Intelligence View
SOCKS Proxy List - 12/17/2019 by Tisocks.net
SOCKS Proxy List by Tisocks.net If you Need Socks5 , Please visit service and add fund via PM , BTC WMZ . Thanks all!! Add fund : https://tisocks.net/addfund Check socks5 Online here : https://checksocks5.com LIVE | 208.113.155.7:57069 |…
If you Need Socks5 , Please visit service and add fund via PM , BTC WMZ . Thanks all!!
Add fund : https://tisocks.net/addfund
Check socks5 Online here : https://checksocks5.com
LIVE | 208.113.155.7:57069 | 0.131 | SOCKS5 | California | 92821 | frederick.dreamhost.com | United States | Checked at https://tisocks.net
LIVE | 75.119.206.59:6514 | 0.29 | SOCKS5 | California | 92821 | mactarnahans.dreamhost.com | United States | Checked at https://tisocks.net
LIVE | 75.119.202.37:6514 | 0.31 | SOCKS5 | California | 92821 | mactarnahans.dreamhost.com | United States | Checked at https://tisocks.net
LIVE | 208.113.155.93:54879 | 0.083 | SOCKS5 | California | 92821 | frederick.dreamhost.com | United States | Checked at https://tisocks.net
LIVE | 54.36.244.128:42828 | 0.818 | SOCKS5 | Texas | 77379 | c-73-232-9-97.hsd1.tx.comcast.net | United States | Checked at https://tisocks.net
LIVE | 208.113.220.122:55295 | 0.675 | SOCKS5 | California | 92821 | xlglass.net | United States | Checked at https://tisocks.net
LIVE | 75.119.206.132:6514 | 0.296 | SOCKS5 | California | 92821 | mactarnahans.dreamhost.com | United States | Checked at https://tisocks.net
LIVE | 192.169.244.80:7308 | 0.281 | SOCKS5 | Arizona | 85260 | ip-192-169-244-80.ip.secureserver.net | United States | Checked at https://tisocks.net
LIVE | 192.169.197.122:8946 | 0.279 | SOCKS5 | Arizona | 85260 | ip-192-169-197-122.ip.secureserver.net | United States | Checked at https://tisocks.net
LIVE | 192.169.244.80:1138 | 0.28 | SOCKS5 | Arizona | 85260 | ip-192-169-244-80.ip.secureserver.net | United States | Checked at https://tisocks.net
LIVE | 173.236.182.125:18174 | 0.11 | SOCKS5 | California | 92821 | flying.dreamhost.com | United States | Checked at https://tisocks.net
LIVE | 64.90.50.215:16502 | 0.946 | SOCKS5 | California | 92821 | sublimity.dreamhost.com | United States | Checked at https://tisocks.net
LIVE | 64.90.49.92:19980 | 1.363 | SOCKS5 | California | 92821 | vale.dreamhost.com | United States | Checked at https://tisocks.net
LIVE | 64.90.50.97:19980 | 1.439 | SOCKS5 | California | 92821 | vale.dreamhost.com | United States | Checked at https://tisocks.net
LIVE | 208.113.222.63:55295 | 0.729 | SOCKS5 | California | 92821 | xlglass.net | United States | Checked at https://tisocks.net
LIVE | 75.119.207.160:6514 | 0.294 | SOCKS5 | California | 92821 | mactarnahans.dreamhost.com | United States | Checked at https://tisocks.net
SOC Incident Playbook: Vulnerability Remediation & Verification
title: Detect Exploitation - SOCKS Proxy List - 12/17/2019 by Tisocks.net
id: 1d01c81b-9d5b-460e-b2f4-78cd35fd098c
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
- https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-24
logsource:
category: network_connection
product: any
detection:
selection:
DestinationIp:
- '208.113.155.7'
- '75.119.206.59'
- '75.119.202.37'
- '208.113.155.93'
- '54.36.244.128'
condition: selection
falsepositives:
- Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
- attack.initial_accessrule CTI_Threat_Indicator {
meta:
author = "iShareStuff CTI Automated Detection Engine"
date = "2026-09-24"
description = "YARA Signature for "
strings:
$str = "SOCKS Proxy List - 12/17/2019 " ascii wide
condition:
any of them
}index=security sourcetype IN ("cisco:asa", "pan:traffic", "zeek_conn", "suricata", "WinEventLog:Security")
(dest_ip="208.113.155.7" OR dest_ip="75.119.206.59" OR dest_ip="75.119.202.37" OR dest_ip="208.113.155.93" OR dest_ip="54.36.244.128")
| stats count earliest(_time) as first_seen latest(_time) as last_seen by src_ip, dest_ip, dest_host, signature
| eval first_seen=strftime(first_seen, "%Y-%m-%d %H:%M:%S"), last_seen=strftime(last_seen, "%Y-%m-%d %H:%M:%S")
| sort - countdestination.ip: ("208.113.155.7" OR "75.119.206.59" OR "75.119.202.37" OR "208.113.155.93" OR "54.36.244.128") and event.category: "network"CommonSecurityLog
| where DestinationIP in ("208.113.155.7", "75.119.206.59", "75.119.202.37", "208.113.155.93", "54.36.244.128")
| summarize EventCount = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated) by SourceIP, DestinationIP, DestinationPort, Activity
| extend DetectionRule = "iShareStuff-CTI-Compiled"
| sort by EventCount descMITRE ATT&CK Matrix Navigator 14 Taktiken
tsecurity.de Cognitive Threat RAG
Kognitive Analyse für identifizierte Bedrohung: Erhöhte Bedrohungslage im Bereich SOCKS Proxy List - 12/17/2019 by Tisocks.... Basierend auf 368k Vektor-Korrelationen werden sofortige Isolationsmaßnahmen für betroffene Endpunkte empfohlen.
Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.
- 1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
- 2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
- 3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
SOCIAL SHARE CARD GENERATOR