206.54.161.139
Classification: Suspicious
206.54.161.139 is a suspicious IP address. Linked to Bundlore malware. Reported by 2 threat sources, last seen 2018-05-05. Network: AS35415 Webzilla B.V..
MITRE ATT&CK associations
Malware families: BUNDLORE (S0482)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Application.Bundler.FileTour | Hybrid-Analysis | 2018-05-02 17:15:18 | 2018-05-05 09:00:13 | ||
| FileTour | Hybrid-Analysis | 2018-04-30 00:15:26 | 2018-04-30 00:15:26 | ||
| Generic.Malware | Hybrid-Analysis | 2018-04-28 22:45:16 | 2018-04-28 22:45:16 | ||
| Adware.FileTour | Hybrid-Analysis | 2018-04-07 19:31:03 | 2018-04-24 18:01:55 | ||
| Adware | Hybrid-Analysis | 2018-04-21 16:00:15 | 2018-04-21 16:00:15 | ||
| evasive | Maltiverse | 2018-03-19 01:31:36 | 2018-03-19 01:31:36 | ||
| bundlore | Maltiverse | 2018-03-14 14:46:20 | 2018-03-14 14:46:20 | S0482 Bundlore |
Tags
bundlore evasive coinminer downloader minerWhois information
- AS name
- AS35415 Webzilla B.V.
- AS registry
- arin
- AS date
- 1995-07-06 00:00:00
- AS CIDR
- 206.54.160.0/21
- CIDR
- 206.54.160.0/19
- Registrant
- Webzilla B.V.
- Address
- 8528 Davis Blvd, Suite 340
- City
- Amsterdam
- State
- TX
- Postal code
- 1012 JS
- Country
- NL — Netherlands 🇳🇱
- Contact email
- [email protected]
- First indexed
- 2018-03-14 14:46:20
- Last updated
- 2025-11-11 05:34:52