18.139.9.214 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 18.139.9.214 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Possibly Malicious Host 🟢 25/100

Host and Network Information

  • Tags: ngrok, tsec

  • JARM: 40d1db40d0000001dc43d1db1db43d76e1f79b8645e08ae7fa8f07eb5e4202

  • View other sources: Spamhaus VirusTotal

  • Country: Singapore
  • Network:
  • Noticed: 6 times
  • Protocols Attacked: Anonymous Proxy
  • Passive DNS Results: web-login-fb.xyz www.srti-server.online tuuoo.top lightningsmp.online mzzyy.top mleety.top thestarstream.online cellannotate-dev.com mc-anycraft.online tienmi-bot.ap.taxigo.cc michael-socketio.ap.taxigo.cc dada-business.ap.taxigo.cc app-dev.yaptutor.ap.ngrok.io bacs-dev.firefense.ap.ngrok.io comet.test.ap.ngrok.io www.vsafety.one acc.bookingtogo.com itless.work simrs.rsudhd.id docufai.layoutreader.ap.ngrok.io clientgeoloc.local.bluspark.io.ap.ngrok.io myrok.gzshiningsun.com aa.10.10.18.106.ap.ngrok.io sms.rubik88.com.ap.ngrok.io bot.daniw.net account.line.me.ap.ngrok.io uat.epicminds.ap.ngrok.io nrsc.gov.sa.ap.ngrok.io hncb.jp.ap.ngrok.io offline.appium.4723.ap.ngrok.io ynguyen.es.ap.ngrok.io sts.tanandtech.com.my 8ff1-88-230-40-124.ap.ngrok.io ds.monday.ap.ngrok.io inspirator.bfactory.ai onboarding.supplybridge.ap.ngrok.io cr-shopware6.sava.eu.ap.ngrok.io nlp-etl-alextay.ai.ap.ngrok.io api-dev.shareloapp.com.ap.ngrok.io images.n1fty.app signify.gov.sg 3.api.dakok.ap.ngrok.io callback.terragon.ap.ng.ap.ngrok.io msisdn.xlcp.in.th shinobi.lo1.ap.ngrok.io bot.test-teams-media-bot.com analytics.googlstatistics.live tendril-dev.ng.ap.ngrok.io www.miketraje.tk events.blackbox.ap.ngrok.io soc.tjakrabirawa.id sys.dgmstore.ph mpd.smkn1kandeman.sch.id registry.tjakrabirawa.id defecd.tjakrabirawa.id mis.dhtr.pk ava.seventhsense.ai ob2.meo.link playground.rexwang.cc dteti-ai.ap.ngrok.io playminevn.ga media.discojc.click grimprojects.com minecraft.house51studio.com tunnel.jaygx.me www.goldenladderph.com debugging.ihsandevs.io ngrok.bizharedev.id.ap.ngrok.io node-red.aws.ap.unco-op.co.th api.askpedro.co.uk clickup.1p.team iccstock.duckdns.org local.staging.onwardticket.com socnow.software zfarm.ap.ngrok.io www.kunnusta.asr.ap.ngrok.io ngrok.an-ld-dev.ap.ngrok.io paystrayp.com farms.sonicfinance.io irassubmit.inventlab.sg z3mb74gq6zmpwu9u5zyb5wct8fmhn6em.turnlab.solutions www.scamsearch.space login.orson.mhub.ninja www.fullhousebeachresort.com www.ruvyrichtrading.com dev.aulet.inc 17c2-58-71-214-7.ap.ngrok.io projectg.tb.ap.ngrok.io dashboard.itsme.ap.ngrok.io carsongross.an-ld-dev.ap.ngrok.io code.worayoot.com codehard.api.ap.ngrok.io www.kopo.online arsns.cloud 0775-123-19-196-180.ap.ngrok.io chat.tjakrabirawa.id grafana.tjakrabirawa.id jocasso.codemafia.io iq.gkoh.ap.ngrok.io f3c1-112-210-84-166.ap.ngrok.io toolbox.cerap.ap.ngrok.io be-admin.devinflearn.com presale.ico-alterverse.com aeon.kulai.ap.ngrok.io dev-hcmc.wehmoen.dev www.kunnusta.dev.ap.ngrok.io elshaddai.ngrok.io.ap.ngrok.io autopsy.tjakrabirawa.id iq.rlau.ap.ngrok.io repo.ctownshend.ap.ngrok.io main.iqc-trading.com steveharold.com www.sumberjayacorporation.com x1playtw.com test.optimez.me.ap.ngrok.io www.51note.ga www.ctbc-bank.com eventbride.mintpax.com antrian.nugroho.tech support.sstc.uat.ap.ngrok.io baohanh.sstc.uat.ap.ngrok.io julo-000031824012.remote-appium.ap.ngrok.io dev.konigle.com.ap.ngrok.io m.goldenladderph.com cvat.pixtavietnam.com rideways-dispatch.travel-link.co dev.hr.kongstudios.net www.mse.ap.ngrok.io julo-4173681049.remote-appium.ap.ngrok.io julo-4159501470.remote-appium.ap.ngrok.io julo-4044374962.remote-appium.ap.ngrok.io julo-4038530881.remote-appium.ap.ngrok.io julo-4044934032.remote-appium.ap.ngrok.io julo-9999.remote-appium.ap.ngrok.io electrum.freedomnode.com ayonc.diritto.work julo-99999.remote-appium.ap.ngrok.io julo-00000.remote-appium.ap.ngrok.io julo-1234.remote-appium.ap.ngrok.io dev.booster-test-emerald.ap.ngrok.io cimb-bpm.nds.co.id d138eb950cce.ap.ngrok.io dev2.feedforce.vn.ap.ngrok.io api-reading.pelco1.org.ph api.orson.mhub.ninja groot.ngrok.botmd.io rocket.ngrok.botmd.io book.orson.mhub.ninja remote.appknox.com amrita.socket.ap.ngrok.io api.rygr.ap.ngrok.io pinotlab.quant.ap.ngrok.io dev.kollectin.ap.ngrok.io dfarobotics.mashbrains.dev smart.locker.ap.ngrok.io mc.hotmenkissing.gay beta.age-gate.unicorn.global attendance.dhtr.pk fe.devinflearn.com universe.live2.nomadas.cloud three.vault.trial.studio www.japotgenmdse.com remo.client.ap.ngrok.io skp.cosmiqo.com mcc.ciims.online mcc.ciims.online.ap.ngrok.io file.jasonzhuang.engineer local2.hashpays.ap.ngrok.io 7ecf-112-210-92-109.ap.ngrok.io pun.local.hashpays.ap.ngrok.io dev.hashpays.ap.ngrok.io comdevpedia.id mcc.ciims.ap.ngrok.io jbryan.ngrok.io.ap.ngrok.io repo.rlau.ap.ngrok.io raspberry.jasonz.engineer 6nyyptuc.cname.ap.ngrok.io bw.e39a562r.tw remote.qeso.fiambres.ap.ngrok.io project.db.ap.ngrok.io api.third.ap.ngrok.io local.hashpays.ap.ngrok.io drivemark.ashraff.my.ap.ngrok.io wp.fecredit.online cds.rama3.ap.ngrok.io ac14-112-207-66-87.ap.ngrok.io dev-api.touch888.vip slt.uat.ap.ngrok.io 50b8-175-158-53-198.ap.ngrok.io supervisi.oncustudio.my.id www.api-pmts.com box.miketraje.tk starlord.ngrok.botmd.io api.dso2o.ap.ngrok.io techar.thepalmerstudio.net mdm.webhook.ap.ngrok.io 3.anywork.ap.ngrok.io api.dev-mildtotoro.onework.services julo.remote-appium.ap.ngrok.io coffee.flitc.ap.ngrok.io confluence.digibank.link platform.nrsc.gov.sa qa.devinflearn.com fe-admin.devinflearn.com qa-business.devinflearn.com be.devinflearn.com be-business.devinflearn.com demo1.aeuie.com remo.server.ap.ngrok.io api.snew.ap.ngrok.io abba.jupyter.ap.ngrok.io universe.live.nomadas.cloud area57.automa.id annguyen.an-ld-dev.ap.ngrok.io test.aguad0.com aa.10.10.18.137.ap.ngrok.io dev.infinitcare.ap.ngrok.io home.chewie.co.uk codesubmit.vietanlife.vn fiambres.printer.qeso.ap.ngrok.io lamsooncyber.tanandtech.com.my portal.pelco1.ap.ngrok.io nlp.vicallbot.com ngrok.shipma.com sign.bouncer.ap.ngrok.io ewebinar-cdn.ap.ngrok.io cms.leaderonomics.ap.ngrok.io efe7-155-94-250-25.ap.ngrok.io colab.xdanger.com gateway.oragonshop.com 0471-112-210-73-31.ap.ngrok.io jhs.smhsapp.com ped.aphsapp.com ped.jsmjcapp.com jhs.jsmjcapp.com demoap.danielhazlewood.com george.receptful.dev manage.mryum.ap.ngrok.io gift-cards.reactify.dev pattaya.hikcentral.ap.ngrok.io api.dev-pittawatm.onework.services jurnal.powercred.io.ap.ngrok.io chall-ycep.dismgryphons.com api.dev-thiti-dev.onework.services api.dev-pornchaiamity.onework.services www.sipandj1.net api.medi-on.com ngrok.api2.quoka.in aa.hkgnbswebsit01.hk.intranet.ap.ngrok.io tracking-demo.firefense.ap.ngrok.io api-local.turnlab.solutions aeon.kulai.httpbin.ap.ngrok.io react.flexo.space api.hsse.master.ap.ngrok.io local.coinhq.co api.mse.ap.ngrok.io satu.filsafat.ap.ngrok.io inspiredropshipping.com.ap.ngrok.io tracking.chongluadao.vn sanjuan.iqc-trading.com sw1.uat.ap.ngrok.io bas.dev.ngrok.io.ap.ngrok.io cctv.corocot.com pinotlab.quant.api.ap.ngrok.io sw.uat.ap.ngrok.io lsna2.eu.ngrok.io.ap.ngrok.io my.swsms.online pxx.senses.chat mihoda.tanandtech.com.my erp.topmountain.ap.ngrok.io kiemtragiaohang.com dadik.smkn1kandeman.sch.id 23828f7d4da0.ngrok.io.ap.ngrok.io 6bb0-173-82-121-42.ap.ngrok.io qa-admin.devinflearn.com wiki.wakumo.vn sri-jelutong.pkppagro.com.my shinetsu.tanandtech.com.my flash.local.ap.ngrok.io aa.hkgnbswebuat01.hk.intranet.ap.ngrok.io abba.jupyter-kmy.ap.ngrok.io pymy.ap.ngrok.io api.tdpk.dev-light.onework.services www.oneshopbuildingmaterials.com cnsb.ap.ngrok.io line.xlcp.in.th sms.azc88vn.com.ap.ngrok.io cvv.bamchk.cc dev.atom.ac hajisenawi.tanandtech.com.my staging-ygg.betway365.vip recruitment.mirdc.dost.gov.ph home8s.angine.work home8s.knewdon.com.ap.ngrok.io www.bestiesph.com www.cvsmedgroupph.com printer.qeso.fiambres.ap.ngrok.io service.ema.nhso.ap.ngrok.io meter-reading.pelco1.ap.ngrok.io generation-api.ngrok.ap.ngrok.io hayatmaju.tanand.ap.ngrok.io sms.ap.ngrok.io.ap.ngrok.io polantassurabaya.id.tmms1.ap.ngrok.io devops.dev.devinflearn.com luzerne.blivracle.com www.tkr2022.com 1.anywork.ap.ngrok.io kube.knewta.com steady.adfcollege.net api.teamtoodle.ap.ngrok.io bislig.hrmis.ap.ngrok.io jenkins.masterin.dev ltiap.mathspace.co appium-server.techmtools.com tripla.e39a562r.tw 6b6e-103-131-109-24.ap.ngrok.io dev.wildthings.club dev.awkowk.io gitlab.nds.co.id chat.otag.online dms.camsurpiao.com asbbtest.ngrok.io.ap.ngrok.io heraeus.oneone.cool ext-wm-staging.l55-ext.com www.scaning-fidusia.web.id liff.dev-kanpizza1150.onework.services sumsub-webhook.staging.finbloxapp.com www.unihomehardware.com reports.suprema.oddbit.id bonjoro.thatsed.com lph.pkppagro.com.my www.lahalohalo-bislig.com ext-jili-staging.x1pbext.com api.hiker.ap.ngrok.io tradoz.ngrok.io.ap.ngrok.io beta-birdie-bff.bongohr.org.ap.ngrok.io abba.label.ap.ngrok.io abba.jupyter-smc.ap.ngrok.io api.tdpk.dev-adisakonework.onework.services aa.10.10.18.170.ap.ngrok.io aa.uat-apihk.hk.intranet.ap.ngrok.io chat.syndi.ap.ngrok.io wax.pplbresource.com mutiaratimur.tanandtech.com.my api.tdpk.dev-pittawatm.onework.services verify.bouncer.io.ap.ngrok.io local.sorimarket.shop www.rockholdhardware.com www.wellhometilestrading.com images.jpeg.ngrok.io.ap.ngrok.io www.buildingbuddieshardware.com codehard.idp.ap.ngrok.io ngrok.pkppagro.com.my webhook.sparklingjewels.live offline.appium.4755.ap.ngrok.io dev.gauntlet.retrospectlabs.com offline.robotremote.ap.ngrok.io api.atoz.ap.ngrok.io checker.bam.gay dev-fitbit.lif.id.ap.ngrok.io backend.dev.devinflearn.com alpha.road.loadmanna.com jenkins-server.techmtools.com api.ephodtech.refinitiv.ap.ngrok.io shulink.com.tw.ap.ngrok.io ap2.maintenance.ctrl.prosumer.io mpdpk.smkn1kandeman.sch.id mdec.gains.ap.ngrok.io knightsbridge.dev.ap.ngrok.io circle-webhook.staging.finbloxapp.com client.caesarcoin.ap.ngrok.io e39a562r.tw ngrok.axielero.com