46.246.6.12 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 46.246.6.12 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Potentially Malicious Host 🟡 44/100

Host and Network Information

  • Tags: apix, c2 domain, c2 fronted, c2 fronting, cobalt strike, domain, fronted domain, fronting domain, go trojan, mythic ip, Njrat, possible cobalt, possible dcrat, possible deimos, possible havoc, possible pupy, possible qakbot, possible sliver, possible viper, push, rat ip, strike c2, unverified

  • View other sources: Spamhaus VirusTotal

  • Contained within other IP sets: stopforumspam_365d

  • Country: Sweden
  • Network: AS42708 glesys ab
  • Noticed: 2 times
  • Protocols Attacked: Anonymous Proxy
  • Passive DNS Results: chongmei33.myddns.rocks chongmei33.publicvm.com pradera.duckdns.org nuevosecua.duckdns.org nuevosremcs.duckdns.org clarosecurity-com.duckdns.org daddy.linkpc.net patria.duckdns.org musica7160.duckdns.org nlucex1980.duckdns.org diciembre24.duckdns.org tiagoodiaz.duckdns.org fortuna777.duckdns.org dubay.duckdns.org spamworzon.duckdns.org matarife.duckdns.org asy1543.duckdns.org mr1963.duckdns.org morelogs22.sytes.net wshlynh.ddns.net septiembre2022.duckdns.org bendito2714.duckdns.org reald27.duckdns.org diosamor27.duckdns.org update.mcafee-endpoint.com personnels.bdm-sa.fr news.banquealtantique.net windowsupdaters.zapto.org proxy21.duckdns.org ecuadordos.duckdns.org ecuado2021.duckdns.org

Malware Detected on Host

Count: 117 6dd25f1f288da8a804f41af680fda859e16b8b14b702025d1d265195f7a1bad3 3c5a733411aca498591aa177a6023984645062af02a127d3f08dc970feb27540 ef9353e2ce183d62fff967fb5d97dce26f862f35f1cfb1a512970c674953eee4 89a09e2f4971b6d329a694f88d8a3f4c09b51eaff819fb4497d63e162e4c2028 2d9425f22ff6bfac3217629cb2b724557e2431718937cef2d8ab629f32a3e92d fb0242383cc04dbaa3a81ac1947d183cad1c91f9fc77c1eddcc5e79b745c0017 7fc11ae7d7870624df39b4a18c11f95c58ff9e5856a523f108814a8d3627641b af375504ca558e9035a8bc319bbb592055bcd73bd20a6932203d252bfcae9530 beec48641e268819b654b29b10417e1c6d843c79211335bfed09b0c919f78209 e40c61053b74dc0f06d169322b5076716d210e1b5a2aadeb000349aa484344f3

Open Ports Detected

3389 443 5000 9999

CVEs Detected

CVE-2006-20001 CVE-2007-4723 CVE-2009-0796 CVE-2009-1390 CVE-2009-2299 CVE-2009-3765 CVE-2009-3766 CVE-2009-3767 CVE-2011-1176 CVE-2011-2688 CVE-2012-3526 CVE-2012-4001 CVE-2012-4360 CVE-2013-0941 CVE-2013-0942 CVE-2013-2765 CVE-2013-4365 CVE-2019-0190 CVE-2022-2097 CVE-2022-36760 CVE-2022-37436 CVE-2022-4304 CVE-2022-4450 CVE-2023-0215 CVE-2023-0286 CVE-2023-0464 CVE-2023-0465 CVE-2023-0466 CVE-2023-25690 CVE-2023-2650 CVE-2023-27522 CVE-2023-31122 CVE-2023-3817 CVE-2023-45802 CVE-2023-4807 CVE-2023-5678 CVE-2024-0727 CVE-2024-27316

Map

Links to attack logs

anonymous-proxy-ip-list-2024-05-21

Share on: