104.47.73.161 Threat Intelligence and Host Information
General
This page contains threat intelligence information for the IPv4 address 104.47.73.161 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.
Likely Malicious Host 🟠 60/100
Host and Network Information
-
Mitre ATT&CK IDs: T1027 - Obfuscated Files or Information, T1031 - Modify Existing Service, T1036 - Masquerading, T1040 - Network Sniffing, T1041 - Exfiltration Over C2 Channel, T1045 - Software Packing, T1053 - Scheduled Task/Job, T1055 - Process Injection, T1056.001 - Keylogging, T1057 - Process Discovery, T1059.007 - JavaScript, T1059 - Command and Scripting Interpreter, T1060 - Registry Run Keys / Startup Folder, T1068 - Exploitation for Privilege Escalation, T1071.001 - Web Protocols, T1071.003 - Mail Protocols, T1071.004 - DNS, T1071 - Application Layer Protocol, T1082 - System Information Discovery, T1083 - File and Directory Discovery, T1100 - Web Shell, T1105 - Ingress Tool Transfer, T1106 - Native API, T1112 - Modify Registry, T1114 - Email Collection, T1122 - Component Object Model Hijacking, T1129 - Shared Modules, T1140 - Deobfuscate/Decode Files or Information, T1147 - Hidden Users, T1156 - Malicious Shell Modification, T1184 - SSH Hijacking, T1210 - Exploitation of Remote Services, T1415 - URL Scheme Hijacking, T1416 - URI Hijacking, T1449 - Exploit SS7 to Redirect Phone Calls/SMS, T1460 - Biometric Spoofing, T1497 - Virtualization/Sandbox Evasion, T1546.015 - Component Object Model Hijacking, T1546 - Event Triggered Execution, T1547 - Boot or Logon Autostart Execution, T1560 - Archive Collected Data, T1583.005 - Botnet, T1588.004 - Digital Certificates, T1588 - Obtain Capabilities, TA0004 - Privilege Escalation, TA0011 - Command and Control
-
Tags: aaaa, abuse contact, accept, acint, active, active threat, address, adload, a domains, adult content, adware, adwind, agency, agent, aig, aig.com, aig.rastreator.mx, akamai, akamaias, alexa, alexa top, algorithm, alibaba cloud, all octoseek, all search, amazon02, amazonaes, analyze, android, anonymizer, a nxdomain, a poster, aposter, apple, apple attack, apple engineering, apple id, apple ios, applenoc, apple private, april, argon data, artemis, artro, as16625, as20940, as24940 hetzner, as4134 chinanet, as58061 scalaxy, as63949 linode, as714, as8075, ascii text, asnone united, asp.net, assaulter, attack, august, author, authority, autoit, autoit windows, automation tool, autorun, available from, awful, backdoor, bahamut, bank, banker, bankerx, behav, beijing, bell south, bellsouth, benjamin, binary, blacklist, blacklist http, blacklist https, body, body doctype, body length, brian, brian sabey, briansabey, browse scan, brute force passwords, bundled, ca, canvas, capture, cellbrite, cellebrite, cellebrite ufed, charles, china, china telecom, china unknown, cidr, cisco umbrella, citadel, ck id, ck matrix, class, cleaner, click, cloudflarenet, cloud host, cmd, cname, cobalt strike, code, coinminer, communicating, communication, company limited, computer, computing, comspec, conduit, config, contact, contacted, contentencoding, contextualizing, cookie, copy, country, covid19, crack, created, create new, creation date, critical, critical risk, crypto, csc corporate, cybercrime, cyber criminal, cyber stalking, cyberstalking, cyber threat, cyber warfare, dashboard, data collection, date, december, defence, detection list, detections file, detections type, digitaloceanasn, discovery, djcodychase.com, dns replication, domain, domain entries, domain name, domain related, domains, domainsite, downldr, downloader, dropbox, dropper, dynadot llc, elf collection, email, emotet, encrypt, endpoints all, engineering, entries, error, et, et cins, et policy, et tor, execution, exit, exodus, expiration, expiration date, exploit, exploit-source, facebook, factory, fakealert, falcon sandbox, false, fear, feeds ioc, file, filehashmd5, filehashsha1, filehashsha256, files, file size, files location, filetour, final url, final url