52.45.178.122
Classification: Suspicious
52.45.178.122 is a suspicious IP address. Linked to Jhuhugit malware. Reported by 5 threat sources, last seen 2022-01-16.
MITRE ATT&CK associations
Malware families: JHUHUGIT (S0044)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Gen:Variant.Sofacy | Hybrid-Analysis | 2021-10-13 06:30:14 | 2022-01-16 13:00:18 | ||
| Malware site | Hybrid-Analysis | 2018-09-19 21:15:15 | 2021-10-28 15:15:42 | ||
| Gen:Variant.Ser.Ursu | Hybrid-Analysis | 2021-10-10 09:30:46 | 2021-10-10 09:30:46 | ||
| Gen:Variant.Graftor | Hybrid-Analysis | 2021-10-10 09:30:41 | 2021-10-10 09:30:41 | ||
| Gen:Variant.Ursu | Hybrid-Analysis | 2020-05-04 00:15:42 | 2020-05-04 00:15:42 | ||
| Malicious site | Hybrid-Analysis | 2019-03-26 19:15:22 | 2020-04-29 19:45:08 | ||
| Gen:Variant.Razy | Hybrid-Analysis | 2020-04-24 14:46:08 | 2020-04-24 14:46:08 | ||
| Worm.Agent | Hybrid-Analysis | 2020-04-24 14:45:28 | 2020-04-24 14:45:28 | ||
| Trojan.MiniDuke | Hybrid-Analysis | 2020-04-17 03:19:12 | 2020-04-17 03:19:13 | ||
| Trojan.Sofacy | Hybrid-Analysis | 2020-04-02 09:00:22 | 2020-04-02 09:00:22 | S0044 JHUHUGIT | |
| VB:Trojan.Valyria | Hybrid-Analysis | 2019-09-18 15:00:27 | 2019-10-21 21:30:06 | ||
| apt | Maltiverse Research Team | 2019-10-08 15:59:14 | 2019-10-08 15:59:14 | ||
| Trojan.Delphocy | Hybrid-Analysis | 2019-02-27 13:18:43 | 2019-02-27 13:18:43 | ||
| Botnet Command and Control Server | IBM X-Force Exchange | 2018-10-09 22:09:00 | 2019-02-04 05:15:00 | ||
| Malicious Host | APT Notes | 2019-01-12 08:41:50 | 2019-01-12 08:42:24 | ||
| Trojan.MSWord.Agent | Hybrid-Analysis | 2018-10-30 21:00:49 | 2018-10-30 21:00:49 | ||
| Gen:Variant.BlackEnergy | Hybrid-Analysis | 2018-09-21 06:45:09 | 2018-09-21 06:45:09 | ||
| Slingshot | Maltiverse Research Team | 2018-05-15 09:48:22 | 2018-05-15 09:48:22 | ||
| apt,apt28,apt29,infostealer,qakbot,sednit,sofacy,zemot | Maltiverse | 2017-12-24 22:46:00 | 2017-12-24 22:46:00 |
Tags
apt apt28 apt29 infostealer qakbot sednit sofacy zemot nato https://www.threatminer.org/report.php?q=a song of intel and fancy _ exploiting fancy bear’s use of ssl certificate.pdf&y=2018Whois information
- AS name
- AS14618 Amazon Technologies Inc.
- AS registry
- arin
- AS date
- 2015-09-02 00:00:00
- AS CIDR
- 52.44.0.0/15
- CIDR
- 52.32.0.0/11
- Registrant
- Amazon Technologies Inc.
- Address
- 410 Terry Ave N.
- City
- Ashburn
- State
- VA
- Postal code
- 20147
- Country
- US — United States 🇺🇸
- Contact email
- [email protected], [email protected]
- First indexed
- 2017-12-24 22:46:00
- Last updated
- 2025-11-13 00:28:38
Malicious IPs in the same CIDR
52.45.77.169 52.45.194.165 52.44.229.124 52.45.92.83 52.44.148.203 52.44.174.136 52.45.29.57 52.45.146.35 52.45.15.233