185.53.177.50 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 185.53.177.50 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

🟠 Elevated — 65/100

Geographic Location

Host and Network Information

  • View other sources: Spamhaus VirusTotal Shodan AbuseIPDB
  • Country: Germany
  • Network: AS61969 team internet ag
  • Noticed: 42 times
  • Protocols Attacked: SSH
  • Countries Attacked: Australia, Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
  • Open Ports: 443, 80
  • Tor Node: No
  • Associated Malware Samples: 565

Tags

  • aaaa
  • abuse
  • a checkin
  • activity dns
  • acurix networks
  • address
  • admin
  • a domains
  • adwind
  • adwind rat
  • agent tesla
  • agenttesla
  • aggah
  • aig
  • akamaias
  • algorithm
  • alienspy
  • all at
  • all octoseek
  • all search
  • amadey
  • amazon 02
  • ammyy
  • ammyy admin
  • analyze
  • android
  • andromut
  • angler
  • anomalous file
  • apart
  • appdata
  • apple
  • apple phone
  • april
  • as133618
  • as133775 xiamen
  • as14061
  • as15169 google
  • as16625 akamai
  • as20940
  • as25577 ide
  • as2914 ntt
  • as35994 akamai
  • as397240
  • as63949 linode
  • as8068
  • as9009 m247
  • ascii text
  • asnone
  • asyncrat
  • attack
  • august
  • aurora
  • avast avg
  • ave maria
  • axpergle
  • azorult
  • bangladesh
  • banker
  • beijing baidu
  • belarus
  • ben c
  • bitcoin
  • bladabindi
  • bodis
  • body
  • body length
  • bokbot
  • bq feb
  • brian sabey
  • briansabey
  • browserpassview
  • capture
  • cascade
  • cayman
  • cdata
  • certificate
  • chacha
  • chanitor
  • chaos
  • chatgpt
  • chrome
  • chthonic
  • ck id
  • class
  • click
  • cloudeye
  • cloudflarenet
  • cname
  • cobalt strike
  • cobaltstrike
  • code
  • collection
  • collections
  • com laude
  • command
  • command decode
  • communicating
  • compiler
  • contact
  • contacted
  • contacted ip
  • contacted urls
  • contentencoding
  • cookie
  • copy
  • core
  • country
  • create c
  • created
  • creation date
  • cridex
  • crimson
  • crimson rat
  • critical
  • critical risk
  • cryp
  • cryptbot
  • crysis
  • csc corporate
  • cus cnr3
  • cve201711882
  • cyber security
  • danabot
  • darkcomet
  • dark power
  • darkside
  • darpa
  • data
  • date
  • date hash
  • debug
  • default
  • delete c
  • desktop
  • detections file
  • dharma
  • digitaloceanasn
  • discord
  • dns intel
  • dns replication
  • dns resolutions
  • dnssec
  • dofoil
  • domain
  • domain http
  • domain robot
  • domains
  • downloadmr
  • dridex
  • dropped
  • dtrack
  • dunihi
  • dynadot
  • dynadot inc
  • dynamicloader
  • dyre
  • egregor
  • email
  • email document
  • emails
  • emotet
  • encrypt
  • entries
  • error
  • eternalblue
  • etisalat misr
  • et tor
  • et trojan
  • execution
  • expiro
  • exploit domain
  • falcon
  • falcon sandbox
  • fallout
  • false
  • fareit
  • february
  • file
  • files
  • file type
  • final url
  • find
  • findwindowa
  • first
  • flawedammy
  • flawedammyy
  • form
  • formbook
  • for privacy
  • friendly
  • gamehack
  • gandcrab
  • gandi sas
  • gecko
  • general
  • generator
  • germany unknown
  • getprocaddress
  • get response
  • glupteba
  • gmt cache
  • gmt connection
  • gmt contenttype
  • gnu linker
  • godaddy online
  • gootkit
  • gozi
  • group
  • guloader
  • hacking tools
  • hacktool
  • hallrender
  • hancitor
  • hashes
  • hashes c2ae
  • hawkeye
  • headers nel
  • header target
  • hermes
  • hidden cobra
  • high
  • highly targeted
  • high process
  • historical ssl
  • host interaction
  • hostname
  • hostnames
  • houdini
  • html
  • http
  • http method
  • http requests
  • http response
  • hunter
  • hunting macro
  • hworm
  • hybrid
  • icedid
  • icmp traffic
  • icons library
  • indicator
  • infected
  • info
  • info compiler
  • info header
  • injection
  • injection t1055
  • installer
  • intel
  • internal
  • internet se
  • ioc
  • iocs
  • ioc search
  • ionos se
  • ip address
  • ip detections
  • ips collection
  • ip traffic
  • ipv4
  • it consultant
  • january
  • javascript
  • jenxcus
  • jfif
  • jpeg image
  • june
  • kb body
  • key algorithm
  • key identifier
  • key info
  • keylogger
  • khtml
  • kill
  • killswitch
  • kimsuky
  • kit exploit
  • kld1063
  • known tor
  • less see
  • link library
  • loader
  • local
  • location canada
  • location united
  • lockbit
  • loki bot
  • lokibot
  • lookup wannacry
  • lowfi
  • low software
  • ltd dba
  • machine intel
  • macos
  • mailpassview
  • mailrubar
  • mailto
  • maldoc
  • malicious
  • malspam
  • malware
  • malware beacon
  • malware dns
  • malware hosting
  • march
  • mars
  • maxads0
  • maze
  • media center
  • media player
  • medium
  • mega
  • memory
  • memory pattern
  • memory scanning
  • meta
  • metro
  • mexico
  • mimikatz
  • mirai
  • mirai malware
  • mitre att
  • mitre attack
  • mozilla
  • msie
  • ms windows
  • mtb may
  • mtb oct
  • mtb showing
  • music
  • mutex
  • name
  • namecheap
  • namecheap inc
  • name md5
  • name server
  • name servers
  • name verdict
  • nanocore
  • nanocore rat
  • napoleon
  • nemty
  • netherlands asn
  • net technology
  • netwalker
  • netwire
  • network hijacks
  • neutrino
  • new ioc
  • next
  • Nextray
  • njrat
  • nuclear
  • number
  • nxdomain
  • observed dns
  • olet
  • ollydbg
  • open
  • orcus
  • orcus rat
  • organization
  • os2 executable
  • otx octoseek
  • overlay
  • owner exploit
  • packing t1045
  • panda banker
  • parent domain
  • parent referrer
  • passive dns
  • paste
  • path
  • pattern
  • pattern domains
  • pattern match
  • pattern urls
  • pdb path
  • pe32
  • pe32 linker
  • pegasus
  • pe section
  • phishing
  • phobos
  • pictures
  • pinkslipbot
  • playgame
  • play ransomware
  • point
  • poisonivy
  • polish
  • pony
  • possible
  • postal code
  • powershell
  • precondition
  • predator
  • predator pain
  • privacy
  • privacy admin
  • privacy service
  • privacy tech
  • products
  • programfiles
  • prynt
  • prynt stealer
  • psexec
  • psiusa
  • pt mora
  • pty ltd
  • public folder
  • pulse pulses
  • push
  • qakbot
  • qbot
  • quasar
  • quasar rat
  • query
  • raccoon
  • racealer
  • ransom
  • ransomexx
  • ransomware
  • rats
  • rdds service
  • read c
  • recent blog
  • record
  • record type
  • record value
  • redacted for
  • redline
  • redline stealer
  • referrer
  • regbinary
  • regdword
  • region create
  • region update
  • registrant
  • registrant name
  • registrar
  • registrar abuse
  • regsetvalueexa
  • related nids
  • remcos
  • reports
  • request
  • resolutions
  • revenge
  • revenge rat
  • reverse dns
  • revil
  • rostpay
  • roundup
  • r processes
  • ryuk
  • ryuk ransomware
  • sabey type
  • samplepath
  • samples
  • scan endpoints
  • scarimson
  • screen
  • screenshot
  • script
  • search
  • searchmeup
  • sections
  • seen
  • september
  • server
  • servers
  • servhelper
  • service
  • serving ip
  • shadow
  • shell code
  • shell commands
  • show
  • showing
  • show technique
  • siblings
  • simda
  • sinkhole cookie
  • siplog
  • skynet
  • slcc2
  • smokeldr
  • smoke loader
  • smokeloader
  • snake
  • sockrat
  • sodinokibi
  • source file
  • spelevo
  • spyware
  • squirrelwaffle
  • ssl certificate
  • startpage
  • stateprovince
  • status
  • status code
  • sticky
  • strings
  • subject public
  • submitters
  • superwebbysearch
  • suricata ipv4
  • susp
  • suspicious
  • suspicous ip
  • systembc
  • t1055
  • tablet
  • teams api
  • teamspy
  • teamviewer
  • tech contact
  • technical city
  • template
  • terdot
  • thief
  • threat
  • threat analyzer
  • threat roundup
  • threats
  • tracker
  • tracking
  • track them
  • tree
  • trickbot
  • trident
  • trojan
  • trojanclicker
  • trojanspy
  • troldesh
  • tsara brashears
  • ttl value
  • tulach
  • twitter
  • uk collection
  • ukraine
  • unique
  • united
  • united kingdom
  • univjos
  • unknown
  • unlocker
  • url http
  • url https
  • urls
  • urlshortner dec
  • urlshortner sep
  • urls http
  • urls https
  • urls url
  • ursnif
  • utc entry
  • utc submissions
  • v3 serial
  • value snkz
  • vawtrak
  • vidar
  • videos
  • virtool
  • virustotal
  • vs2008
  • vs2008 sp1
  • vs2010
  • wannacry
  • wcry ransomware
  • webtoolbar
  • whitelisted
  • whois
  • whois file
  • whois lookup
  • whois record
  • whois service
  • whois sslcert
  • whois whois
  • win16 ne
  • win32
  • win32 dynamic
  • win32 exe
  • win32pcmega jan
  • win32upatre may
  • win64
  • windigo
  • windir
  • windows nt
  • winrar
  • withheld
  • worm
  • wow64
  • write
  • write c
  • x8bxe5
  • xor ddos
  • xorddos
  • xpire.info
  • xtremerat
  • yara detections
  • yara rule
  • youth
  • zbot
  • zenbox
  • zeppelin
  • zloader

MITRE ATT&CK TTPs

  • T1012 - Query Registry
  • T1027 - Obfuscated Files or Information
  • T1031 - Modify Existing Service
  • T1033 - System Owner/User Discovery
  • T1036 - Masquerading
  • T1040 - Network Sniffing
  • T1045 - Software Packing
  • T1047 - Windows Management Instrumentation
  • T1053 - Scheduled Task/Job
  • T1055 - Process Injection
  • T1056 - Input Capture
  • T1057 - Process Discovery
  • T1059 - Command and Scripting Interpreter
  • T1060 - Registry Run Keys / Startup Folder
  • T1063 - Security Software Discovery
  • T1070 - Indicator Removal on Host
  • T1071 - Application Layer Protocol
  • T1074 - Data Staged
  • T1082 - System Information Discovery
  • T1100 - Web Shell
  • T1105 - Ingress Tool Transfer
  • T1106 - Native API
  • T1107 - File Deletion
  • T1112 - Modify Registry
  • T1114 - Email Collection
  • T1119 - Automated Collection
  • T1129 - Shared Modules
  • T1132 - Data Encoding
  • T1140 - Deobfuscate/Decode Files or Information
  • T1155 - AppleScript
  • T1218 - Signed Binary Proxy Execution
  • T1220 - XSL Script Processing
  • T1449 - Exploit SS7 to Redirect Phone Calls/SMS
  • T1518 - Software Discovery
  • T1560 - Archive Collected Data
  • T1563 - Remote Service Session Hijacking
  • T1564 - Hide Artifacts
  • T1566 - Phishing
  • T1583.005 - Botnet
  • T1614 - System Location Discovery
  • TA0003 - Persistence
  • TA0004 - Privilege Escalation
  • TA0005 - Defense Evasion
  • TA0006 - Credential Access
  • TA0007 - Discovery
  • TA0009 - Collection
  • TA0011 - Command and Control
  • TA0034 - Impact
  • TA0040 - Impact

Passive DNS

  • fresbo.eu

Attack Log References