summary, firehol, FireHOL, first, fjlsedauv, forbidden, formbook, for privacy, fraud, full name, fusioncore, gandi sas, general, generator, generic, generic malware, genkryptik, germany, germany unknown, get autoit, getprocaddress, gmo internet, gmt content, goldfinder, google, google llc, gootloader, go.sabey, graph, graph community, group, hacktool, hallrender, hashes files, headers, headers nel, heur, hidden privacy, high, historical, historical ssl, hostile, hostname, Hostname: RecoveryStore-3.7.5.1.4.6.2.0-D917-11E7-B67B-080027A49, HTML document ASCII text, http, http request, http response, https, hybrid, iana id, icefog, icloud, identifier, identity theft, iframe, incapsula, indicator, info, install, installcore, installer, intel, internapblk4, iocs, ioc search, iocs kb, ios, ip address, ip detections, ip summary, ipv4, ipv6, ireland netsky, issuer, it’s back, japan national police agency, javascript, jekyll, json data, june, kb body, kb file, key algorithm, key identifier, keylogger, killav, kimsuky, known tor, latest, limited, linkid252669, list, local, localappdata, logistics, lokibot, mail spammer, malicious, malicious host, malicious site, malicious url, maltiverse, malvertizing, malware, malware beacon, malware site, march, markmonitor, masquerading, matches rule, medium, meta, metro, Miles IT, million, misc activity, misc attack, mitre, mitre att, mitre attk, model, modified, module load, monitoring, month ago, months ago, ms windows, mtb dec, mtb jan, mtsub26293293, mumblehard, name, namecheapnet, name server, name servers, namesilo, name verdict, national police agency japan, netherlands, network, new ioc, next, nimda, nircmd, node traffic, no expiration, noname057, nr-data.net, nuance, number, nxdomain, nymaim, observed email, october, octoseek, office open, open, opencandy, origin1, otx octoseek, packed, page, parent referrer, parking crew, passive dns, paste, patch, patcher, path, pattern match, pcap, pdf cellebrite, pdf community, pdf report, pegasus, persistence, phishing, phishing site, pony, pornography, post root, prefetch8, presenoker, privacy invasion, privilege escalation, privilege https, process32nextw, proxy, pte ltd, pty ltd, pulse pulses, pulse submit, pulse use, qakbot, qbot, quasar, quoth, raccoon, raven, read c, record type, record value, redacted for, redirector, redline stealer, referrer, regdword, registrar, registrar abuse, registrarsafe, registrar url, registrar whois, registry domain, regsetvalueexa, reimer, reinsurance, relacion, relacionada, related nids, relay, relayrouter, remote, remote attack, report spam, resolutions, responder, riskware, root, root ca, rwi dtools, s1de, s1us, sabey, safe site, sameorigin, sample, sample path, samples, sandbox, sa victim, scalaxy, scammer, scan endpoints, script, script urls, search, seraph, server, servers, service, serving ip, setup, sha256, show, showing, show technique, siblings, sibot, simple, singlehopllc, site, skynet, small, smtp service, social engineering, spammer, span, speakez securus, spying, squarespace, ssh on server, ssl certificate, ssl hostname, startpage, state, status, status code, status codes, stealer, stix, strings, subdomains, subid, subject key, submit, submit quasar, submitters, summary, summary iocs, suppobox, Suricata Alert, survivor, susp, swisscom root, swrort, system46606, systweak, t1129, t1140, tagging, targets sa, team, team internet, teams api, temp, text, threat, threat analyzer, threat report, threat roundup, tiggre, title, tjprojmain, tofsee, tor ssl, tracker, tracking, trojan, trojanspy, trojanx, trust, tsara brashears, ttl value, tucows, tulach, twitter, type, type name, ufed4pc, ufed iphone, ufed release, unclejohn, unified layer, united, United states, unknown, unknown urls, unruy, unsafe, url analysis, url http, url https, urls, urls https, urls latest, url summary, usage, us autonomous, useragent, utc submissions, utmsourcemailer, v3 serial, vary, vawtrak, verdict, verified, vidar, virus network, virustotal, vt graph, wacatac, webcompanion, webico company, webtoolbar, whois, whois record, whois whois, win32, win32 dll, win32 exe, win64, windir, workaposter, worm, write, writeconsolea, x509v3 extended, x509v3 key, xml document, xml spreadsheet, xobo, xrat, xtrat, zpevdo
