2.1.1.4 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 2.1.1.4 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

🔴 High Risk — 77/100

Geographic Location

Host and Network Information

Tags

  • a block
  • a boolean
  • abstract
  • abstract may
  • abstract must
  • a byte
  • access
  • account
  • acl account
  • addhandler
  • addtype
  • advanced server
  • a facility
  • afinet
  • afinet6
  • agent
  • a handler
  • aiff
  • aishah lazim
  • alias error
  • alive
  • allow
  • almost
  • apache
  • apache version
  • apiavailable
  • apiunavailable
  • apple
  • apple computer
  • april
  • argus
  • aris
  • articles faqs
  • ascii
  • assistant
  • a string
  • attcertpath
  • attribute
  • audio
  • authkey
  • authtype
  • auto exit
  • auxiliary
  • auxiliary may
  • auxiliary must
  • base dcexample
  • bashno
  • batchmode
  • bcgjnuwz
  • berkeley
  • beware
  • bindash binksh
  • bin sbin
  • binsh bintcsh
  • bin usrsbin
  • blank
  • bol
  • bonjour service
  • bool
  • bridge
  • bssid
  • bundle
  • calendar
  • calls
  • ca message
  • care
  • category
  • change
  • chaos
  • checkhostip
  • ciphers
  • cisco
  • claim
  • class
  • click
  • clocal mode
  • close
  • coast
  • code
  • co l
  • co llective
  • collective
  • column
  • commands
  • common setup
  • computername
  • config
  • configure
  • const
  • contact
  • control access
  • copyright
  • corba
  • corba object
  • cosine pilot
  • crunch
  • crypt
  • cups
  • cups scheduler
  • customlog
  • customs
  • customs data
  • cyrus
  • daemon
  • daniel quinlan
  • default
  • default pf
  • default require
  • default user
  • define
  • definitions
  • demand
  • deref
  • d esc
  • de sc
  • des c
  • desc
  • desc account
  • desc mount
  • desc password
  • desc pool
  • desktop
  • destination
  • devnull
  • direct
  • directory
  • directory forum
  • directoryindex
  • discussion
  • dns hostname
  • dns protocol
  • dns proxy
  • dns query
  • dns resolution
  • dns server
  • dns traffic
  • documentroot
  • dovecot
  • duas
  • dynamic group
  • encapsulation
  • enforce
  • enterprise
  • entry
  • equal ity
  • equality
  • errordocument
  • errorhttp
  • errorlog
  • every
  • example
  • example share
  • facility
  • fallback
  • false
  • fcodes
  • file
  • filesystems
  • fips
  • first
  • fixed speed
  • flags
  • form
  • format
  • formats
  • for production
  • forwardagent
  • forwardx11
  • fraud
  • freebsd
  • freeze
  • ftpd
  • function
  • gate daemon
  • generic
  • greg roelofs
  • group database
  • group lp
  • groups
  • group value
  • guangzhou five
  • guest
  • guid
  • header
  • hellman group
  • high
  • hold
  • host
  • host database
  • hostkey
  • hosts
  • hotspot
  • hotspothelper
  • html
  • http
  • httpcookie
  • icmp
  • identityfile
  • id key
  • ifdefine
  • ifmodule
  • ike session
  • ike version
  • import data
  • importgenius
  • importkey
  • import records
  • include
  • indexed
  • inetorgperson
  • info
  • initialize
  • inpck
  • interface
  • internet
  • internetdrafts
  • ip address
  • ipnetmasknumber
  • ip network
  • ipsec endpoint
  • ipsec server
  • ipv4
  • ipv4 subnet
  • ipv6
  • ip version
  • isis
  • jabber
  • java
  • java class
  • java object
  • jndi
  • jndi reference
  • kame
  • kdc schema
  • keepalive
  • kerberos
  • kerberos v
  • kernel
  • kexalgorithms
  • kind
  • ldap
  • ldap defaults
  • ldap directory
  • ldap entry
  • ldap server
  • ldif
  • learn
  • level
  • level error
  • license
  • limit
  • line
  • linus walleij
  • linux
  • list
  • listen
  • listenaddress
  • loadfile c
  • loadmodule
  • localnetbootdir
  • localonly
  • location
  • lpadmin
  • lte network
  • m1460
  • m265
  • macos
  • macos x
  • macs
  • magic
  • main
  • maker
  • manlocale
  • manpager
  • manpath
  • manpath optman
  • mark
  • matches for
  • match syntax
  • maximum number
  • maxsparethreads
  • maybe
  • may contain
  • may description
  • message
  • message mc
  • message secure
  • message sep
  • method
  • microsoft
  • mime type
  • mind
  • minsparethreads
  • modp
  • monitoring
  • mpms
  • multi
  • multitouchhid
  • music
  • must
  • must contain
  • mutex file
  • name
  • name contact
  • name domaindns
  • name group
  • name leaf
  • name managedby
  • name samdomain
  • neappproxyflow
  • neapprule
  • neapprule api
  • necopynullable
  • nednsprotocol
  • nednssettings
  • nefilteraction
  • nefilterflow
  • nefiltermanager
  • nefilterreport
  • nefilterrule
  • nefilterverdict
  • neflowmetadata
  • nehotspothelper
  • neindirect
  • neipv4route
  • neipv6route
  • nenetworkrule
  • neondemandrule
  • nepacket
  • nepacket object
  • neprovider
  • neproxyserver
  • neproxysettings
  • nerelay
  • nerelay class
  • nerelaymanager
  • netapi
  • netboot
  • netbootmount
  • netbootshadow
  • netinfo
  • netinfo preset
  • netinfo rpcs
  • netlicense
  • netscape
  • network
  • networkd
  • networkonly
  • networkup
  • nevpnexport
  • nevpnmanager
  • nevpnprotocol
  • nmap syn
  • nnnbaud
  • nonnull
  • notice
  • not recommended
  • nroff
  • nsarray
  • nsdata
  • nsdictionary
  • nsenum
  • nserror
  • nserror object
  • nsinteger
  • nsnumber
  • nsnumber object
  • nsstring
  • nsuinteger
  • nsurlsession
  • number
  • nwendpoint
  • nwendpointh
  • nwhostendpoint
  • nwhostendpointh
  • nwpath
  • nwpathh
  • nwpathstatus
  • nwtcpconnection
  • nwtlsparameters
  • nwudpsession
  • objectclass
  • obsolete
  • ocsp stapling
  • oid base
  • oncrpcnumber
  • open
  • openbsd
  • open directory
  • openldap
  • openldap note
  • openldaporg
  • openldapou
  • openldaproot
  • openssh
  • openssl
  • opera
  • optionspropfind
  • order deny
  • owner
  • panjiva
  • param
  • parenb istrip
  • parity
  • pass8
  • passwd
  • password policy
  • path
  • pathbin
  • paths
  • pathusrbin
  • pc entry
  • permittty
  • pfinet
  • pidfile
  • pkcs
  • please
  • port
  • postfix
  • postfix scsd
  • postscript
  • prior
  • prng
  • project
  • property
  • propertysetguid
  • propfind
  • protocol
  • proxyhtmllinks
  • prunedirs
  • prunepaths
  • public license
  • purpose
  • push
  • quality
  • rangelower
  • rangeupper
  • read
  • redistribution
  • refer
  • requestmethod
  • requesturi
  • require
  • require user
  • reserved
  • restrict access
  • r etcbashrc
  • return
  • returnpath via
  • returns yes
  • rewritecond
  • rewriteengine
  • rewriterule
  • rfc1274
  • rfc1323
  • rfc2252
  • rfc2307
  • rfc2798
  • rolesyntax
  • rpcs number
  • rpcsrc
  • rsvp
  • rule
  • samba server
  • sbin
  • scam
  • schema
  • schema mapping
  • searchpaths
  • security
  • see also
  • sender
  • server
  • serveradmin
  • servername
  • serverroot
  • serversignature
  • service
  • set command
  • shall not
  • sharing
  • signature
  • signeddata
  • singlevalue
  • sitewide
  • six technology
  • size
  • sizelimit
  • smb2
  • smb3
  • smime
  • spaces
  • specification
  • specify
  • springboard
  • ssh algorithms
  • ssid
  • ssl engine
  • ssl handshake
  • sslrandomseed
  • sslrequire
  • sslsessioncache
  • ssltls standard
  • standalone
  • startservers
  • status mailfrom
  • store
  • structural
  • structural may
  • structural must
  • subclass
  • subclass of
  • substr caseigno
  • sunnet manager
  • sup container
  • sup ipsecbase
  • sup name
  • sup person
  • sup rpcentry
  • synack
  • synconclose no
  • syntax
  • system
  • systemonly
  • tcp port
  • template
  • term
  • this
  • threadid
  • threadsperchild
  • threadstacksize
  • tiff
  • tiger
  • time
  • timelimit
  • tls client
  • tmpdir
  • touch id
  • trade data
  • triad
  • troff
  • true
  • tun interface
  • typedef
  • udp session
  • udp traffic
  • uncomment
  • unicode
  • unix
  • unix copy
  • unknown
  • uri ldap
  • use diffie
  • use kvo
  • user
  • user database
  • userdir
  • userdir sites
  • usereventagent
  • userlogdir
  • user lp
  • useruuid
  • usrbin usrsbin
  • uucp port
  • vartmp
  • virtualhost
  • virtualhost 80
  • vpn connection
  • vpn server
  • vpn socket
  • vpn tunnel
  • w3c html
  • waiting
  • warp
  • wave
  • webdav
  • webdavclient
  • webdav file
  • wfsserveraddr
  • wfsservername
  • wfsserverport
  • whatispager
  • wifi network
  • win32
  • windows
  • windows sp1
  • with syntax
  • workgroup
  • write
  • xhtml xht
  • xlam
  • xlc xlt
  • xlm xla
  • xlsb
  • xlsm
  • xltm
  • xp sp1
  • yourincludepath
  • z7 z8

MITRE ATT&CK TTPs

  • T1037.002 - Logon Script (Mac)
  • T1038 - DLL Search Order Hijacking
  • T1048.002 - Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
  • T1048.003 - Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • T1059.001 - PowerShell
  • T1059.007 - JavaScript
  • T1068 - Exploitation for Privilege Escalation
  • T1069.001 - Local Groups
  • T1071 - Application Layer Protocol
  • T1147 - Hidden Users
  • T1158 - Hidden Files and Directories
  • T1184 - SSH Hijacking
  • T1210 - Exploitation of Remote Services
  • T1211 - Exploitation for Defense Evasion
  • T1222.002 - Linux and Mac File and Directory Permissions Modification
  • T1449 - Exploit SS7 to Redirect Phone Calls/SMS
  • T1557 - Man-in-the-Middle
  • T1562.004 - Disable or Modify System Firewall
  • T1564.005 - Hidden File System
  • T1568.001 - Fast Flux DNS
  • T1596.001 - DNS/Passive DNS
  • TA0029 - Privilege Escalation

Passive DNS

  • 8533a.com

Attack Log References