  • jfif
  • jpeg image
  • june
  • kb body
  • key algorithm
  • key identifier
  • key info
  • keylogger
  • khtml
  • known tor
  • latest
  • less see
  • limited
  • local
  • localappdata
  • location canada
  • machine intel
  • mail spammer
  • malicious
  • malicious host
  • malicious site
  • maltiverse
  • malvertizing
  • malware
  • malware beacon
  • malware site
  • march
  • masquerading
  • media center
  • media player
  • medium
  • meta
  • meta tags
  • metro
  • million
  • mirai malware
  • mitre
  • mitre att
  • mitre attk
  • module load
  • monitoring
  • movies
  • msie
  • ms windows
  • mtb dec
  • mtb jan
  • mtb oct
  • mtsub26293293
  • music
  • name
  • name servers
  • name verdict
  • national police agency japan
  • netherlands asn
  • net technology
  • network
  • new ioc
  • next
  • no expiration
  • nuance
  • number
  • nxdomain
  • october
  • octoseek
  • office open
  • olet
  • ollydbg
  • open
  • opencandy
  • organization
  • otx octoseek
  • parent referrer
  • parking crew
  • passive dns
  • password crack
  • paste
  • path
  • pattern match
  • pcap
  • pdf community
  • pdf report
  • pe32
  • pegasus
  • persistence
  • phishing
  • phishing site
  • pictures
  • point
  • porn
  • pornhub
  • possible
  • postal code
  • presenoker
  • privacy admin
  • privacy tech
  • process32nextw
  • products
  • prynt
  • prynt stealer
  • psiusa
  • pt3rc1
  • pt3uc1
  • pty ltd
  • public folder
  • pulse pulses
  • pulse submit
  • pulse use
  • qakbot
  • quasar
  • query
  • rdds service
  • read c
  • record
  • record type
  • record value
  • redacted for
  • redline stealer
  • referrer
  • regbinary
  • regdword
  • registrant
  • registrar
  • regsetvalueexa
  • reinsurance
  • relacion
  • related nids
  • relay
  • remote
  • remote attack
  • resolutions
  • reverse dns
  • riskware
  • root
  • root ca
  • runescape
  • rwi dtools
  • sabey
  • safe site
  • sameorigin
  • samples
  • sandbox
  • scalaxy
  • scammer
  • scan endpoints
  • screenshot
  • script
  • search
  • searchmeup
  • sections
  • september
  • server
  • servers
  • service
  • serving ip
  • sha256
  • shell code
  • show
  • showing
  • show technique
  • siblings
  • sibot
  • simda
  • simple
  • sinkhole cookie
  • site
  • skynet
  • slcc2
  • small
  • social engineering
  • softcnapp
  • spammer
  • span
  • speakez securus
  • spying
  • spyware
  • ssh on server
  • ssl certificate
  • ssl hostname
  • state
  • stateprovince
  • status
  • status code
  • status codes
  • stix
  • strings
  • subdomains
  • subid
  • subject key
  • subject public
  • submit
  • submit quasar
  • submitters
  • suddenlink tv
  • summary iocs
  • suspicious
  • system46606
  • t1055
  • t1129
  • tagging
  • target tsara brashears
  • team
  • teams api
  • tech contact
  • temp
  • template
  • text
  • threat
  • threat analyzer
  • threat roundup
  • tiggre
  • tofsee
  • toshiba
  • tracker
  • trackers amazon
  • tracking
  • trident
  • trojan
  • trojanspy
  • tsara brashears
  • ttl value
  • tucows
  • tulach
  • twitter
  • tylerknott
  • unclejohn
  • unified layer
  • unique
  • united
  • united kingdom
  • United states
  • unknown
  • unknown urls
  • unlocker
  • unsafe
  • url analysis
  • url http
  • url https
  • urls
  • urls http
  • urls https
  • urls latest
  • us autonomous
  • useragent
  • utc entry
  • utc submissions
  • v3 serial
  • value snkz
  • verdict
  • verified
  • videos
  • virtool
  • virustotal
  • vs2008
  • vs2008 sp1
  • vs2010
  • vt graph
  • wacatac
  • watch
  • whitelisted
  • whois
  • whois record
  • whois service
  • whois whois
  • win32
  • win32 exe
  • win64
  • windows nt
  • workaposter
  • worm
  • wow64
  • write
  • write c
  • writeconsolea
  • x509v3 key
  • x8bxe5
  • xml spreadsheet
  • xobo
  • xpire.info
  • xrat
  • xtrat
  • yara detections
  • yara rule
  • zenbox
  • zeppelin

MITRE ATT&CK TTPs

  • T1027 - Obfuscated Files or Information
  • T1031 - Modify Existing Service
  • T1040 - Network Sniffing
  • T1045 - Software Packing
  • T1053 - Scheduled Task/Job
  • T1055 - Process Injection
  • T1056.001 - Keylogging
  • T1057 - Process Discovery
  • T1059.007 - JavaScript
  • T1059 - Command and Scripting Interpreter
  • T1060 - Registry Run Keys / Startup Folder
  • T1063 - Security Software Discovery
  • T1071.001 - Web Protocols
  • T1071.004 - DNS
  • T1071 - Application Layer Protocol
  • T1082 - System Information Discovery
  • T1100 - Web Shell
  • T1105 - Ingress Tool Transfer
  • T1106 - Native API
  • T1112 - Modify Registry
  • T1114 - Email Collection
  • T1119 - Automated Collection
  • T1122 - Component Object Model Hijacking
  • T1129 - Shared Modules
  • T1140 - Deobfuscate/Decode Files or Information
  • T1156 - Malicious Shell Modification
  • T1184 - SSH Hijacking
  • T1210 - Exploitation of Remote Services
  • T1415 - URL Scheme Hijacking
  • T1416 - URI Hijacking
  • T1449 - Exploit SS7 to Redirect Phone Calls/SMS
  • T1460 - Biometric Spoofing
  • T1497 - Virtualization/Sandbox Evasion
  • T1547 - Boot or Logon Autostart Execution
  • T1560 - Archive Collected Data
  • T1566 - Phishing
  • T1583.005 - Botnet
  • TA0011 - Command and Control

Attack Log References

Whois Information

NetRange: 104.40.0.0 - 104.47.255.255 CIDR: 104.40.0.0/13 NetName: MSFT NetHandle: NET-104-40-0-0-1 Parent: NET104 (NET-104-0-0-0-0) NetType: Direct Allocation OriginAS: Organization: Microsoft Corporation (MSFT) RegDate: 2014-05-07 Updated: 2021-12-14 Ref: https://rdap.arin.net/registry/ip/104.40.0.0 OrgName: Microsoft Corporation OrgId: MSFT Address: One Microsoft Way City: Redmond StateProv: WA PostalCode: 98052 Country: US RegDate: 1998-07-10 Updated: 2023-11-17 Comment: To report suspected security issues specific to traffic emanating from Microsoft online services, including the distribution of malicious content or other illicit or illegal material through a Microsoft online service, please submit reports to: Comment: * https://cert.microsoft.com. Comment: Comment: For SPAM and other abuse issues, such as Microsoft Accounts, please contact: Comment: * abuse@microsoft.com. Comment: Comment: To report security vulnerabilities in Microsoft products and services, please contact: Comment: * secure@microsoft.com. Comment: Comment: For legal and law enforcement-related requests, please contact: Comment: * msndcc@microsoft.com Comment: Comment: For routing, peering or DNS issues, please Comment: contact: Comment: * IOC@microsoft.com Ref: https://rdap.arin.net/registry/entity/MSFT OrgAbuseHandle: MAC74-ARIN OrgAbuseName: Microsoft Abuse Contact OrgAbusePhone: +1-425-882-8080 OrgAbuseEmail: abuse@microsoft.com OrgAbuseRef: https://rdap.arin.net/registry/entity/MAC74-ARIN OrgTechHandle: BEDAR6-ARIN OrgTechName: Bedard, Dawn OrgTechPhone: +1-425-538-6637 OrgTechEmail: dabedard@microsoft.com OrgTechRef: https://rdap.arin.net/registry/entity/BEDAR6-ARIN OrgRoutingHandle: CHATU3-ARIN OrgRoutingName: Chaturmohta, Somesh OrgRoutingPhone: +1-425-882-8080 OrgRoutingEmail: someshch@microsoft.com OrgRoutingRef: https://rdap.arin.net/registry/entity/CHATU3-ARIN OrgTechHandle: MRPD-ARIN OrgTechName: Microsoft Routing, Peering, and DNS OrgTechPhone: +1-425-882-8080 OrgTechEmail: IOC@microsoft.com OrgTechRef: https://rdap.arin.net/registry/entity/MRPD-ARIN OrgTechHandle: SINGH683-ARIN OrgTechName: Singh, Prachi OrgTechPhone: +1-425-707-5601 OrgTechEmail: pracsin@microsoft.com OrgTechRef: https://rdap.arin.net/registry/entity/SINGH683-ARIN OrgTechHandle: IPHOS5-ARIN OrgTechName: IPHostmaster, IPHostmaster OrgTechPhone: +1-425-538-6637 OrgTechEmail: iphostmaster@microsoft.com OrgTechRef: https://rdap.arin.net/registry/entity/IPHOS5-ARIN