3.134.39.220 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 3.134.39.220 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Likely Malicious Host 🟠 60/100

Host and Network Information

  • Mitre ATT&CK IDs: T1003.008 - /etc/passwd and /etc/shadow, T1012 - Query Registry, T1027 - Obfuscated Files or Information, T1029 - Scheduled Transfer, T1041 - Exfiltration Over C2 Channel, T1043 - Commonly Used Port, T1055 - Process Injection, T1056.001 - Keylogging, T1056 - Input Capture, T1059 - Command and Scripting Interpreter, T1060 - Registry Run Keys / Startup Folder, T1068 - Exploitation for Privilege Escalation, T1071.001 - Web Protocols, T1071.002 - File Transfer Protocols, T1071.004 - DNS, T1071 - Application Layer Protocol, T1088 - Bypass User Account Control, T1095 - Non-Application Layer Protocol, T1100 - Web Shell, T1105 - Ingress Tool Transfer, T1110.002 - Password Cracking, T1112 - Modify Registry, T1114 - Email Collection, T1129 - Shared Modules, T1140 - Deobfuscate/Decode Files or Information, T1176 - Browser Extensions, T1179 - Hooking, T1183 - Image File Execution Options Injection, T1449 - Exploit SS7 to Redirect Phone Calls/SMS, T1496 - Resource Hijacking, T1497 - Virtualization/Sandbox Evasion, T1560 - Archive Collected Data, T1583 - Acquire Infrastructure, TA0002 - Execution, TA0003 - Persistence, TA0004 - Privilege Escalation, TA0005 - Defense Evasion, TA0006 - Credential Access, TA0007 - Discovery, TA0009 - Collection

  • Tags: aaaa, abuse, accept, access, acint, active related, active threats, added active, address, adload, a domains, advisory, adware, adwaresig, aes256gcm, agent, agent tesla, agenttesla, akamaias, akamaiasn1, alexa, alexa top, all octoseek, all search, amazon02, android, api blog, apnic, apnic whois, apple, apple hacking, apple ios, apple phone, apple private, applicunwnt, artemis, articles, as13789, as14061, as15169, as16509, as20940, as22075, as3209 vodafone, as3359, as54113, as797 att, as8075, as852, ascii text, asia pacific, attack, attorney, august, australia, author avatar, auto-generated security, av detections, azorult, babar, bank, banker, bazaloader, b body, beach research, behav, binder, bing ads, bitminer, blacklist, blacklist http, blacklist https, blister, body, body length, bomb, botnetwork, bot networks, bradesco, brashears, brian, brian sabey, brochure url, brontok, button, bypass, c2, c2ae, c2 raccoon, china telecom, cisco umbrella, civicalg, civicalg.com, ck id, ck matrix, cl0p, class, cleaner, click, close, cloudflare, cloudflarenet, cname, cnc server, cnnic, cobalt strike, column, com laude, communicating, company limited, computer, conduit, conhost, connection, contact, contacted, contacted urls, content type, control server, copy, copyright, copyright c, core, count blacklist, covid19, crack, create new, creation date, creation_of_an_executable_by_an_executable, critical, critical risk, crypt, cryptinject, csc corporate, cuba, cutwail, cve201711882, cyber crime, cyberstalking, cyber threat, cyber warfare, dapato, data, data collection, date, date hash, date sat, december, decode, deepscan, defense, de indicators, denied trackers, detection list, detections type, detplock, digicert global, disability, district, dllinject, dns, dnspionage, dns replication, docs pricing, domain, domains, domains domain, downldr, download, download csv, downloader, driverpack, dropper, dynamicloader, elderly, emotet, encpk, encrypt, engineering, entries, error, etpro malware, et tor, excel, execution, exit, expiration, expiration date, expiressat, exploit, facebook, facebook link, failed_code_integrity_checks, fakealert, fakeinstaller, falcon sandbox, fareit, february, feodo, file, filehash, filerepmalware, files, filetour, final url, firehol, first, floxif, form, formbook, fraud services, freemake, fri jun, fusioncore, g2 tls, gandcrab, gandcrab dns, gecko, general, general full, generator, generic, generic malware, genkryptik, genpack, geoip, germany, germany unknown, get h2, ghost, glupteba, gmbh version, gmt contenttype, google, government relations, graph community, greatcall, gti9080l, gti9128v, gti9158, hackers, hacktool, hall render, hallrender.com, hallrender.com/attorney/brian-sabey, hash, hashes, headers, health phone, heodo, heur, highly targeted, hijacking, historical ssl, home pg, host, hostname, hsbc, html, html info, http response, hybrid, icann whois, ids detections, iframe, ii llc, indicator, indicator role, indonesia, information, inmortal, innova co, input, installcore, installer, installpack, iobit, iocs, ip address, ip addresses, ip summary, ipv4, japan, java, javascript, jpeg image, json ip, jul jan, june, keygen, keylogger, khtml, known tor, kraddare, label, laplasclipper, length, level3, linkedin link, linkid252669, link url, lively, loadmoney, local, lockbit, login, lookup, lovgate, lsmeta function, lsoldgsqueue, ltd dba, lumma stealer, m, macros sneaky, magazine, main, malicious, malicious host, malicious site, malicious url, maltiverse, malware, malware generic, malware site, march, mark, masquerade, maxage31536000, mb iesettings, mb opera, mb qimage, mb setup, mb super, media, mediaget, memscan, meta, metastealer, meterpreter, metro, mexico, microsoft, million, mimikatz, miner, mini, mirai, misc attack, mitre att, modernizr, mo.gov, moved, msclkidn, name, namecheap inc, name servers, name verdict, nanjing, nanocore, nanocore rat, network, networm, next, ngrok, nircmd, njrat, no data, node tcp, node udp, no expiration, noname057, notepad, nsis, nymaim, occamy, offercore, opencandy, optimizer, otx octoseek, parent domain, passive dns, password, patcher, path, pattern match, paypal, pe resource, phish, phishing, phishing chase, phishing site, please, pony, porkbun llc, powershell, powershell_create_scheduled, pragma, predator, premium, presenoker, processes tree, project, protocol h2, proton, proxy, psexec, public url, pulse pulses, pulses, pulses url, pykspa, python_initiated-connection, qakbot, qbot, quasar, quasar rat, query, raccoon, ramnit, ransom, ransomexx, ransomware, record value, redirector, redline, redline stealer, referrer, registrar, registrar abuse, relacionada, related pulses, relayrouter, remcos, render, report spam, resolutions, resource, reverse dns, riskware, rms, role title, round, rsa sha256, runescape, sabey, safebae.org, safe site, sality, sample, samplepath, samples, scan endpoints, search, search live, secrisk, security, security tls, seraph, server, service, serving ip, setup stub, seznam, sha256, shell commands, show, showing, show technique, site, site safe, site top, softonic, software, sonbokli, spammer, span, spyrixkeylogger, spyware, ssdeep, ssl certificate, startpage, status, status code, stealer, strings, submitters, summary, summary iocs, suppobox, suspected, suspicious, switch dns, swrort, systweak, tag count, tag manager, tag tag, team, team malware, technology, telecom, temp, this, threat report, threat roundup, threats et, thu aug, tiggre, title access, title added, tld count, tofsee, tor exit, tor known, tor relayrouter, tracking, traffic, trojan, trojanspy, trojanx, true defense, tsara, tsara brashears, tue dec, tulach, tulach.cc, t whois, twitter, type, ubot, ukraine, ultimate, unauthorized, union, united, united kingdom, unknown, unlocker, unruy, unsafe, update checker, url http, url https, urls, url summary, urls url, use collection, utc google, utc submissions, uztuby, value, variables, ver2, verisign, veryhigh, vidar, vids1, virus network, virustotal, virut, vitzo, wacatac, wannacry kill, webtoolbar, whasz, whois database, whois parent, whois record, whois whois, win32, win32 exe, win32.pdf.alien, win64, windows nt, worm, write, xrat, xtrat, zbot, zeus, zpevdo

  • View other sources: Spamhaus VirusTotal

  • Country: United States
  • Network:
  • Noticed: 33 times
  • Protocols Attacked: SSH
  • Countries Attacked: Anguilla, Aruba, Australia, Bahamas, Barbados, Canada, Cayman Islands, Costa Rica, Curaçao, Georgia, Guatemala, Japan, Mexico, Netherlands, Panama, Philippines, Poland, Saint Kitts and Nevis, Saint Martin (French part), Saint Vincent and the Grenadines, Sint Maarten (Dutch part), Tanzania United Republic of, Trinidad and Tobago, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America

Malware Detected on Host

Count: 523 c63de17152a7ed7020c63b85227676def72a250f3aeaa969565ba2f314015090 f1e3411387a69f0ede6a34ac3859a8a5086028262ae74d3e6c8769b84d8d3f2f 3d672ade4e9f1bdd577cfb7f22dfeceb1ea1eef24872666cb17e6bc33ee775e2 09e4648077e1e1e67c05c7ce3a373aa518dbfa4e36da53b5fd16da84e8efc335 34315b63ec9b099361897c00a95b133439b4451701b36f393c82b7c782032379 d2763255527646dea4b04c7b7a32297729a7e2c4917df6f3c9dc4b505a169be5 d2f11bff2c41704ef652d94fe845b40e27f9be6e829224e090a5b6b1344c9adf ab06d0ff5765a65ad132e99b884694fad41e7ba4f7d3951ddc3f8c8b86e3a1fa d286f21619b4c760cdc5830d35e98e20bd7c41b78f910db3774a720f45323d82 607e98a87021f80d4f4e1ddd35ee6b0ddf212fa5297243dfd2cd02cb7194c684

Open Ports Detected

443 80

Map

Whois Information

Links to attack logs

****** ****** ******

Share on: