185.140.53.137 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 185.140.53.137 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Likely Malicious Host 🟠 60/100

Host and Network Information

  • Mitre ATT&CK IDs: T1071 - Application Layer Protocol, T1106 - Native API, T1498 - Network Denial of Service, T1499.002 - Service Exhaustion Flood, T1499 - Endpoint Denial of Service, T1566 - Phishing

  • Tags: agent tesla, android, asyncrat, august, autoit, blacklist, brazil, brazil user, bulgaria, cc.py, coinminer, cvss, cvss base, dcrat, DDoS, domains, enterprise, february, germany, germany user, hashes, HEAD Floods, indonesia, ip address, Killnet, lithuania, lockbit, lumma, malware url, mexico, microsoft, mozi, mozi link, muddywater, panama, panda, penterac2, powershell, proxy, qilin, recordbreaker, redlinestealer, remcos, romania, russia, russia user, sha values, singapore user, snakekeylogger, spynote, stealc, steam, submission, T1498, T1499, turkey, united kingdom, urls http, urls https, usa user, user submission, vipersoftx, week, windows

  • View other sources: Spamhaus VirusTotal

  • Country: Sweden
  • Network:
  • Noticed: 22 times
  • Protocols Attacked: Anonymous Proxy
  • Passive DNS Results: iphanyi.mywire.org iphanyi.mooo.com iphanyi.webredirect.org info1.dynamic-dns.net mirroronthewall.hopto.org favorali.duckdns.org indigobaba.publicvm.com newlogs.ddns.net soith999.ddns.net teames.hopto.org 5541.gotdns.ch cool.gotdns.ch newmexy.ddns.net elvis4.ddns.net mmiri1.ddns.net liam001.spdns.eu cj419.ddns.net

Malware Detected on Host

Count: 47 6acaed46cf23fefd30d73e5b21e8480f711614aee0afcedfd29085df9430c73e 0fc54d55d3cb27bf5ec3c09325478deeebc49ff858fd7f413a62fb949b7a9666 9e303489b6a886ee967ace328a26749db9664604ab638e544e260918044b21de 10f5584682c3f5d54ba1e3afd68822c81e8234531c8b1a41e11774b980915c72 baccd3d2cd02286e08b6739dfc786f67bd64b5da6bfca6ba93ddf21f8e9d8359 f6d0fdcf620ebd3b483c6dd7e9bc7bea2f9acca8d34eb7b84ebaf457671fd758 efbae02e814b3845a289aaec71ae79b8639fd21bdd0ac91ba91b8282ff1b7b29 b1d613125002c9ad976f2a6f2dda3a835bc1ad0530cab7fe9af1eecf05fe6cc6 a2c4bdeac21d1c1a3d9522ad738f405810618fd9a3e0735cfe5a258c80ddcfaf e748e76168a7e308c718a4caff95bcee0e5315937c293169015aed60b27ab135

Map

Whois Information

  • inetnum: 185.140.52.0 - 185.140.55.255
  • netname: SE-BLYCKA-20160224
  • country: SE
  • org: ORG-BA1511-RIPE
  • admin-c: MA25866-RIPE
  • tech-c: MA25866-RIPE
  • status: ALLOCATED PA
  • mnt-by: lir-se-blycka-1-MNT
  • mnt-by: RIPE-NCC-HM-MNT
  • created: 2022-11-15T10:34:44Z
  • last-modified: 2022-11-15T10:34:44Z
  • organisation: ORG-BA1511-RIPE
  • org-name: Blycka AB
  • country: SE
  • org-type: LIR
  • address: Sankt Eriksgatan 18
  • address: 11239
  • address: Stockholm
  • address: SWEDEN
  • phone: +46707974694
  • admin-c: MA25866-RIPE
  • tech-c: MA25866-RIPE
  • abuse-c: AR69298-RIPE
  • mnt-ref: lir-se-blycka-1-MNT
  • mnt-by: RIPE-NCC-HM-MNT
  • mnt-by: lir-se-blycka-1-MNT
  • created: 2022-11-08T10:25:26Z
  • last-modified: 2022-11-08T10:25:26Z
  • role: Maintainer
  • address: SWEDEN
  • address: Stockholm
  • address: 11239
  • address: Sankt Eriksgatan 18
  • phone: +46707974694
  • nic-hdl: MA25866-RIPE
  • mnt-by: lir-se-blycka-1-MNT
  • created: 2022-11-08T10:25:24Z
  • last-modified: 2022-11-08T10:25:25Z
  • route: 185.140.53.0/24
  • origin: AS215324
  • mnt-by: MENET-MNT
  • created: 2024-08-23T14:32:40Z
  • last-modified: 2024-08-23T14:32:40Z
  • route: 185.140.53.0/24
  • origin: AS63801
  • mnt-by: lir-se-blycka-1-MNT
  • mnt-by: se-tombii-1-mnt
  • mnt-by: MENET-MNT
  • created: 2024-02-22T07:21:05Z
  • last-modified: 2024-02-22T07:21:21Z