-
View other sources: Spamhaus VirusTotal
- Country: United States
- Network: AS8075 microsoft corporation
- Noticed: 50 times
- Protcols Attacked: SSH
- Countries Attacked: Canada, Netherlands, United States of America
- Passive DNS Results: hotmail-com.olc.protection.outlook.com 1863723012.pamx1.hotmail.com 1721717832.pamx1.hotmail.com 2081814144.pamx1.hotmail.com 83dfba53a17c4ba6b2b63aac6bf27a.pamx1.hotmail.com 121375864.pamx1.hotmail.com msn-com.olc.protection.outlook.com 104.47.73.161
Malware Detected on Host
Count: 307 a573220d479907e3bd983b2a578cfcb82326e80a29356794ccf7c7dd46b4ae06 b11bdd1bf762f50afc338bbb585b4f620cbef4328d479da027c75b03c7942984 fbb5a7815204506512cbb3ed36bececa637e1fc0da29f85fa37e1b75bb476c1e 8e8a5c54622f7311fd6651cf8b341a3c021695c219b660f9fe35577099ccdd7e 3ebd46e93626e8ff43b04c43fcd3def8c71d36f84c81328432f3d22b031d7134 fb001251acba06fc9e682a4af19d097f3bec489ac95c22329eb58597ec9494da d92e460d7f844af778623d4e534ac806b85b1678f82da75eec74bc46982dadb4 899fd8a10042417330208174ddf972c8265db96011e15de60970a8fd2f3d1f74 3736f619acd83b3fe594b68b400f7c3936d8ca57e2b131b7116f1d87664fa08a fc0d5327e12b019f4002fefe56228670e5b18ed4c4076a1decf39aef20429099
Open Ports Detected
Map
Whois Information
- NetRange: 104.40.0.0 - 104.47.255.255
- CIDR: 104.40.0.0/13
- NetName: MSFT
- NetHandle: NET-104-40-0-0-1
- Parent: NET104 (NET-104-0-0-0-0)
- NetType: Direct Allocation
- OriginAS:
- Organization: Microsoft Corporation (MSFT)
- RegDate: 2014-05-07
- Updated: 2021-12-14
- Ref: https://rdap.arin.net/registry/ip/104.40.0.0
- OrgName: Microsoft Corporation
- OrgId: MSFT
- Address: One Microsoft Way
- City: Redmond
- StateProv: WA
- PostalCode: 98052
- Country: US
- RegDate: 1998-07-10
- Updated: 2023-11-17
- Comment: To report suspected security issues specific to traffic emanating from Microsoft online services, including the distribution of malicious content or other illicit or illegal material through a Microsoft online service, please submit reports to:
- Comment: * https://cert.microsoft.com.
- Comment:
- Comment: For SPAM and other abuse issues, such as Microsoft Accounts, please contact:
- Comment: * abuse@microsoft.com.
- Comment:
- Comment: To report security vulnerabilities in Microsoft products and services, please contact:
- Comment: * secure@microsoft.com.
- Comment:
- Comment: For legal and law enforcement-related requests, please contact:
- Comment: * msndcc@microsoft.com
- Comment:
- Comment: For routing, peering or DNS issues, please
- Comment: contact:
- Comment: * IOC@microsoft.com
- Ref: https://rdap.arin.net/registry/entity/MSFT
- OrgTechHandle: MRPD-ARIN
- OrgTechName: Microsoft Routing, Peering, and DNS
- OrgTechPhone: +1-425-882-8080
- OrgTechEmail: IOC@microsoft.com
- OrgTechRef: https://rdap.arin.net/registry/entity/MRPD-ARIN
- OrgTechHandle: SINGH683-ARIN
- OrgTechName: Singh, Prachi
- OrgTechPhone: +1-425-707-5601
- OrgTechEmail: pracsin@microsoft.com
- OrgTechRef: https://rdap.arin.net/registry/entity/SINGH683-ARIN
- OrgTechHandle: IPHOS5-ARIN
- OrgTechName: IPHostmaster, IPHostmaster
- OrgTechPhone: +1-425-538-6637
- OrgTechEmail: iphostmaster@microsoft.com
- OrgTechRef: https://rdap.arin.net/registry/entity/IPHOS5-ARIN
- OrgTechHandle: BEDAR6-ARIN
- OrgTechName: Bedard, Dawn
- OrgTechPhone: +1-425-538-6637
- OrgTechEmail: dabedard@microsoft.com
- OrgTechRef: https://rdap.arin.net/registry/entity/BEDAR6-ARIN
- OrgAbuseHandle: MAC74-ARIN
- OrgAbuseName: Microsoft Abuse Contact
- OrgAbusePhone: +1-425-882-8080
- OrgAbuseEmail: abuse@microsoft.com
- OrgAbuseRef: https://rdap.arin.net/registry/entity/MAC74-ARIN
- OrgRoutingHandle: CHATU3-ARIN
- OrgRoutingName: Chaturmohta, Somesh
- OrgRoutingPhone: +1-425-882-8080
- OrgRoutingEmail: someshch@microsoft.com
- OrgRoutingRef: https://rdap.arin.net/registry/entity/CHATU3-ARIN