198.54.117.242 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 198.54.117.242 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

🟠 Elevated — 60/100

Geographic Location

Host and Network Information

  • View other sources: Spamhaus VirusTotal Shodan AbuseIPDB
  • Country: United States
  • Noticed: 21 times
  • Protocols Attacked: SSH
  • Open Ports: 80
  • Tor Node: No
  • Associated Malware Samples: 16

Tags

  • address
  • aes256gcm
  • agenttesla
  • agentteslaexe
  • akamai
  • algorithm
  • amadey
  • amazon02
  • americachicago
  • am utc
  • appdata
  • april
  • apt38
  • arkeistealer
  • as213702
  • asn16509
  • asn as16509
  • atx dcit
  • august
  • authority key
  • azorult
  • azorultexe
  • b body
  • b document
  • bluenoroff
  • bluenoroffapt38
  • body
  • body length
  • cdns
  • certificate
  • certua
  • chrome
  • clickonce
  • cloudflare
  • comment
  • config
  • confucius
  • covenant
  • creation date
  • ctf ctf
  • cus cnlet
  • danabot
  • darkrat
  • data upload
  • date
  • date checked
  • domain
  • domain related
  • domains show
  • dridex
  • dridexopendir
  • ecdsa
  • emotetheodo
  • encrypt
  • enom
  • enter s
  • enter sc
  • enter soudse
  • entries
  • entries related
  • exclude
  • exclude data
  • exclude sugges
  • extr
  • extra
  • extrac please
  • extraction
  • extraction data
  • extra data
  • extre amanuav
  • extri data
  • failed
  • february
  • filel
  • filel data
  • files ip
  • find
  • find s
  • formbook
  • gandcrab
  • gecko
  • general full
  • gozi
  • graph summary
  • hancitor
  • hawkeye
  • hdi ad
  • headers
  • heodo
  • http
  • hunter
  • icedid
  • identifier id
  • idrsa
  • idrsa r
  • include
  • include review
  • indicaton
  • indicator
  • indiicatun data
  • IOCs
  • ips spread
  • issuer
  • january
  • june
  • key identifier
  • key info
  • khtml
  • kimsuky
  • kpot
  • kpotstealer
  • lazarus
  • linux x8664
  • loader
  • location united
  • loki
  • luminositylink
  • lumma
  • lumma infection
  • Malware
  • manuany browse
  • media
  • metasploit
  • moved
  • msie
  • nanocore
  • nemty
  • netwire
  • next associated
  • nop exec
  • number
  • october
  • onv incmde
  • orpcbackdoor
  • passive dns
  • phishing
  • Phishing
  • phorpiex
  • pm utc
  • pony
  • post body
  • present jul
  • present jun
  • present oct
  • present sep
  • primary request
  • protocol h2
  • qakbot
  • qealler
  • quasarrat
  • raccoonstealer
  • rain
  • ransomware
  • record value
  • redirect chain
  • remcos
  • remcosrat
  • resource hash
  • reverse dns
  • review
  • review exclude
  • review locs
  • sc data
  • sc type
  • search
  • security tls
  • september
  • server response
  • servhelper
  • sha256
  • shodan
  • showing
  • software
  • stealer
  • stop
  • stop typ
  • subject public
  • sugges
  • suggested
  • suggested ocs
  • swift
  • systembc
  • telegram
  • tewdac
  • Threat Feed
  • thumbprint
  • trickbot
  • troldesh
  • type
  • type mimetype
  • typ no
  • ubuntu
  • united
  • uny inuuue
  • url hostname
  • url https
  • urls
  • urls show
  • v3 serial
  • verified
  • veryhigh
  • vidar
  • virustotal
  • vt api
  • x3 olet
  • x509v3 subject
  • zloader

MITRE ATT&CK TTPs

  • T1027 - Obfuscated Files or Information
  • T1041 - Exfiltration Over C2 Channel
  • T1059 - Command and Scripting Interpreter
  • T1071.001 - Web Protocols
  • T1071.004 - DNS
  • T1078 - Valid Accounts
  • T1090.002 - External Proxy
  • T1095 - Non-Application Layer Protocol
  • T1105 - Ingress Tool Transfer
  • T1204.002 - Malicious File
  • T1486 - Data Encrypted for Impact
  • T1490 - Inhibit System Recovery
  • T1547 - Boot or Logon Autostart Execution
  • T1550.002 - Pass the Hash
  • T1555 - Credentials from Password Stores
  • T1557 - Man-in-the-Middle
  • T1566.001 - Spearphishing Attachment
  • T1583.003 - Virtual Private Server

Passive DNS

  • hxsyidf.xyz

Attack Log References

Whois Information

NetRange: 198.54.112.0 - 198.54.127.255 CIDR: 198.54.112.0/20 NetName: NAMEC-4 NetHandle: NET-198-54-112-0-1 Parent: NET198 (NET-198-0-0-0-0) NetType: Direct Allocation OriginAS: Organization: Namecheap, Inc. (NAMEC-4) RegDate: 2015-11-13 Updated: 2015-11-13 Ref: https://rdap.arin.net/registry/ip/198.54.112.0 OrgName: Namecheap, Inc. OrgId: NAMEC-4 Address: 11400 W. Olympic Blvd. Suite 200 City: Los Angeles StateProv: CA PostalCode: 90064 Country: US RegDate: 2011-01-28 Updated: 2024-11-25 Ref: https://rdap.arin.net/registry/entity/NAMEC-4 OrgAbuseHandle: ABUSE2885-ARIN OrgAbuseName: Abuse team OrgAbusePhone: +1-323-375-2822 OrgAbuseEmail: abuse@namecheaphosting.com OrgAbuseRef: https://rdap.arin.net/registry/entity/ABUSE2885-ARIN OrgTechHandle: TECHT4-ARIN OrgTechName: Tech team OrgTechPhone: +1-661-310-2107 OrgTechEmail: tech@namecheaphosting.com OrgTechRef: https://rdap.arin.net/registry/entity/TECHT4-ARIN OrgTechHandle: EFIME-ARIN OrgTechName: Efimenko, Igor OrgTechPhone: +1-323-375-2822 OrgTechEmail: igor.e@namecheap.com OrgTechRef: https://rdap.arin.net/registry/entity/EFIME-ARIN network:Class-Name:network network:Auth-Area:198.54.117.0/24 network:ID:NET-79086.198.54.117.0/24 network:Network-Name:anycast-edge-fwd-range network:IP-Network:198.54.117.0/24 network:IP-Network-Block:198.54.117.0 - 198.54.117.255 network:Org-Name:Web-hosting.com network:Street-Address: network:City:Atlanta network:State:GA network:Postal-Code:30303/3030 network:Country-Code:US network:Tech-Contact:MAINT-79086.198.54.117.0/24 network:Created:20190523133801000 network:Updated:20190523163010000 network:Updated-By:net-admin@namecheap.com contact:POC-Name:Network team contact:POC-Email:net-admin@namecheap.com contact:POC-Phone: contact:Tech-Name:Network team contact:Tech-Email:net-admin@namecheap.com contact:Tech-Phone: contact:Abuse-Name:Abuse team contact:Abuse-Email:abuse@namecheaphosting.com