104.40.188.185

Classification: Suspicious

104.40.188.185 is a suspicious IP address. Linked to Bundlore malware. Reported by 2 threat sources, last seen 2021-12-15.

MITRE ATT&CK associations

Malware families: BUNDLORE (S0482)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Malware Hybrid-Analysis 2021-11-26 10:00:11 2021-12-15 12:00:23
Gen:Variant.Application.Bundler.DownloadGuide Hybrid-Analysis 2018-04-30 09:15:28 2021-11-24 14:45:40
Application.DownloadGuide Hybrid-Analysis 2021-07-08 14:30:10 2021-07-08 14:30:10
Application.Bundler.DownloadGuide Hybrid-Analysis 2020-02-20 08:15:16 2021-06-22 08:30:32
Generic.Malware Hybrid-Analysis 2018-12-04 10:30:04 2020-07-29 06:30:07
Application.Downloader Hybrid-Analysis 2019-12-05 19:15:15 2019-12-05 19:15:15
Malicious site Hybrid-Analysis 2019-07-26 11:15:19 2019-07-26 11:15:19
bundlore Maltiverse 2018-02-19 05:19:15 2018-03-05 13:09:52 S0482 Bundlore
adware,nsis Maltiverse 2017-11-16 04:31:52 2017-11-16 04:31:52

Tags

bundlore

Whois information

AS name
AS8075 Microsoft Corporation
AS registry
arin
AS date
2014-05-07 00:00:00
AS CIDR
104.40.0.0/13
CIDR
104.40.0.0/13
Registrant
Microsoft Corporation
Address
One Microsoft Way
City
Amsterdam
State
WA
Postal code
1012 JS
Country
NL — Netherlands 🇳🇱
Contact email
[email protected], [email protected], [email protected]
First indexed
2017-11-16 04:31:52
Last updated
2025-11-18 08:31:37

Malicious IPs in the same CIDR

104.41.137.249 104.42.175.153 104.40.211.153 104.43.200.55