52.45.178.122

Classification: Suspicious

52.45.178.122 is a suspicious IP address. Linked to Jhuhugit malware. Reported by 5 threat sources, last seen 2022-01-16.

MITRE ATT&CK associations

Malware families: JHUHUGIT (S0044)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Gen:Variant.Sofacy Hybrid-Analysis 2021-10-13 06:30:14 2022-01-16 13:00:18
Malware site Hybrid-Analysis 2018-09-19 21:15:15 2021-10-28 15:15:42
Gen:Variant.Ser.Ursu Hybrid-Analysis 2021-10-10 09:30:46 2021-10-10 09:30:46
Gen:Variant.Graftor Hybrid-Analysis 2021-10-10 09:30:41 2021-10-10 09:30:41
Gen:Variant.Ursu Hybrid-Analysis 2020-05-04 00:15:42 2020-05-04 00:15:42
Malicious site Hybrid-Analysis 2019-03-26 19:15:22 2020-04-29 19:45:08
Gen:Variant.Razy Hybrid-Analysis 2020-04-24 14:46:08 2020-04-24 14:46:08
Worm.Agent Hybrid-Analysis 2020-04-24 14:45:28 2020-04-24 14:45:28
Trojan.MiniDuke Hybrid-Analysis 2020-04-17 03:19:12 2020-04-17 03:19:13
Trojan.Sofacy Hybrid-Analysis 2020-04-02 09:00:22 2020-04-02 09:00:22 S0044 JHUHUGIT
VB:Trojan.Valyria Hybrid-Analysis 2019-09-18 15:00:27 2019-10-21 21:30:06
apt Maltiverse Research Team 2019-10-08 15:59:14 2019-10-08 15:59:14
Trojan.Delphocy Hybrid-Analysis 2019-02-27 13:18:43 2019-02-27 13:18:43
Botnet Command and Control Server IBM X-Force Exchange 2018-10-09 22:09:00 2019-02-04 05:15:00
Malicious Host APT Notes 2019-01-12 08:41:50 2019-01-12 08:42:24
Trojan.MSWord.Agent Hybrid-Analysis 2018-10-30 21:00:49 2018-10-30 21:00:49
Gen:Variant.BlackEnergy Hybrid-Analysis 2018-09-21 06:45:09 2018-09-21 06:45:09
Slingshot Maltiverse Research Team 2018-05-15 09:48:22 2018-05-15 09:48:22
apt,apt28,apt29,infostealer,qakbot,sednit,sofacy,zemot Maltiverse 2017-12-24 22:46:00 2017-12-24 22:46:00

Tags

apt apt28 apt29 infostealer qakbot sednit sofacy zemot nato https://www.threatminer.org/report.php?q=a song of intel and fancy _ exploiting fancy bear’s use of ssl certificate.pdf&y=2018

Whois information

AS name
AS14618 Amazon Technologies Inc.
AS registry
arin
AS date
2015-09-02 00:00:00
AS CIDR
52.44.0.0/15
CIDR
52.32.0.0/11
Registrant
Amazon Technologies Inc.
Address
410 Terry Ave N.
City
Ashburn
State
VA
Postal code
20147
Country
US — United States 🇺🇸
Contact email
[email protected], [email protected]
First indexed
2017-12-24 22:46:00
Last updated
2025-11-13 00:28:38

Malicious IPs in the same CIDR

52.45.77.169 52.45.194.165 52.44.229.124 52.45.92.83 52.44.148.203 52.44.174.136 52.45.29.57 52.45.146.35 52.45.15.233