198.12.145.214 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 198.12.145.214 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Likely Malicious Host 🟠 57/100

Host and Network Information

  • Mitre ATT&CK IDs: T1012 - Query Registry, T1027 - Obfuscated Files or Information, T1036.004 - Masquerade Task or Service, T1040 - Network Sniffing, T1041 - Exfiltration Over C2 Channel, T1043 - Commonly Used Port, T1045 - Software Packing, T1055 - Process Injection, T1056.001 - Keylogging, T1056 - Input Capture, T1057 - Process Discovery, T1059.006 - Python, T1059.007 - JavaScript, T1059 - Command and Scripting Interpreter, T1060 - Registry Run Keys / Startup Folder, T1068 - Exploitation for Privilege Escalation, T1071.001 - Web Protocols, T1071.004 - DNS, T1071 - Application Layer Protocol, T1100 - Web Shell, T1102 - Web Service, T1105 - Ingress Tool Transfer, T1110.002 - Password Cracking, T1112 - Modify Registry, T1114.001 - Local Email Collection, T1114 - Email Collection, T1129 - Shared Modules, T1140 - Deobfuscate/Decode Files or Information, T1143 - Hidden Window, T1176 - Browser Extensions, T1179 - Hooking, T1185 - Man in the Browser, T1204.001 - Malicious Link, T1204.002 - Malicious File, T1204.003 - Malicious Image, T1447 - Delete Device Data, T1449 - Exploit SS7 to Redirect Phone Calls/SMS, T1457 - Malicious Media Content, T1496 - Resource Hijacking, T1497 - Virtualization/Sandbox Evasion, T1512 - Capture Camera, T1523 - Evade Analysis Environment, T1560 - Archive Collected Data, T1566 - Phishing, T1568.002 - Domain Generation Algorithms, T1568 - Dynamic Resolution, T1578.003 - Delete Cloud Instance, T1583.001 - Domains, T1583.005 - Botnet, T1583 - Acquire Infrastructure, T1588.001 - Malware, T1610 - Deploy Container

  • Tags: 114.114.114.114, abuse, accept, accept encoding, acint, active related, adaptivebee, added active, address, adload, admin city, a domains, adult content, advisory, adware, adwaresig, aes256gcm, agent, agent tesla, agenttesla, akamaias, alexa, alexa top, algorithm, all octoseek, all scoreblue, all search, amazon02, android, api blog, apnic, apnic whois, apollo, appdata, apple, apple hacking, apple ios, apple phone, applicunwnt, artemis, articles, as26710 icann, as396982 google, as44273 host, as54113, ascii text, asia pacific, asn16509, asyncrat, attack, attacker, attorney, august, author avatar, aws, azorult, babar, back, bandoo, bank, banker, banking, bazaloader, b body, beach research, behav, benjamin, bhagam bhag, binder, bitminer, bits, blackievirus.com, blacklist, blacklist http, blacklist https, bladabindi, blister, blockchain, body, body length, bomb, boost mobile, botnetwork, br, bradesco, brian, brian sabey, brochure url, brontok, business, button, bypass, c2, C2, c2ae, c2 raccoon, cachecontrol, chase personal, checkin, child pornographer, china cobalt, china telecom, cisco umbrella, citadel, civicalg, civicalg.com, ck id, ck matrix, cl0p, class, cleaner, click, close, cloudflare, cloudflarenet, cname, CNC, cnc feodo, cnc server, cnnic, cobalt strike, code, collections, colorado, column, com laude, command decode, common upatre, communicating, company limited, compromised websites, computer, comspec, conduit, connection, contact, contacted, contacted urls, control server, cookie, cookie bot, copy, copyright, core, count blacklist, country, covid19, covid19 scam, crack, create c, createdate, create new, creation date, creation_of_an_executable_by_an_executable, critical, critical risk, cryptinject, csc corporate, cus olet, cutwail, cve201711882, cybercrime, cyber harassment, cyberstalking, cyber threat, daisy, daisy coleman, dapato, data, datalayer, date, death threats, december, deepscan, defacement, default, de indicators, detection list, detections type, detplock, dev, developer, digicert global, dirtsearch, district, div div, divergent, dllinject, dns, dnspionage, dns replication, dns resolutions, dock, docs pricing, domain, domains, domain status, downer, downldr, download, download csv, downloader, download json, driverpack, dropper, elf collection, emails, emotet, enablement, encpk, encrypt, encrypt cnr11, engineering, entries, error, et tor, excel, execution, exit, expiration, expiration date, expiry, exploit, exploitation, explore, facebook, facebook link, failed_code_integrity_checks, fakealert, fakeinstaller, falcon sandbox, false, fareit, february, feodo, figma, file, filehash, filerepmalware, files, filetour, final url, find, firehol, first, floxif, footer, form, format, formbook, formbook cnc, found, fraud service, freemake, fri jun, fusioncore, g2 tls, g5nxq655fgp, gecko, general, general full, generator, generic, generic malware, genkryptik, genpack, get h2, get http, get updates, ghost rat, github pages, glupteba, gmbh version, gmt content, google, gopher, government relations, grafana labs, graph community, gti9080l, gti9128v, gti9158, gvt google video transcoding, hackers, hacktool, hall law, hall render, hallrender, hallrender.com, hallrender.com/attorney/brian-sabey, hall render denver, hash, hashes, headers, headers age, heodo, heur, high, highly targeted, hijacking, historical ssl, hit, hiv, home screen, honey client, host, hostname, hostnames, hsbc, html, html info, http, http header, http host, http response, https, huge domains, hybrid, icann whois, identity_helper.exe, iframe, ii llc, impressum, indicator, indicator role, indonesia, information, injector, inmortal, innova co, input, installcore, installer, installpack, iobit, iocs, ip address, ip check, iphone unlocker, ip summary, ipv4, java, javascript, jfif standard, jpeg image, json ip, json sample, jul jan, june, kb body, keygen, key identifier, keylogger, kgs0, khtml, kls0, known infection source, known tor, kraddare, kyriazhs1975, label, laplasclipper, law, learn, learn more, legal, legend, level3, life, linkedin, linkedin link, linkid252669, link url, loadmoney, local, login, lovgate, lowfi, lsmeta function, lsoldgsqueue, ltd dba, lumma stealer, macros sneaky, magazine, main, malicious, malicious host, malicious site, malicious url, maltiverse, malvertizing, malware, malware generic, malware host, malware hosting, malware service, malware site, malware sites, man, march, mark, mark brian sabey, mas, matsnu, mb iesettings, mb opera, mb qimage, mb setup, mb super, media, mediaget, mediamagnet, media sharing, memscan, men, meta, metastealer, meterpreter, metro, metro t-mobile, mgeinteg, michelle, microsoft, mile high media, million, mimikatz, miner, mirai, misc attack, missouri, mitre att, model, modernizr, module load, mo.gov, monitoring, moved, msil, mtb feb, mtb jan, name, namecheap inc, name servers, name value, name verdict, nanjing, nanocore, nanocore rat, networm, next, nircmd, njrat, no data, node tcp, node udp, no expiration, noname057, nora, notepad, nsis, number, nymaim, occamy, offercore, office open, ogilvy, open, opencandy, optimizer, organization, org log, org meta, org og, org twitter, orkut, otx octoseek, outbreak, parking crew, passive dns, paste, patcher, path, pattern match, paypal, persistence, phish, phishing, phishing chase, phishing google, phishing site, phishtank, pixel, please, pony, porkbun llc, possible, postal code, post http, powershell_create_scheduled, pragma, predator, premium, presenoker, privacy admin, probe, project, protocol h2, proxy, psexec, pulse pulses, pulses, pulses url, pykspa, python_initiated-connection, qakbot, qbot, q https, qiwi hack, quasar, quasar rat, raccoon, radar ineractive, ramnit, ransomexx, ransomware, read c, real estate, record value, redacted for, redirector, redline, redline stealer, referrer, regdword, registrar, registrar abuse, regsetvalueexa, relacionada, related pulses, relayrouter, remcos, remote procedure call, render, replacement, report spam, resolutions, resolved ips, resource, reverse dns, right person, riskware, rms, role title, romeo scheme, rsa sha256, runescape, runtime process, sabey, sabey data centers, safebae, safebae.org, safe site, sality, sample, samples, scan endpoints, script, script domains, script urls, search, search live, secrisk, security, security tls, select xmp, seraph, server, servers, service, service privacy, services, serving ip, setup stub, sha1, sha256, shell, show, showing, show technique, sign, simda, site, site safe, site top, smokeloader, sneaky server, soc http, soc https, social engineering, softonic, software, sonbokli, spammer, span, spyrixkeylogger, spyware, squirrelwaffle, sreredrum, ssl certificate, stalker, start, startpage, stateprovince, status, status code, status page, stealer, steam route, strike, strings, subdomains, subject public, submitters, summary, summary iocs, suppobox, suricata ipv4, suricata udpv4, suspected, suspicious, swrort, systweak, tag count, tag manager, tags viewport, tag tag, target, targeting, tcp traffic, team, team malware, team phishing, technology, telefonica, telefonica co, temp, the org, this, threat, threat report, threat roundup, threats et, thu aug, tiggre, title, title added, title bhagam, tld count, t-mobile, tofsee, tool, tor exit, tor known, tor relayrouter, tracker, tracker malware, traffic, trojan, trojanspy, trojanx, TrojanX, tsara brashears, ttl value, tue dec, tulach, tulach.cc, twitter, ua71173394, ubot, ultimate, unauthorized, union, united, unknown, unlocker, unruy, unsafe, upatre, update checker, url http, url https, urls, urls https, url summary, utc google, utc submissions, uztuby, v3 serial, validity, value, variables, verisign, veryhigh, vidar, virus network, virustotal, virut, visa scheme, vitzo, wacatac, wannacry kill, webshell, webtoolbar, whois database, whois parent, whois record, whois sslcert, whois whois, win32, win32 exe, win32.pdf.alien, win64, window, windows nt, wininit, woman, worm, write, write c, x509v3 subject, xml document, xrat, xtrat, yandex dropper extend, yara rule, yixun, youtube video, zbot, zeus, zpevdo

  • View other sources: Spamhaus VirusTotal

Open Ports Detected

2052 2053 2082 2083 2086 2087 2095 443 80 8080 8443 8880

Map

Whois Information

Links to attack logs

****** ****** ******

Share on: