103.157.81.203 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 103.157.81.203 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Likely Malicious Host 🟠 55/100

Host and Network Information

  • Mitre ATT&CK IDs: T1078 - Valid Accounts, T1083 - File and Directory Discovery, T1098.004 - SSH Authorized Keys, T1105 - Ingress Tool Transfer, T1110 - Brute Force, T1110.004 - Credential Stuffing

  • Tags: Nextray, SSH, Scanner, Telnet, Webattack, attack, brute-force, bruteforce, cowrie, cyber security, digital ocean, ioc, login, malicious, phishing, scanner, scanners, scanning, smtp, ssh, tcp, vultr

  • View other sources: Spamhaus VirusTotal

  • Contained within other IP sets: haley_ssh

  • Country: Indonesia
  • Network: AS58369 fiber networks indonesia
  • Noticed: 1 times
  • Protcols Attacked: ssh
  • Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Spain, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
  • Passive DNS Results: agis.link

Open Ports Detected

10000 10134 10243 10250 10443 10554 110 1515 1521 1599 1604 1701 179 19000 1925 1935 20 2000 20000 2002 2008 2022 2050 2064 2065 2067 2070 2081 2082 2083 2086 2087 21 2121 2154 2181 2220 2222 2323 2345 2376 2379 2404 2566 26 2650 27015 27017 2761 2985 3000 3333 3389 35000 37 37777 443 444 4443 4444 445 450 4500 465 4899 5000 5001 5006 5009 5010 5090 515 5222 53 554 5672 587 6002 636 6443 7001 7071 80 8000 8001 8069 8080 8081 8083 8085 8086 8090 8099 82 8443 8500 8554 88 8878 8880 8887 8888 8989 9000 9001 9002 9003 9008 9011 9021 9025 9030 9031 9042 9051 9070 9080 9090 9091 9092 9093 9095 9100 9151 9160 9191 9200 9204 9219 9220 9295 9301 9306 9418 9443 9530 9595 9600 9633 9663 9743 9761 9800 9869 9943 9944 9981 999 9991 9998 9999

CVEs Detected

CVE-2016-10735 CVE-2018-14040 CVE-2018-14042 CVE-2018-20676 CVE-2018-20677 CVE-2019-8331

Map

Whois Information

  • inetnum: 103.157.80.0 - 103.157.81.255
  • netname: IDNIC-KOMISIYUDISIAL-ID
  • descr: Komisi Yudisial RI
  • descr: Government / Direct member IDNIC
  • descr: Jl. Kramat Raya No.57
  • descr: Senen, Kramat
  • descr: Jakarta Pusat 10450
  • admin-c: HSP12-AP
  • tech-c: HSP12-AP
  • country: ID
  • mnt-by: MNT-APJII-ID
  • mnt-irt: IRT-KOMISIYUDISIAL-ID
  • mnt-routes: MAINT-ID-KOMISIYUDISIAL
  • status: ASSIGNED PORTABLE
  • last-modified: 2020-10-15T02:44:17Z
  • irt: IRT-KOMISIYUDISIAL-ID
  • address: Komisi Yudisial RI
  • address: Jl. Kramat Raya No.57
  • address: Senen, Kramat
  • address: Jakarta Pusat 10450
  • e-mail: palinfo@komisiyudisial.com
  • abuse-mailbox: palinfo@komisiyudisial.com
  • admin-c: HSP12-AP
  • tech-c: HSP12-AP
  • mnt-by: MAINT-ID-KOMISIYUDISIAL
  • last-modified: 2020-10-15T01:32:38Z
  • person: Heri Sanjaya Putra
  • address: Komisi Yudisial RI
  • address: Jl. Kramat Raya No.57
  • address: Senen, Kramat
  • address: Jakarta Pusat 10450
  • country: ID
  • phone: +62-21-3905876
  • e-mail: palinfo@komisiyudisial.com
  • nic-hdl: HSP12-AP
  • mnt-by: MNT-APJII-ID
  • fax-no: +62-21-3906215
  • last-modified: 2020-10-15T01:03:07Z
  • route: 103.157.80.0/23
  • descr: Route object for 103.157.80.0/23
  • country: ID
  • origin: AS58369
  • mnt-by: MAINT-FIBERNET-ID
  • last-modified: 2023-03-06T03:18:12Z

Links to attack logs

dolondon-ssh-bruteforce-ip-list-2022-06-24 vultrparis-ssh-bruteforce-ip-list-2022-07-03 dosing-ssh-bruteforce-ip-list-2022-06-15 vultrmadrid-ssh-bruteforce-ip-list-2022-07-02 dotoronto-ssh-bruteforce-ip-list-2022-07-04

Share on: