2.0.1.4 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 2.0.1.4 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

🔴 High Risk — 79/100

Geographic Location

Host and Network Information

Tags

  • 10357
  • agent tesla
  • anchor hrefs
  • android
  • ascii text
  • atkafij0
  • axelo
  • breached
  • city
  • com laude
  • communicating
  • contacted
  • contacted urls
  • copy
  • create c
  • csc corporate
  • delete c
  • del f
  • detections type
  • discovery
  • discovery t1057
  • dock
  • domain name
  • domain robot
  • domains
  • dynadot inc
  • dynamicloader
  • execution
  • files
  • file size
  • first
  • flashpix
  • gandi sas
  • gang breached
  • high
  • highest f
  • historical ssl
  • html info
  • html internet
  • iana
  • iana ref
  • iana special
  • installer
  • intel
  • internet
  • ipv4 prefix
  • javascript
  • keysystems gmbh
  • kgs0
  • khtml
  • kls0
  • linux x8664
  • los angeles
  • magic html
  • magika html
  • malibot
  • medium
  • memcommit
  • memreserve
  • metro
  • minute tr
  • ms windows
  • name
  • net108
  • net1080000
  • net192
  • net1920000
  • nethandle
  • netrange
  • network pty
  • next
  • november
  • orgabusehandle
  • orgabusephone
  • orgdnshandle
  • orgdnsref
  • orgid
  • orgtechhandle
  • orgtechref
  • pe32
  • persistence
  • porkbun llc
  • prefix
  • process32nextw
  • psiusa
  • ransomware gang
  • read c
  • redline stealer
  • red team
  • referrer
  • regdword
  • regopenkeyexw
  • regsetvalueexa
  • runresdll
  • script tags
  • search
  • sha256
  • shared address
  • show
  • space
  • space meta
  • ssdeep
  • ssl certificate
  • start
  • submitters
  • t1045
  • t1057
  • tags
  • team
  • template
  • threat roundup
  • title rfc
  • trojan
  • tucows
  • united
  • unknown
  • urls http
  • urls url
  • utc submissions
  • vhash
  • whois lookup
  • whois record
  • whois whois
  • win32
  • win32 exe
  • write
  • write c
  • writeconsolea
  • yara detections
  • yara rule

MITRE ATT&CK TTPs

  • T1003 - OS Credential Dumping
  • T1005 - Data from Local System
  • T1012 - Query Registry
  • T1040 - Network Sniffing
  • T1045 - Software Packing
  • T1053 - Scheduled Task/Job
  • T1055 - Process Injection
  • T1057 - Process Discovery
  • T1060 - Registry Run Keys / Startup Folder
  • T1070 - Indicator Removal on Host
  • T1071 - Application Layer Protocol
  • T1081 - Credentials in Files
  • T1082 - System Information Discovery
  • T1112 - Modify Registry
  • T1119 - Automated Collection
  • T1129 - Shared Modules
  • T1143 - Hidden Window

Attack Log References