142.154.32.124
Classification: Neutral
142.154.32.124 is a neutral IP address. Reported by 3 threat sources, last seen 2023-07-17. Network: AS15290 Allstream Corp.
MITRE ATT&CK associations
Malware families: QAKBOT (S0650)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| ET CNC Feodo Tracker Reported CnC Server UDP | Emerging Threats | 2023-06-17 12:45:00 | 2023-07-17 13:02:24 | malicious-activity | |
| ET CNC Feodo Tracker Reported CnC Server TCP | Emerging Threats | 2023-06-17 12:44:55 | 2023-07-17 13:02:20 | malicious-activity | |
| QakBot | FeodoTracker Abuse.ch | 2023-06-16 00:00:34 | 2023-06-18 00:00:25 | malicious-activity | |
| QakBot | ThreatFox Abuse.ch | 2023-06-15 11:17:09 | 2023-06-17 10:20:33 | malicious-activity | S0650 QakBot |
Tags
c&c port:443 oakboat pinkslipbot qbot quakbotWhois information
- AS name
- AS15290 Allstream Corp
- AS registry
- ripencc
- AS date
- 1992-07-23 00:00:00
- AS CIDR
- 142.154.32.0/20
- CIDR
- 142.154.0.0/17
- Address
- P.O Box 295997 11351 Riyadh SAUDI ARABIA
- Country
- SA — Saudi Arabia 🇸🇦
- Contact email
- [email protected]
- First indexed
- 2023-06-15 11:17:09
- Last updated
- 2023-07-17 13:02:24