45.64.104.223 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 45.64.104.223 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Likely Malicious Host 🟠 65/100

Host and Network Information

  • Mitre ATT&CK IDs: T1027 - Obfuscated Files or Information, T1053 - Scheduled Task/Job, T1080 - Taint Shared Content, T1102 - Web Service, T1210 - Exploitation of Remote Services, T1486 - Data Encrypted for Impact, T1490 - Inhibit System Recovery, T1566 - Phishing

  • Tags: agent tesla, cobalt strike, cobaltstrike, desktop, domains, emotet, emotet malware, eternalblue, fake net, fallout, first, flawedammyy, hashes, iocs ip, malware, microsoft, qbot, systembc, trickbot, trojan, wannacry, wannycry, wcry

  • View other sources: Spamhaus VirusTotal

  • Contained within other IP sets: hphosts_fsa, hphosts_psh

Malware Detected on Host

Count: 7 1690c88b7c2f9a681330e87d8012f6904bd5dc44a61c16aba3b5fd584ae46478 099585dece2a535d3c7445453617e80e0f56e63fea64c305089cf3f945718b32 9ab69f8de843b9796b9a1f99e220883a1cbe9d09f61f92e75843194e67e8d42c 6bf493452bab46c3395a4e41f1e5f587738eb6cb009315e27780d219070b3890 7c80a0c687c12363ce9a6ecd853f7482c30fa3b21fca689f3317cebde09c0390 82ab78f028a71725fe0b27b22cbc8769c4f3cee3808656fc910f0070bdeaaaf9 37dc4ba62c932e0795bddec64ffc93ff012bb07a2e8652a9d42cf53d2a3e9f94

Map

Whois Information

  • inetnum: 45.64.104.0 - 45.64.107.255
  • netname: LEAPSWITCH-IN
  • descr: LEAPSWITCH NETWORKS PRIVATE LIMITED
  • country: IN
  • org: ORG-LNPL10-AP
  • admin-c: AD1378-AP
  • tech-c: AD1378-AP
  • abuse-c: AL1842-AP
  • status: ASSIGNED PORTABLE
  • mnt-by: APNIC-HM
  • mnt-routes: MAINT-LEAPSWITCH-IN
  • mnt-irt: IRT-LEAPSWITCH-IN
  • last-modified: 2024-06-26T09:58:24Z
  • irt: IRT-LEAPSWITCH-IN
  • address: Office 410, Spectra, Paud Road, Pune Maharashtra 411038
  • e-mail: reportabuse@leapswitch.com
  • abuse-mailbox: reportabuse@leapswitch.com
  • admin-c: AD1378-AP
  • tech-c: AD1378-AP
  • mnt-by: MAINT-LEAPSWITCH-IN
  • last-modified: 2024-06-26T10:14:40Z
  • organisation: ORG-LNPL10-AP
  • org-name: LEAPSWITCH NETWORKS PRIVATE LIMITED
  • org-type: LIR
  • country: IN
  • address: Office 410, Spectra, Paud Road
  • phone: +919595233556
  • e-mail: corporate@leapswitch.com
  • mnt-ref: APNIC-HM
  • mnt-by: APNIC-HM
  • last-modified: 2024-05-29T13:08:13Z
  • role: ABUSE LEAPSWITCHIN
  • address: Office 410, Spectra, Paud Road, Pune Maharashtra 411038
  • country: ZZ
  • phone: +000000000
  • e-mail: reportabuse@leapswitch.com
  • admin-c: AD1378-AP
  • tech-c: AD1378-AP
  • nic-hdl: AL1842-AP
  • abuse-mailbox: reportabuse@leapswitch.com
  • mnt-by: APNIC-ABUSE
  • last-modified: 2024-06-26T10:14:54Z
  • person: Abuse Department
  • address: Office 410, Spectra, Paud Road, Pune Maharashtra 411038
  • country: IN
  • phone: +919595233556
  • e-mail: reportabuse@leapswitch.com
  • nic-hdl: AD1378-AP
  • mnt-by: MAINT-LEAPSWITCH-IN
  • last-modified: 2024-06-26T09:58:16Z
  • route: 45.64.104.0/24
  • descr: LeapSwitch Networks Pvt Ltd
  • country: IN
  • origin: AS132335
  • mnt-by: MAINT-LEAPSWITCH-IN
  • last-modified: 2024-06-07T02:23:56Z

Links to attack logs

****** ****** ******

Share on: