5.79.79.211 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 5.79.79.211 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

🔴 High Risk — 80/100

Geographic Location

Host and Network Information

  • View other sources: Spamhaus VirusTotal Shodan AbuseIPDB
  • Country: Netherlands
  • Noticed: 21 times
  • Protocols Attacked: SSH
  • Countries Attacked: Australia, China, Hong Kong, Netherlands, United Kingdom of Great Britain and Northern Ireland, United States of America
  • Open Ports: 443, 53, 80, 8080
  • Tor Node: No
  • Associated Malware Samples: 2725

Tags

  • 198-46-194-153-host.colocrossing.com
  • 2nd corintnthians 4:8-9
  • 707713
  • aaaa
  • accept
  • acint
  • active
  • active2
  • active related
  • active threat
  • activity dns
  • adapter driver
  • adblock pro
  • added active
  • address
  • address domain
  • addtopayload
  • adload
  • admin
  • admin city
  • a domains
  • aes256gcm
  • age86400 set
  • agent
  • agent tesla
  • alexa
  • alexa top
  • algorithm
  • alina
  • all octoseek
  • all scoreblue
  • all search
  • all txt
  • alphacrypt cnc
  • amadey
  • america asn
  • analyze
  • analyzer
  • android
  • andromeda
  • anomalous_deletefile
  • anomalous file
  • anonymizer
  • antidebug_guardpages
  • antivm_generic_disk
  • a nxdomain
  • api blog
  • apple
  • apple app store compromise
  • apple as8075
  • apple computer
  • apple ios
  • apple iphone
  • apple itunes
  • apple support compromise
  • applicunwnt
  • app store
  • april
  • arizona
  • artemis
  • as133618
  • as134175 unit
  • as15169 google
  • as16509
  • as19905
  • as24940
  • as24940 hetzner
  • as26710
  • as26710 icann
  • as29066 host
  • as33387
  • AS33387 nocix llc
  • as36352
  • as38365 beijing
  • as393601 state
  • as39494 jsc
  • as397241
  • as40528 icann
  • as43350 nforce
  • as44273 host
  • as47846
  • as47995
  • as4837 china
  • as51852
  • as60558 phoenix
  • as63949 linode
  • as6461 zayo
  • as8560
  • asn as133618
  • asnone
  • asyncrat
  • athena
  • attack
  • attention
  • attorney james
  • auction
  • august
  • authentication
  • authority
  • av detections
  • awful
  • aws
  • azorult
  • b59bn timestamp
  • backdoor
  • bambernek
  • bambernek gen
  • bambernek simda
  • banco
  • bandoo
  • bank
  • banker
  • banking
  • bayrob
  • b body
  • beacon
  • beginstring
  • behav
  • betabot
  • beta version
  • blacklist
  • blacklist http
  • blacklist https
  • body
  • body doubles
  • body length
  • bot
  • bot network
  • bradesco
  • breadcrumbs
  • briannsabey breadcrumbs
  • brian sabey
  • briansabey
  • brontok
  • business
  • bypass_firewall
  • C2
  • ca1 odigicert
  • ca g2
  • ca issuers
  • canada unknown
  • cane
  • cape
  • cellbrite
  • cellebrite
  • cellerebrand
  • certificate
  • certificate status
  • certsentry
  • chaos
  • check in
  • china unknown
  • cins active
  • cisco umbrella
  • citadel
  • city
  • city center
  • ck id
  • class
  • cleaner
  • click
  • cmstp
  • cname
  • cnc
  • cobalt strike
  • code
  • coinminer
  • colibri loader
  • collections
  • command_and_control
  • commerce
  • communicating
  • components
  • compromised websites
  • comspec
  • conduit
  • confirm https
  • contacted
  • contacted urls
  • contact phone
  • cookie
  • copy
  • copyright
  • core
  • count blacklist
  • country
  • country us
  • cowboy
  • crack
  • cracked
  • create new
  • creation date
  • critical
  • crlf line
  • cryptowall
  • csc corporate
  • cus cnapple
  • cus cndigicert
  • cus olet
  • cvss v2
  • cybercrime
  • cyber stalking
  • cyberstalking
  • cyber threat
  • d417n
  • daisy coleman
  • dalles
  • dangerous
  • dark
  • data
  • database
  • data brokers
  • data center
  • date
  • date sat
  • dcom
  • deepscan
  • default
  • de indicators
  • delete
  • delete c
  • delphi
  • detection list
  • dev
  • dexter
  • dga domain
  • dgs
  • dirtsearch
  • disables_windowsupdate
  • discord
  • dns
  • dns lookup
  • dnsname
  • dns replication
  • dns resolutions
  • dnssec
  • docs pricing
  • domain
  • domain names
  • domain privacy
  • domains
  • domain status
  • domain xn
  • downldr
  • download
  • download encrypt
  • downloader
  • dropped
  • dropper
  • dynamic
  • dynamic_function_loading
  • dynamicloader
  • ecc ca
  • elite
  • email
  • emailaddress
  • emails
  • emotet
  • encrypt
  • encrypt cnr11
  • engineering
  • entity
  • entries
  • error
  • et
  • et cins
  • eternalblue
  • et tor
  • eu data
  • eva reimer
  • evilnum
  • execution
  • exit
  • expiration
  • expiration date
  • exploit
  • facebook
  • factory
  • fakealert
  • falcon sandbox
  • false
  • false files
  • february
  • fexp24007246
  • ff2c217402202b
  • file execution
  • filehash
  • filehashmd5
  • filehashsha1
  • filehashsha256
  • filerepmetagen
  • files
  • files ip
  • filetour
  • final url
  • firehol
  • firehol gozi
  • first
  • floxif
  • for privacy
  • full name
  • g1 oapple
  • galaxy
  • galaxy watch
  • gear s
  • gear s2
  • gear s3
  • gear sport
  • gecko
  • general
  • general full
  • generator
  • genericm
  • genkryptik
  • germany unknown
  • get h2
  • get http
  • get na
  • global g2
  • gmbh version
  • gmt content
  • gmt location
  • gmt max
  • gmtn
  • gmt server
  • go daddy
  • google
  • gpt analyzer
  • graph summary
  • guard
  • hackers
  • hacktool
  • hallrender
  • hash
  • hashes
  • hawkeye
  • headers
  • hetzner
  • heur
  • hiddentear
  • high
  • high attack
  • high level
  • highly targeted
  • hijacker
  • historical
  • historical ssl
  • hong kong
  • hosting
  • hostname
  • hostnames
  • house.mo.gov
  • http
  • http identifier
  • http_request
  • http response
  • https://lawlink.com/documents/10935/blackbag-technologies-announ
  • huge domains
  • hybrid
  • icann
  • icloud compromise
  • ieudinit
  • iframe
  • impact
  • indicator facts
  • indicator role
  • info
  • infy
  • injection_create_remote_thread
  • injection_inter_process
  • inmortal
  • installcore
  • installer
  • intel
  • internet storm
  • iocs
  • ios
  • ip address
  • ip files
  • ip related
  • ip reputation
  • ip summary
  • ip tcp
  • ipv4
  • ipv4address
  • issuers
  • itunes
  • jackpos
  • javascript
  • june
  • kb body
  • keepaliveyes
  • key
  • key algorithm
  • key identifier
  • key info
  • keylogger
  • khtml
  • known infection source
  • known tor
  • kraken
  • land use
  • lazarus
  • learn more
  • lemon duck
  • life
  • limited
  • linkid252669
  • link location
  • local
  • localappdata
  • location first
  • location united
  • lockbit
  • log id
  • login
  • loki
  • loki password
  • lookups
  • main
  • malicious
  • malicious site
  • malicious url
  • maltiverse
  • malvertising
  • malvertizing
  • malware
  • malware infection
  • malware service
  • malware site
  • malware sites
  • mas
  • matsnu
  • maze
  • media center
  • media sharing
  • medium
  • meekserver
  • mercenary
  • meta
  • metasploit
  • methodpost
  • metro
  • metroby-tmo
  • mhkz
  • microsoft
  • midia-4
  • miles2
  • million
  • mirai
  • misc attack
  • misc http
  • missouri
  • mitre att
  • model
  • modify_proxy infostealer_cookies
  • monitoring
  • mon jul
  • moved
  • msie
  • mtb feb
  • mtb mar
  • mtb may
  • mvi2
  • name
  • name servers
  • name verdict
  • nanocore
  • nat32
  • n cvss
  • netsupport rat
  • network
  • network_http
  • networm
  • neutrino
  • neworder.doc
  • next
  • nids
  • nircmd
  • nivdort
  • njrat
  • no data
  • node tcp
  • node traffic
  • no expiration
  • november
  • nsyt
  • null
  • number
  • nxdomain
  • nymaim
  • object
  • observed dns
  • october
  • octoseek
  • opencandy
  • open path
  • open ports
  • orbiters
  • organization
  • orgid
  • orgtechhandle
  • orgtechref
  • otx octoseek
  • parallax rat
  • parent domain
  • parking crew
  • parking payload
  • passive dns
  • password
  • paste
  • patcher
  • path max
  • pattern match
  • pattern url
  • payload
  • pcap
  • pdf broadcom
  • pdf report
  • pegasus
  • pegasystem
  • pe resource
  • persistence_autorun
  • phase
  • phishing
  • phishing site
  • phishtank
  • pingback
  • pjp3sltkz
  • plasma
  • playgame
  • please
  • pony
  • poor reputation
  • possible
  • postal code
  • post http
  • powershell
  • powershell_download
  • powershell_request
  • presenoker
  • privacy admin
  • privacy tech
  • privateloader
  • probe ms17010
  • problems
  • procmem_yara
  • project
  • protocol h2
  • public key
  • public server
  • pulse pulses
  • pulses
  • pulses otx
  • pulse submit
  • pulse use
  • push
  • pykspa
  • python infostealer
  • qakbot
  • qbot
  • quasar
  • quasar rat
  • query
  • qwest
  • ramnit
  • ransom
  • ransomexx
  • ransomware
  • raspberry robin
  • ratel
  • rauschenberg
  • read c
  • real estate
  • realteck audio
  • record type
  • record value
  • red
  • redacted for
  • redacted referrer
  • redir
  • redline stealer
  • referrer
  • refresh
  • regbinary
  • regdword
  • registrant fax
  • registrar
  • registrar abuse
  • registrar iana
  • registrar of
  • registrar url
  • registrar whois
  • registry arin
  • registry domain
  • registry policy
  • regsetvalueexa
  • regsetvalueexw
  • related nids
  • related pulses
  • related tags
  • relayrouter
  • remcos
  • remcos rat
  • renos
  • replication
  • reputation ip
  • resolutions
  • resolved ips
  • resource
  • reverse dns
  • rexxfield
  • rgba
  • riskware
  • role title
  • roundup
  • rsa cn
  • rtechhandle
  • rtechref
  • russia unknown
  • safebae
  • safe site
  • sakula malware
  • sample
  • samples
  • samsug
  • samsung galaxy
  • scan endpoints
  • scottsdale
  • script
  • script domains
  • script script
  • script urls
  • search
  • search live
  • security
  • security tls
  • september
  • server
  • servers
  • service
  • serving ip
  • setcookie geous
  • sha256
  • show
  • showing
  • simda
  • sinkhole cookie
  • site
  • slcc2
  • slingshot
  • smsspy
  • soc
  • software
  • spammer
  • span
  • spitmo
  • spyeye
  • spyware
  • ssl certificate
  • sslcertificate
  • startpage
  • state
  • stateprovince
  • status
  • status code
  • stealer
  • steam
  • stevens creek
  • stop ransomware
  • strings
  • striven
  • subject
  • subject billing
  • subject key
  • subject public
  • submit
  • summary
  • suppobox
  • susp
  • swrort
  • systweak
  • T1622 - Debugger Evasion
  • tactics
  • tag count
  • tag tag
  • target
  • targeting
  • taskscheduler
  • team
  • teams
  • threat
  • threat network
  • threat report
  • threat roundup
  • threats et
  • tiggre
  • timestamp
  • title added
  • tld count
  • tls rsa
  • tls web
  • t-mobile
  • tools
  • tor known
  • tor relayrouter
  • tracking
  • traffic
  • trojan
  • trojandropper
  • trojanspy
  • tsara brashears
  • ttl value
  • tulach
  • type
  • type indicator
  • type name
  • typosquatting
  • ua71173394
  • unicode text
  • union
  • unique
  • united
  • united kingdom
  • united tls web
  • unknown
  • unknown url
  • unruy
  • unsafe
  • url analysis
  • url http
  • url https
  • urls
  • urls http
  • urls https
  • url summary
  • ursnif
  • usbank
  • utf8
  • v3 serial
  • v3 severity
  • validity
  • value snkz
  • vawtrak
  • verdict
  • veryhigh
  • virgin islands
  • virut
  • vps
  • vskimmer
  • wacatac
  • wannacry
  • warbot
  • watch
  • wc3 rpg
  • webp
  • webtoolbar
  • west domains
  • whois record
  • whois ssl
  • whois whois
  • win32
  • win32 exe
  • win64
  • windows
  • windows nt
  • wininit
  • win.trojan
  • wow64
  • write
  • x509v3
  • x509v3 subject
  • xorddos
  • xpcegvo2adsnq
  • xrat
  • xtrat
  • xtreme
  • yara detections
  • yara rule
  • zbot
  • zeus
  • zombie devices

MITRE ATT&CK TTPs

  • T1003 - OS Credential Dumping
  • T1005 - Data from Local System
  • T1010 - Application Window Discovery
  • T1027 - Obfuscated Files or Information
  • T1036.004 - Masquerade Task or Service
  • T1051 - Shared Webroot
  • T1055 - Process Injection
  • T1056.001 - Keylogging
  • T1057 - Process Discovery
  • T1059.002 - AppleScript
  • T1059.007 - JavaScript
  • T1059 - Command and Scripting Interpreter
  • T1060 - Registry Run Keys / Startup Folder
  • T1071.001 - Web Protocols
  • T1071.003 - Mail Protocols
  • T1071.004 - DNS
  • T1071 - Application Layer Protocol
  • T1078.004 - Cloud Accounts
  • T1082 - System Information Discovery
  • T1083 - File and Directory Discovery
  • T1090 - Proxy
  • T1102 - Web Service
  • T1105 - Ingress Tool Transfer
  • T1106 - Native API
  • T1110.002 - Password Cracking
  • T1114.001 - Local Email Collection
  • T1114 - Email Collection
  • T1123 - Audio Capture
  • T1129 - Shared Modules
  • T1140 - Deobfuscate/Decode Files or Information
  • T1155 - AppleScript
  • T1185 - Man in the Browser
  • T1204.001 - Malicious Link
  • T1204.002 - Malicious File
  • T1204.003 - Malicious Image
  • T1204 - User Execution
  • T1210 - Exploitation of Remote Services
  • T1218 - Signed Binary Proxy Execution
  • T1447 - Delete Device Data
  • T1448 - Carrier Billing Fraud
  • T1449 - Exploit SS7 to Redirect Phone Calls/SMS
  • T1457 - Malicious Media Content
  • T1497 - Virtualization/Sandbox Evasion
  • T1506 - Web Session Cookie
  • T1512 - Capture Camera
  • T1518 - Software Discovery
  • T1523 - Evade Analysis Environment
  • T1546 - Event Triggered Execution
  • T1548 - Abuse Elevation Control Mechanism
  • T1560 - Archive Collected Data
  • T1562.003 - Impair Command History Logging
  • T1566 - Phishing
  • T1578.003 - Delete Cloud Instance
  • T1583.001 - Domains
  • T1583.005 - Botnet
  • T1583 - Acquire Infrastructure
  • T1588.001 - Malware
  • T1598 - Phishing for Information
  • T1600 - Weaken Encryption
  • T1610 - Deploy Container
  • TA0001 - Initial Access
  • TA0002 - Execution
  • TA0003 - Persistence
  • TA0004 - Privilege Escalation
  • TA0005 - Defense Evasion
  • TA0007 - Discovery
  • TA0008 - Lateral Movement
  • TA0009 - Collection
  • TA0010 - Exfiltration
  • TA0011 - Command and Control
  • TA0037 - Command and Control

Passive DNS

  • girhub.io

Whois Information

inetnum: 5.79.64.0 - 5.79.127.255 netname: NL-LEASEWEB-20120614 country: NL org: ORG-OB3-RIPE admin-c: lswn1-RIPE tech-c: lswn1-RIPE status: ALLOCATED PA mnt-by: RIPE-NCC-HM-MNT mnt-by: LEASEWEB-NL-MNT mnt-lower: LEASEWEB-NL-MNT mnt-domains: LEASEWEB-NL-MNT mnt-routes: LEASEWEB-NL-MNT created: 2012-06-14T07:52:30Z last-modified: 2017-11-16T10:10:08Z organisation: ORG-OB3-RIPE org-name: LeaseWeb Netherlands B.V. country: NL org-type: LIR address: Postbus 93054 address: 1090BB address: Amsterdam address: NETHERLANDS phone: +31203162880 fax-no: +31203162890 admin-c: lswn1-RIPE abuse-c: LWAD-RIPE mnt-ref: RIPE-NCC-HM-MNT mnt-ref: LEASEWEB-NL-MNT mnt-by: RIPE-NCC-HM-MNT mnt-by: LEASEWEB-NL-MNT created: 2004-04-17T11:42:05Z last-modified: 2020-12-16T12:49:01Z role: Leaseweb NL NOC address: Hessenbergweg 95, 1101 CX. Amsterdam admin-c: SPW1-RIPE nic-hdl: lswn1-RIPE mnt-by: LEASEWEB-NL-MNT created: 2017-11-16T10:05:00Z last-modified: 2022-07-05T12:59:36Z route: 5.79.64.0/18 descr: LEASEWEB origin: AS60781 mnt-by: LEASEWEB-NL-MNT created: 2014-03-10T12:46:38Z last-modified: 2015-09-30T23:00:01Z