104.41.149.192

Classification: Suspicious

104.41.149.192 is a suspicious IP address. Linked to Bundlore malware. Reported by 2 threat sources, last seen 2021-12-15.

MITRE ATT&CK associations

Malware families: BUNDLORE (S0482)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Malware Hybrid-Analysis 2021-11-26 10:00:11 2021-12-15 12:00:23
Gen:Variant.Application.Bundler.DownloadGuide Hybrid-Analysis 2018-12-16 00:47:08 2021-08-13 08:15:47
Application.DownloadGuide Hybrid-Analysis 2020-12-07 12:00:22 2021-04-20 20:45:07
Generic.Malware Hybrid-Analysis 2018-12-04 10:30:04 2021-01-22 19:00:31
Application.Bundler.DownloadGuide Hybrid-Analysis 2020-02-20 08:15:16 2020-11-10 06:15:13
Application.Downloader Hybrid-Analysis 2020-01-16 20:47:08 2020-01-16 20:47:08
Malicious site Hybrid-Analysis 2018-11-07 20:45:05 2018-11-07 20:45:05
bundlore Maltiverse 2018-02-13 14:23:39 2018-03-05 13:09:52 S0482 Bundlore
adware,nsis Maltiverse 2018-02-03 22:19:32 2018-02-03 22:19:32

Tags

adware nsis bundlore

Whois information

AS name
AS8075 Microsoft Corporation
AS registry
arin
AS date
2014-05-07 00:00:00
AS CIDR
104.40.0.0/13
CIDR
104.40.0.0/13
Registrant
Microsoft Corporation
Address
One Microsoft Way
City
Washington
State
DC
Postal code
20500
Country
US — United States 🇺🇸
Contact email
[email protected], [email protected], [email protected]
First indexed
2018-02-03 22:19:32
Last updated
2025-11-23 10:54:06