148.66.137.120 Threat Intelligence and Host Information

General

IP Address
148.66.137.120
IPv4 Address
Location
🇸🇬 Singapore, Singapore
SG
Network
AS26496
AS-26496-GO-DADDY-COM-LLC
Threat Score
70/100
High Risk
$WebWatsonadaptivebeeadultcontentagentagentteslaagenttesla
Attack Intelligence
MITRE ATT&CK Techniques
T1001 - Data Obfuscation, T1027 - Obfuscated Files or Information, T1055 - Process Injection, T1059.007 - JavaScript, T1059 - Command and Scripting Interpreter, T1068 - Exploitation for Privilege Escalation, T1071.001 - Web Protocols, T1071.004 - DNS, T1105 - Ingress Tool Transfer, T1114 - Email Collection, T1140 - Deobfuscate/Decode Files or Information, T1176 - Browser Extensions, T1190 - Exploit Public-Facing Application, T1210 - Exploitation of Remote Services, T1211 - Exploitation for Defense Evasion, T1412 - Capture SMS Messages, T1449 - Exploit SS7 to Redirect Phone Calls/SMS, T1450 - Exploit SS7 to Track Device Location, T1454 - Malicious SMS Message, T1496 - Resource Hijacking, T1497 - Virtualization/Sandbox Evasion, T1498 - Network Denial of Service, TA0011 - Command and Control, TA0029 - Privilege Escalation
Open Ports Detected
110
Geographic Location
Country
Singapore
City
Singapore
Region
Unknown
Coordinates
1.3036, 103.8554
Network Information
ASN
AS26496
Organization
AS-26496-GO-DADDY-COM-LLC
Network
AS26496 AS-26496-GO-DADDY-COM-LLC
WHOIS Information
NetRange
148.66.128.0 - 148.66.159.255
CIDR
148.66.128.0/19
NetName
APNIC
NetHandle
NET-148-66-128-0-1
Parent
NET148 (NET-148-0-0-0-0)
NetType
Early Registrations, Transferred to APNIC
OriginAS
Organization
Asia Pacific Network Information Centre (APNIC)
RegDate
Updated
2012-01-24
Ref
https://rdap.arin.net/registry/entity/APNIC
OrgName
Asia Pacific Network Information Centre
OrgId
APNIC
Address
PO Box 3646
City
South Brisbane
StateProv
QLD
PostalCode
4101
Country
AU
OrgTechHandle
AWC12-ARIN
OrgTechName
APNIC Whois Contact
OrgTechPhone
+61 7 3858 3188
OrgTechEmail
search-apnic-not-arin@apnic.net
OrgTechRef
https://rdap.arin.net/registry/entity/AWC12-ARIN
OrgAbuseHandle
AWC12-ARIN

Malware Detected on Host

Count: 21 2f71c2aca595dca2830cd5ecb4927e3a5f8502637929ca874165ccf1997f896f ec89d0e6cae628f658627f32a83bd166ba7e708decfb3e5e0f1f2a8c13afa8ae 4cef59db0391b1c586c231bdf47e4ae037943f1d4452eb8de2488877d75ce82d edfdda1e7c68e0de6f76d5cd93e972ad04643552dd7b50174ca2f462ee73c74e a2700a0d548fc2a103507eb8e9188f435ccdfa9cbb7338647d1504d725c2c43a 1ec6a3bd9f69d50a67c39d36512e60d46c4c543aa38239fb7547998ca49f29f1 20d2be74f91e5d549f72ac8d65a6a7c436c2936950efd41cd626ab9eff520c7c 6c67c435c6894c0ec992d34794f68a497c5c55778a4ea811b322b9c1f539841b 946d379003a8578e7f97313a542c8bdaaabb216968b6cd6db6336ddcf7324d15 a863b80f05038941385d809148546aa22fc71eb2b14ce02b78f40470e718a6a9

CVEs Detected

CVE-2007-2768 CVE-2008-3844 CVE-2010-4478 CVE-2010-4755 CVE-2010-5107 CVE-2011-4327 CVE-2011-5000 CVE-2012-0814 CVE-2014-1692 CVE-2014-2532 CVE-2014-2653 CVE-2015-5352 CVE-2015-5600 CVE-2015-6563 CVE-2015-6564 CVE-2016-0777 CVE-2016-10009 CVE-2016-10010 CVE-2016-10011 CVE-2016-10012 CVE-2016-10708 CVE-2016-1908 CVE-2016-20012 CVE-2016-3115 CVE-2017-15906 CVE-2018-15473 CVE-2018-20685 CVE-2019-6109 CVE-2019-6110 CVE-2019-6111 CVE-2020-15778 CVE-2021-36368 CVE-2023-38408 CVE-2023-48795 CVE-2023-51384 CVE-2023-51385 CVE-2023-51767

Disclaimer
This page contains threat intelligence information for the IPv4 address 148.66.137.120 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.