1.0.0.50 Threat Intelligence and Host Information

Share on:

General

This page was generated as a result of this host being detected actively attacking or scanning another host. See below for information related to the host network, location, number of days noticed, protocols attacked and other information including reverse DNS and whois.

Host and Network Information

  • Mitre ATT&CK IDs: T1500 - Compile After Delivery
  • Tags: Monero Mining Worm using EternalBlue Exploit
  • View other sources: Spamhaus VirusTotal
  • Contained within other IP sets: dm_tor, hphosts_emd, hphosts_psh, lashback_ubl

  • Country: Australia
  • Network: AS13335 cloudflare
  • Noticed: 2 times
  • Protcols Attacked: telnet
  • Countries Attacked: United States of America
  • Passive DNS Results: www.lsqcgs.com www.yunzhongzhuan.com cdn-static-www.yunzhongzhuan.com www.zgzb88.com www.hzzrsw.com root.leafwolf.net funnews7.com www.wpdcjt.com www.leafwolf.net gamebook88.com leafwolf.net mb-crystal.com wpdcjt.com gamer28.com suidoyahk.com www.suidoyahk.com 234ac.com www.wpdc.top wpdc.top www.hum.ink hum.ink 52happyday.com wpfdc.net www.wpfdc.net device8112007-055e9b56-local.wd2go.com cf.n5.jcdpn.cn 1688game.com gamehse.com data.uid.hk ipv4.cdn.harkin.cc s3.amazonaws.com www.twoo.com scontent.xx.fbcdn.net chart.googleapis.com

Malware Detected on Host

Count: 2 3efcb5e3a506cd073d2df5f6e4b9f89055f527458ff87c65c4e7317f337ed5da aeb3d5ec1d144a7b2d51bdb603c052fd52700defb1b039491c4df3f32ece517a

Open Ports Detected

2052 2082 2086 2087 2096 443 80 8443

Map

Whois Information

  • inetnum: 1.0.0.0 - 1.0.0.255
  • netname: APNIC-LABS
  • descr: APNIC and Cloudflare DNS Resolver project
  • descr: Routed globally by AS13335/Cloudflare
  • descr: Research prefix for APNIC Labs
  • country: AU
  • org: ORG-ARAD1-AP
  • admin-c: AR302-AP
  • tech-c: AR302-AP
  • abuse-c: AA1412-AP
  • status: ASSIGNED PORTABLE
  • mnt-by: APNIC-HM
  • mnt-routes: MAINT-AU-APNIC-GM85-AP
  • mnt-irt: IRT-APNICRANDNET-AU
  • last-modified: 2020-07-15T13:10:57Z
  • irt: IRT-APNICRANDNET-AU
  • address: PO Box 3646
  • address: South Brisbane, QLD 4101
  • address: Australia
  • e-mail: [email protected]
  • abuse-mailbox: [email protected]
  • admin-c: AR302-AP
  • tech-c: AR302-AP
  • mnt-by: MAINT-AU-APNIC-GM85-AP
  • last-modified: 2021-03-09T01:10:21Z
  • organisation: ORG-ARAD1-AP
  • org-name: APNIC Research and Development
  • country: AU
  • address: 6 Cordelia St
  • phone: +61-7-38583100
  • fax-no: +61-7-38583199
  • e-mail: [email protected]
  • mnt-ref: APNIC-HM
  • mnt-by: APNIC-HM
  • last-modified: 2017-10-11T01:28:39Z
  • role: ABUSE APNICRANDNETAU
  • address: PO Box 3646
  • address: South Brisbane, QLD 4101
  • address: Australia
  • country: ZZ
  • phone: +000000000
  • e-mail: [email protected]
  • admin-c: AR302-AP
  • tech-c: AR302-AP
  • nic-hdl: AA1412-AP
  • abuse-mailbox: [email protected]
  • mnt-by: APNIC-ABUSE
  • last-modified: 2021-03-09T01:10:22Z
  • role: APNIC RESEARCH
  • address: PO Box 3646
  • address: South Brisbane, QLD 4101
  • address: Australia
  • country: AU
  • phone: +61-7-3858-3188
  • fax-no: +61-7-3858-3199
  • e-mail: [email protected]
  • nic-hdl: AR302-AP
  • tech-c: AH256-AP
  • admin-c: AH256-AP
  • mnt-by: MAINT-APNIC-AP
  • last-modified: 2018-04-04T04:26:04Z
  • route: 1.0.0.0/24
  • origin: AS13335
  • descr: APNIC Research and Development
  • mnt-by: MAINT-AU-APNIC-GM85-AP
  • last-modified: 2018-03-16T16:58:27Z

Links to attack logs

b2b-backup_com-domain-info bruteforce-files-list-2021-04-11 the-bitcoin-desk_com-domain-info bitcoinkompanie_com-domain-info schnelltest-corona_nrw-domain-info banksybbay_com-domain-info awsau-telnet-bruteforce-ip-list-2022-04-02 b2bbackup_com-domain-info khanzaman_net-domain-info alibabavinyl_com-domain-info