Cyber Threat Intelligence

Discover malicious IPs and domains with Akamai Guardicore Segmentation

IP Address: 181.111.228.107Previously Malicious

IP Address: 181.111.228.107Previously Malicious

This IP address attempted an attack on a machine in our threat sensors network

Threat Information

Role

Attacker, Connect-Back, Scanner

Services Targeted

SMB

Tags

Outgoing Connection Service Deletion CMD Service Start MSRPC Service Creation Successful SMB Login SMB

Associated Attack Servers

178.62.49.17 183.129.226.162

Basic Information

IP Address

181.111.228.107

Domain

-

ISP

Telecom Argentina S.A.

Country

Argentina

WHOIS

Created Date

2001-12-27

Updated Date

2021-12-13

Organization

TELECOM ARGENTINA SOCIEDAD ANONIMA

First seen in Akamai Guardicore Segmentation

2022-12-19

Last seen in Akamai Guardicore Segmentation

2022-12-19

What is Akamai Guardicore Segmentation
Akamai Guardicore Segmentation is a data center and cloud security solution that protects the organization's core assets, using flexible, quickly deployed and easy to understand micro-segmentation controls. Akamai Guardicore Segmentation generates in-context security incidents, with details on attacker tools and techniques, that help IR teams prioritize incident investigation and reduce dwell time. Learn More

Attack Flow

A user logged in using SMB with the following username: administrator - Authentication policy: Reached Max Attempts

Successful SMB Login

A user logged in using SMB with the following username: administrator - Authentication policy: Previously Approved User 2 times

Successful SMB Login

c:\windows\system32\services.exe installed and started mshta.exe as a service named AC00 under service group None

Service Start Service Creation

Service MSIServer was started

Service Start

Process c:\windows\system32\msiexec.exe generated outgoing network traffic to: 178.62.49.17:14664 and 183.129.226.162:15427

Outgoing Connection

c:\windows\system32\services.exe installed and started mshta.exe as a service named AC03 under service group None

Service Start Service Creation

Connection was closed due to user inactivity