financial-data.teamtoodle.ap.ngrok.io 5.api.dakok.ap.ngrok.io test.nhso.ap.ngrok.io soal2.sukses.live soal4.sukses.live soal1.sukses.live 2.api.dakok.ap.ngrok.io 1.api.dakok.ap.ngrok.io drax.ngrok.botmd.io gamora.ngrok.botmd.io utmlab.com.sg.ap.ngrok.io aa.uat.laswf.ap.ngrok.io ac1f-110-159-169-58.ap.ngrok.io reports.nrsc.gov.sa cloud.pkppagro.com.my pxx.xanthous.cn bouncer.monitor.ap.ngrok.io api.iol.ap.ngrok.io line.iol.ap.ngrok.io vault.tunnel.yucorp.biz port.alredho.ap.ngrok.io telebot.zaaml.com visprepaiddprocessings.com.ap.ngrok.io webview-ngrok-dev.algocare.link ng.kyedoesdev.com tg.atoz.ap.ngrok.io accounts.nguyenchicuong.dev portainer.nguyenchicuong.dev minio.nguyenchicuong.ap.ngrok.io sts.tanand.ap.ngrok.io aa.10.10.18.35.ap.ngrok.io chargebee.asia.ap.ngrok.io keycloak.pymy.ap.ngrok.io workflow.pymy.ap.ngrok.io wax-test.pplbresource.com tunnel-04.sowat.dev beta.change-author.unicorn.global api.oragon.ventures pplbresource.com aa.hkgjavawebuat02.hk.intranet.ap.ngrok.io 4397-58-136-5-71.ap.ngrok.io jasonz.engineer api.dev-adisakonework.onework.services xasdb.odin.nai.peer-ai.com portainer.home.ap.ngrok.io cpn.hikcentral.ap.ngrok.io router.kknd0.cn bulkapidev.suwitsa.ap.ngrok.io fireblocks-webhook.staging.finbloxapp.com offline.remoterobot.ap.ngrok.io dodb.vpc.arpa.ph polantassurabaya.id.ap.ngrok.io b55b-2a02-7b40-c3b5-f2bb-00-1.ap.ngrok.io 2.anywork.ap.ngrok.io admin.genyc.ap.ngrok.io jakarta.growthpath.ap.ngrok.io www.grabonline.co.nz 3amsrvtjs.cname.ap.ngrok.io 33jtajjrk.cname.ap.ngrok.io 2ycnbzccu.cname.ap.ngrok.io emma2.chatcampaign.io strapi.ngrok.io.ap.ngrok.io auth.wealthx.ap.ngrok.io cd.next.ap.ngrok.io ap1.maintenance.ctrl.prosumer.io drone.masterin.dev tzn.dev.ngrok.cenports.net training.mirdc.dost.gov.ph andrew.ngrok.botmd.io lwww.itestable.net api-dev.pb268.com esaas-api.2vanx.ap.ngrok.io geck.slack.ap.ngrok.io argocd.ap.ngrok.com eurekapet.fgct.tech droneci-alextay96.prometheus-hq.ap.ngrok.io mlflow-alextay96.prometheus-hq.ap.ngrok.io inacbg01.mikron.id fellaslounge.tk api.hsse.limbah.ap.ngrok.io hsse.kecelakaan.api.ap.ngrok.io www.ishla.ma pg.wowgame.games kollectin.webhook.ap.ngrok.io certbot.komprok.com sochon.lehuy.vn a7ac-2409-4064-b9a-b863-1894-cb16-55ef-4bc6.ap.ngrok.io ext-sa-staging.x1pbext.com paytm.kyc.m.ap.ngrok.io sms-tool.xlcp.in.th paytm.kyc.ap.ngrok.io isp-supplies.net media.zookcorp.com lmbjkn.mikron.id localdash.annode2.ap.ngrok.io feedforce.vn.ap.ngrok.io 2sjef9mxc.cname.ap.ngrok.io 0a85-2409-4064-e81-f837-7d46-816e-4335-e51c.ap.ngrok.io webstaging.tjakrabirawa.id gocdt.tjakrabirawa.id 011a-2409-4064-e86-251d-8051-9dba-97f1-42df.ap.ngrok.io api.tjakrabirawa.id sq.tjakrabirawa.id elastic.tjakrabirawa.id jnj.oee.tanandtech.com.my wnc.tanand.ap.ngrok.io kol.meimaii.store tvs.kloudsites.com petstar-aldi.a.ap.ngrok.io nirmalasastera.com my001.lynclab.ap.ngrok.io thechefz.co.ap.ngrok.io c4.senre.dev.ap.ngrok.io www.vigtwin.com seraphsearch.line.biblesearch.test.ap.ngrok.io api.sms.oragon.ph.ap.ngrok.io rindle-michael.ngrok.io.ap.ngrok.io ngrok.senre.dev sql-server.home.ap.ngrok.io dbstaging.tjakrabirawa.id spiderfoot.tjakrabirawa.id rynmsh.ap.ngrok.io console.storage.odin.nai.peer-ai.com development.aptiway.com www.iotserver-ps.xyz serge.ngrok.botmd.io nodejs-harsa.wallex.ninja