Links to attack logs

anonymous-proxy-ip-list-2023-12-16 anonymous-proxy-ip-list-2023-07-15 anonymous-proxy-ip-list-2023-08-05 anonymous-proxy-ip-list-2023-09-25 anonymous-proxy-ip-list-2023-10-18 anonymous-proxy-ip-list-2023-10-25 anonymous-proxy-ip-list-2023-11-20 anonymous-proxy-ip-list-2024-01-03 anonymous-proxy-ip-list-2023-07-28 anonymous-proxy-ip-list-2023-10-05 anonymous-proxy-ip-list-2023-10-17 anonymous-proxy-ip-list-2023-11-24 anonymous-proxy-ip-list-2023-11-25 anonymous-proxy-ip-list-2023-08-30 anonymous-proxy-ip-list-2023-10-31 anonymous-proxy-ip-list-2023-11-04 anonymous-proxy-ip-list-2023-12-10 anonymous-proxy-ip-list-2023-07-18 anonymous-proxy-ip-list-2023-08-23 anonymous-proxy-ip-list-2023-08-25 anonymous-proxy-ip-list-2023-11-29 anonymous-proxy-ip-list-2023-11-02 anonymous-proxy-ip-list-2023-11-14 anonymous-proxy-ip-list-2023-11-17 ****** anonymous-proxy-ip-list-2023-08-07 anonymous-proxy-ip-list-2023-09-12 anonymous-proxy-ip-list-2023-10-19 anonymous-proxy-ip-list-2023-10-27 anonymous-proxy-ip-list-2023-11-16 anonymous-proxy-ip-list-2023-09-24 anonymous-proxy-ip-list-2023-10-20 anonymous-proxy-ip-list-2023-10-21 anonymous-proxy-ip-list-2023-10-30 anonymous-proxy-ip-list-2023-11-05 anonymous-proxy-ip-list-2023-12-24 anonymous-proxy-ip-list-2023-07-27 anonymous-proxy-ip-list-2023-08-24 anonymous-proxy-ip-list-2023-09-01 anonymous-proxy-ip-list-2023-11-01 anonymous-proxy-ip-list-2023-11-03 anonymous-proxy-ip-list-2023-11-06 anonymous-proxy-ip-list-2023-12-08 anonymous-proxy-ip-list-2023-12-21 anonymous-proxy-ip-list-2023-08-08 anonymous-proxy-ip-list-2023-08-16 anonymous-proxy-ip-list-2023-08-21 anonymous-proxy-ip-list-2023-11-26 anonymous-proxy-ip-list-2023-11-28 anonymous-proxy-ip-list-2023-09-04 anonymous-proxy-ip-list-2023-11-13 anonymous-proxy-ip-list-2023-12-22 anonymous-proxy-ip-list-2023-12-30 anonymous-proxy-ip-list-2023-07-10 anonymous-proxy-ip-list-2023-12-27 anonymous-proxy-ip-list-2023-09-15 anonymous-proxy-ip-list-2023-09-27 anonymous-proxy-ip-list-2023-11-21 anonymous-proxy-ip-list-2023-12-03 anonymous-proxy-ip-list-2024-01-02 anonymous-proxy-ip-list-2023-10-16 anonymous-proxy-ip-list-2023-11-19 anonymous-proxy-ip-list-2023-11-10 anonymous-proxy-ip-list-2023-06-30 anonymous-proxy-ip-list-2023-08-04 anonymous-proxy-ip-list-2023-10-08 anonymous-proxy-ip-list-2023-10-22 anonymous-proxy-ip-list-2023-10-28 anonymous-proxy-ip-list-2023-11-18 anonymous-proxy-ip-list-2023-12-25 anonymous-proxy-ip-list-2023-07-31 anonymous-proxy-ip-list-2023-08-19 anonymous-proxy-ip-list-2023-11-12 anonymous-proxy-ip-list-2023-12-04 anonymous-proxy-ip-list-2023-12-26 anonymous-proxy-ip-list-2023-07-09 anonymous-proxy-ip-list-2023-08-14 anonymous-proxy-ip-list-2023-09-10 anonymous-proxy-ip-list-2023-10-23 anonymous-proxy-ip-list-2023-11-27 anonymous-proxy-ip-list-2023-11-15 anonymous-proxy-ip-list-2023-12-07 anonymous-proxy-ip-list-2023-12-19 anonymous-proxy-ip-list-2023-08-20 anonymous-proxy-ip-list-2023-10-11 anonymous-proxy-ip-list-2023-10-24 anonymous-proxy-ip-list-2023-11-30 anonymous-proxy-ip-list-2023-12-01 anonymous-proxy-ip-list-2023-08-31 anonymous-proxy-ip-list-2023-10-29 anonymous-proxy-ip-list-2023-11-08 anonymous-proxy-ip-list-2023-12-05 anonymous-proxy-ip-list-2023-12-12 anonymous-proxy-ip-list-2023-12-17 anonymous-proxy-ip-list-2023-12-20 ****** anonymous-proxy-ip-list-2023-06-22 anonymous-proxy-ip-list-2023-07-03 anonymous-proxy-ip-list-2023-09-26 anonymous-proxy-ip-list-2023-10-02 anonymous-proxy-ip-list-2023-07-13 anonymous-proxy-ip-list-2023-11-22 anonymous-proxy-ip-list-2023-11-09 anonymous-proxy-ip-list-2023-11-11 anonymous-proxy-ip-list-2023-12-18 anonymous-proxy-ip-list-2023-12-06 anonymous-proxy-ip-list-2023-12-11 ****** anonymous-proxy-ip-list-2023-07-14 anonymous-proxy-ip-list-2023-08-27 anonymous-proxy-ip-list-2023-09-29 anonymous-proxy-ip-list-2023-10-26 anonymous-proxy-ip-list-2023-11-23 anonymous-proxy-ip-list-2023-12-23 anonymous-proxy-ip-list-2023-12-31 anonymous-proxy-ip-list-2024-01-01

Share on: