104.248.63.248

Classification: Suspicious

104.248.63.248 is a suspicious IP address. Linked to Emotet malware. Reported by 13 threat sources, last seen 2021-02-22. Network: AS14061 Digitalocean, LLC.

MITRE ATT&CK associations

Malware families: EMOTET (S0367)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Malicious Hostname Cyber Threat Coalition 2020-12-14 04:51:04 2021-02-22 08:21:06 malicious-activity
Phishing Mr.Looquer 2020-01-11 02:40:31 2021-02-22 07:01:33
Phishing Maltiverse 2020-11-16 16:14:19 2021-02-22 04:49:15 compromised
Social Engineering Maltiverse 2020-11-16 16:14:19 2021-02-22 04:49:15 malicious-activity
Generic.Malware Hybrid-Analysis 2019-12-18 20:15:22 2021-02-20 20:15:38
Malicious url Cyber Threat Coalition 2020-12-28 17:14:10 2021-02-19 20:52:20 malicious-activity
Phishing site Hybrid-Analysis 2020-04-08 02:45:06 2021-02-18 15:30:57
Phishing Phishtank 2019-11-28 02:25:51 2021-01-31 16:20:08 compromised malicious-activity
Web Mr.Looquer 2019-12-23 02:15:56 2021-01-31 12:37:25
Social Engineering Phishtank 2020-11-29 10:48:06 2021-01-31 11:47:37 malicious-activity
paypal phishing Antiphishing.com.ar 2020-10-07 11:23:41 2021-01-15 09:29:25
Social Engineering Antiphishing.com.ar 2020-06-30 03:34:00 2021-01-15 09:29:25 malicious-activity
Facebook phishing Antiphishing.com.ar 2020-12-17 02:57:15 2021-01-02 12:15:20
Apple phishing Antiphishing.com.ar 2020-12-26 07:20:27 2020-12-26 07:20:27
Covid19 scam Cyber Threat Coalition 2020-11-20 20:05:54 2020-12-13 08:35:35 malicious-activity
Phishing Facebook Phishtank 2020-12-08 09:34:39 2020-12-10 18:18:15 compromised malicious-activity
Phishing Generic/Spear Phishing OpenPhish 2020-10-13 06:59:36 2020-10-13 06:59:36
Social Engineering OpenPhish 2020-03-17 02:50:30 2020-10-13 06:59:36 malicious-activity
Phishing Office365 OpenPhish 2020-03-17 02:50:30 2020-10-01 03:23:07
Phishing Facebook, Inc. OpenPhish 2020-09-06 06:44:28 2020-10-01 03:23:00
Trojan.Generic Hybrid-Analysis 2020-09-24 01:00:17 2020-09-24 01:00:17
Malicious site Hybrid-Analysis 2020-02-10 14:45:06 2020-09-21 18:00:20
Phishing Netflix Inc. OpenPhish 2020-08-27 11:49:53 2020-08-27 11:49:53
Covid19 scam DomainTools 2020-04-19 18:16:34 2020-08-18 00:25:07 malicious-activity
QVM03.0.CB23.Malware Hybrid-Analysis 2020-07-26 02:30:49 2020-07-26 02:30:49
Phishing Chase Personal Banking OpenPhish 2020-07-15 05:08:45 2020-07-15 05:08:45
Orange phishing Antiphishing.com.ar 2020-06-30 03:34:00 2020-06-30 03:34:00
Phishing Internal Revenue Service Phishtank 2020-06-23 04:44:46 2020-06-23 04:44:46
Unsafe.AI_Score_80% Hybrid-Analysis 2020-06-05 23:30:05 2020-06-05 23:30:05
Phishing Orange OpenPhish 2020-04-18 09:25:04 2020-05-05 03:52:40
Covid19 scam CCN-CERT 2020-04-13 22:30:55 2020-05-02 11:12:43 malicious-activity
Anonymisation Services IBM X-Force Exchange 2020-01-09 15:30:00 2020-04-18 13:21:00
Malicious domain Telefonica Peru 2020-04-08 18:04:21 2020-04-09 05:07:14
Phishing BT Group plc OpenPhish 2020-04-07 03:23:03 2020-04-07 03:23:03
Phishing Bank of America OpenPhish 2020-04-04 08:17:16 2020-04-04 08:17:16
Phishing Google Inc. OpenPhish 2020-03-17 08:56:59 2020-03-17 08:56:59
MyEtherWallet phishing Antiphishing.com.ar 2020-03-17 01:55:04 2020-03-17 01:55:04
Cryptocurrency Mining IBM X-Force Exchange 2020-01-14 20:40:00 2020-03-10 13:55:00
Emotet Mr.Looquer 2020-03-05 02:42:07 2020-03-05 02:42:07 S0367 Emotet
l\'Assurance Maladie phishing Antiphishing.com.ar 2020-02-25 08:13:20 2020-02-25 08:13:20
Phishing Orange Phishtank 2020-01-04 09:16:50 2020-01-04 09:16:50
linkedin phishing Antiphishing.com.ar 2019-12-11 01:45:40 2019-12-11 01:45:40
Mail Spammer Barracuda 2019-11-28 02:25:51 2019-11-28 02:25:51
Mail Spammer Abuseat.org 2019-11-28 02:25:51 2019-11-28 02:25:51

Tags

phishing fraud coinminer malware binary sector:online services office365 sector:email provider google inc. sector:financial bank of america sector:telecommunications bt group plc covid19 coronavirus scam orange chase personal banking sector:online/cloud service netflix inc. sector:social networking facebook, inc. generic/spear phishing

Whois information

AS name
AS14061 Digitalocean, LLC
AS registry
arin
AS date
2018-08-06 00:00:00
AS CIDR
104.248.48.0/20
CIDR
104.248.0.0/16
Registrant
Digitalocean, LLC
Address
101 Ave of the Americas 10th Floor
City
North Bergen
State
NJ
Postal code
07047
Country
US — United States 🇺🇸
Contact email
[email protected], [email protected]
First indexed
2019-11-28 02:25:51
Last updated
2026-02-06 06:25:59

Malicious IPs in the same CIDR

104.248.57.74 104.248.55.140 104.248.60.59 104.248.57.195 104.248.57.223