Malware Detected on Host

Count: 38 91172b3e11351efb9ecad413278dc52c11a68429a633cf22f1c7c49151410138 d9c88ab29f40ca6865aa0b0a99e8fe0ad9e00d57c88e084e94d70bf2ecf53b62 6e8bb54fdc69d7a4ce09c44ca1585b84a68efdc0044a7b965d9bd3025a9818bb 2110c8af622e5ecfa0fd6d1fbc4998c788bf61ca9a520debfeaa49d20b994a1a 99474b8cfbbeedd0b14102583dcdd6e40e6bc2178f9491dbc08c7354ae090b3e 4b4e7871d8f03070a1adbb25db6a40609550588cdf6d72acab330ce9e77741f4 f8a0b177ffb660fdb71826feb4d92ae9ad666d12270871411910d9f0dc06a95f 51404c6494b6ae80e39d758a19d15e64ca680daa3d212fbf61d8ce4086fc0dbe d33fe54a5c9a9b05754bd60b72ed2b7c885d9d2538c1db83f3441f47e5004484 e50b50e7a2ef91ca18524298dfe771f252a8c6f4bce2c1cdd7e7748a0f89f76f

Open Ports Detected

443

Map

Whois Information

Links to attack logs

****** anonymous-proxy-ip-list-2023-05-26 ****** ******

Share on: