50.63.13.135 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 50.63.13.135 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Likely Malicious Host 🟠 60/100

Host and Network Information

  • Mitre ATT&CK IDs: T1001 - Data Obfuscation, T1003 - OS Credential Dumping, T1014 - Rootkit, T1016 - System Network Configuration Discovery, T1018 - Remote System Discovery, T1021 - Remote Services, T1027 - Obfuscated Files or Information, T1049 - System Network Connections Discovery, T1053 - Scheduled Task/Job, T1055 - Process Injection, T1056 - Input Capture, T1057 - Process Discovery, T1059 - Command and Scripting Interpreter, T1071 - Application Layer Protocol, T1072 - Software Deployment Tools, T1080 - Taint Shared Content, T1082 - System Information Discovery, T1090 - Proxy, T1095 - Non-Application Layer Protocol, T1102 - Web Service, T1105 - Ingress Tool Transfer, T1110 - Brute Force, T1111 - Two-Factor Authentication Interception, T1113 - Screen Capture, T1115 - Clipboard Data, T1123 - Audio Capture, T1125 - Video Capture, T1127 - Trusted Developer Utilities Proxy Execution, T1140 - Deobfuscate/Decode Files or Information, T1176 - Browser Extensions, T1195 - Supply Chain Compromise, T1210 - Exploitation of Remote Services, T1218 - Signed Binary Proxy Execution, T1486 - Data Encrypted for Impact, T1490 - Inhibit System Recovery, T1497 - Virtualization/Sandbox Evasion, T1499 - Endpoint Denial of Service, T1543 - Create or Modify System Process, T1547 - Boot or Logon Autostart Execution, T1548 - Abuse Elevation Control Mechanism, T1564 - Hide Artifacts, T1566 - Phishing, T1574 - Hijack Execution Flow

  • Tags: adwind, agent tesla, agenttesla, all at, analysis, analyze script, any.run, apart, api quotas, april, arkei, asyncrat, august, automated, awards, azorult, belarus, bladabindi, change, chatgpt, click, cobalt strike, cobaltstrike, crimson rat, crypto, danabot, darkcomet, dcrat, december, desktop, discord, dunihi, egregor, email, emotet, eternalblue, execution, fallout, february, ficker, ficker stealer, first, flawedammyy, formbook, gcleaner, gootkit, hancitor, hawkeye, houdini, hworm, icedid, inst, jenxcus, keep tabs, lumma, lummac2, lumma stealer, macos, malware, mars, matiex, microsoft, nanocore, netwire, njrat, november, october, open, orcus, orcus rat, orcusrat, oski, path, pinkslipbot, poisonivy, pony, powershell, predator, privateloader, qakbot, qbot, quasar, quasar rat, raccoon, racealer, rats, redline, redline stealer, remcos, remote access, report, rust, ryuk, screen, seen, september, smoke loader, smokeloader, snake, snake keylogger, streamline, strrat, systembc, teamviewer, tesla, threats, track them, trickbot, trojan, ukraine, ursnif, vidar, wannacry, wannycry, word, wsh, wshrat, xtremerat, xworm

  • View other sources: Spamhaus VirusTotal

  • Country: United States
  • Network: AS398101 godaddy.com llc
  • Noticed: 10 times
  • Protocols Attacked: Anonymous Proxy
  • Countries Attacked: Armenia, Austria, Belarus, Canada, Germany, India, Italy, Kazakhstan, Kyrgyzstan, Poland, Russian Federation, Switzerland, Tajikistan, Ukraine, Uzbekistan
  • Passive DNS Results: mobiazzam.com kaftanpretty.com sharedojo.com akaicloud.com

Malware Detected on Host

Count: 89 5073e8d676f7c24a0748156dfceb7490ac30992cd4f6bcb2e61b15a230ad418a df54b747358a1bf8a7d1d515b1f5c8f292f5f60944d7831aef8f1883c1902540 0c64c69cdcb6b8bbc8530bdbb75b87ed839d4861c7a0ac8a319f299e3c90b805 b54e962463076bc5d2d22d3da51ed5f98464996c384128980a75da526786b2fe af7cff18f52b1fd9eb870c8259a2e07aee9f27a6a6166a829c0c5277e34470a4 90e6ca1cd70ecd554375b1b7cda60cbe29c0c038b0fd62c62372608aece6aec0 5a6922818540b2ed36f605142b2d78962fa22263a3ec7dcbd4c41eb086361ee3 d13e8271d8f7f8fd55cbb08d2334d9e5d3b81f209e30b291bc2d2e1c1051252c 61f99140c11f1bb352b757be8b920ae10b4df81779e8466bbe0511becd109f99 28c09996fad1d7607f4d9db12978166025ff6768e97bf4c3f632632022911eca

Map

Whois Information

Links to attack logs

anonymous-proxy-ip-list-2024-02-11

Share on: