45.9.148.122

Classification: Suspicious

45.9.148.122 is a suspicious IP address. Linked to Cobalt Strike malware. Reported by 5 threat sources, last seen 2026-08-20.

Current activity

  • TOR node — Part of the TOR anonymization network.
  • Open proxy — Provides anonymization that can hide an attacker.

MITRE ATT&CK associations

Malware families: COBALT STRIKE (S0154)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic Emerging Threats 2026-07-21 13:02:23 2026-08-20 11:02:32 anomalous-activity anonymization tor
ET TOR Known Tor Exit Node TCP Traffic Emerging Threats 2026-07-21 13:01:40 2026-08-20 11:01:43 anomalous-activity anonymization tor
TOR Exit Node TorProject.org 2026-07-18 12:03:03 2026-08-18 10:03:05 anomalous-activity anonymization tor
Proxy IPWhois.io 2026-08-17 08:51:13 2026-08-17 08:51:13 anonymization proxy
Anonymizer FireHOL 2026-07-18 20:37:29 2026-08-04 20:24:49 anomalous-activity anonymization
Proxy FireHOL 2026-07-31 21:58:09 2026-08-02 21:58:11 anomalous-activity anonymization proxy
Cobalt Strike ThreatFox Abuse.ch 2022-09-18 15:19:05 2022-09-20 14:18:46 malicious-activity S0154 Cobalt Strike

Tags

cobaltstrike niceit port:80 agentemis beacon cobeacon tor anonymization

Whois information

AS name
AS49447 Nice IT Customers Network
AS registry
ripencc
AS date
2019-04-18 00:00:00
AS CIDR
45.9.148.0/24
CIDR
45.9.148.0/25
Registrant
Nice IT Customers Network
Address
28 Cork Street, Roseau, Dominica
City
Amsterdam
Postal code
1012 AB
Country
NL — Netherlands 🇳🇱
First indexed
2022-09-18 15:19:05
Last updated
2026-08-20 11:02:32

Malicious IPs in the same CIDR

45.9.148.50 45.9.148.37 45.9.148.65 45.9.148.138