45.9.148.122
Classification: Suspicious
45.9.148.122 is a suspicious IP address. Linked to Cobalt Strike malware. Reported by 5 threat sources, last seen 2026-08-20.
Current activity
- TOR node — Part of the TOR anonymization network.
- Open proxy — Provides anonymization that can hide an attacker.
MITRE ATT&CK associations
Malware families: COBALT STRIKE (S0154)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic | Emerging Threats | 2026-07-21 13:02:23 | 2026-08-20 11:02:32 | anomalous-activity anonymization tor | |
| ET TOR Known Tor Exit Node TCP Traffic | Emerging Threats | 2026-07-21 13:01:40 | 2026-08-20 11:01:43 | anomalous-activity anonymization tor | |
| TOR Exit Node | TorProject.org | 2026-07-18 12:03:03 | 2026-08-18 10:03:05 | anomalous-activity anonymization tor | |
| Proxy | IPWhois.io | 2026-08-17 08:51:13 | 2026-08-17 08:51:13 | anonymization proxy | |
| Anonymizer | FireHOL | 2026-07-18 20:37:29 | 2026-08-04 20:24:49 | anomalous-activity anonymization | |
| Proxy | FireHOL | 2026-07-31 21:58:09 | 2026-08-02 21:58:11 | anomalous-activity anonymization proxy | |
| Cobalt Strike | ThreatFox Abuse.ch | 2022-09-18 15:19:05 | 2022-09-20 14:18:46 | malicious-activity | S0154 Cobalt Strike |
Tags
cobaltstrike niceit port:80 agentemis beacon cobeacon tor anonymizationWhois information
- AS name
- AS49447 Nice IT Customers Network
- AS registry
- ripencc
- AS date
- 2019-04-18 00:00:00
- AS CIDR
- 45.9.148.0/24
- CIDR
- 45.9.148.0/25
- Registrant
- Nice IT Customers Network
- Address
- 28 Cork Street, Roseau, Dominica
- City
- Amsterdam
- Postal code
- 1012 AB
- Country
- NL — Netherlands 🇳🇱
- First indexed
- 2022-09-18 15:19:05
- Last updated
- 2026-08-20 11:02:32