159.180.84.2

Classification: Suspicious

159.180.84.2 is a suspicious IP address. Linked to Bundlore malware. Reported by 3 threat sources, last seen 2020-03-30. Network: AS33047 Instart Logic Inc.

MITRE ATT&CK associations

Malware families: BUNDLORE (S0482)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic.Malware Hybrid-Analysis 2018-07-29 19:31:00 2020-03-30 15:15:21
Malware site Hybrid-Analysis 2019-03-30 10:30:06 2020-02-26 18:15:48
Phishing site Hybrid-Analysis 2019-05-20 06:00:07 2020-01-17 18:18:38
Malicious site Hybrid-Analysis 2019-01-25 13:30:29 2020-01-17 16:05:58
Trojan.Downloader Hybrid-Analysis 2020-01-15 09:30:07 2020-01-15 09:30:10
Phishing Phishtank 2019-04-15 08:44:59 2019-04-15 08:44:59
bundlore Maltiverse 2018-02-10 17:20:17 2018-02-10 17:20:17 S0482 Bundlore

Tags

bundlore phishing

Whois information

AS name
AS33047 Instart Logic Inc
AS registry
ripencc
AS date
1993-09-01 00:00:00
AS CIDR
159.180.84.0/24
City
Palo Alto
State
CA
Postal code
94301
Country
US — United States 🇺🇸
First indexed
2018-02-10 17:20:17
Last updated
2026-02-12 00:04:30