104.40.156.71

Classification: Suspicious

104.40.156.71 is a suspicious IP address. Linked to Bundlore malware. Reported by 2 threat sources, last seen 2021-11-29.

MITRE ATT&CK associations

Malware families: BUNDLORE (S0482)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Gen:Variant.Application.Bundler.DownloadGuide Hybrid-Analysis 2018-04-30 09:15:28 2021-11-29 13:30:25
Malware Hybrid-Analysis 2021-11-12 06:30:09 2021-11-12 06:30:09
Adware.CovusCRTD Hybrid-Analysis 2021-07-20 21:45:29 2021-07-20 21:45:29
Application.DownloadGuide Hybrid-Analysis 2021-07-08 14:30:10 2021-07-08 14:30:10
Application.Bundler.DownloadGuide Hybrid-Analysis 2019-11-05 13:30:08 2021-06-22 08:30:32
Generic.Malware Hybrid-Analysis 2018-07-23 03:30:54 2021-02-10 00:15:41
Malicious site Hybrid-Analysis 2019-04-08 09:15:11 2019-04-08 09:15:11
bundlore Maltiverse 2018-03-07 09:47:04 2018-03-07 09:47:04 S0482 Bundlore
adware,nsis Maltiverse 2017-11-16 04:31:51 2017-11-16 04:31:51

Tags

adware nsis bundlore

Whois information

AS name
AS8075 Microsoft Corporation
AS registry
arin
AS date
2014-05-07 00:00:00
AS CIDR
104.40.0.0/13
CIDR
104.40.0.0/13
Registrant
Microsoft Corporation
Address
One Microsoft Way
City
Amsterdam
State
WA
Postal code
1012 JS
Country
NL — Netherlands 🇳🇱
Contact email
[email protected], [email protected], [email protected]
First indexed
2017-11-16 04:31:51
Last updated
2025-11-23 07:29:21