103.159.64.194 Threat Intelligence and Host Information
General
This page contains threat intelligence information for the IPv4 address 103.159.64.194 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.
Possibly Malicious Host 🟢 25/100
Host and Network Information
-
Mitre ATT&CK IDs: T1110 - Brute Force
-
Tags: Brute-Force, Bruteforce, Nextray, SSH, cyber security, ioc, malicious, phishing
-
View other sources: Spamhaus VirusTotal
- Country: Singapore
- Network: AS395092 shock hosting llc
- Noticed: 1 times
- Protcols Attacked: ntp
- Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
- Passive DNS Results: nat.mllllm.ml wbsg.herola.eu.org sg2023.966988.xyz sgv4.sixsixsix.cf mmllmm.ml sgp.hecan.win sgnat.5206688.xyz sgp.6266888.xyz zmqnever996.icu tiro.gq sgp-webhorizon-fly.7777672.xyz 655558.xyz sgp.655558.xyz wsg.a.eway.za.net china-sg1.99765.xyz box.anj.ink youyou.eu.org sgnat.kbqn.top sg.0002.ga china-sg.99765.xyz xjp256.511118.xyz sgp.fanqiang.de sgnatipv4.ipaopao.xyz xjp256.baolai.cloudns.ph v4.trap.eu.org ssh.budi.asia sg1.kbyyds.xyz whsgpnat.579757.xyz w.affa.eu.org sgo.dothome.cn sgp2wh.freeisfree.tk sig.812000.xyz mllll.ml sgp2.6166888.xyz aws-debian.v2rie.pp.ua sg.fanqiang.de www.isingapore.tk debian.v2rie.pp.ua sg.wsxn.ml webh.justok.club sjv4.851210.xyz gate.echemoo.com whsg.419v.com whsg.ctjin.com 01234.cf sgpwh.freeisfree.tk whsg.521555.xyz sgx02.asia.habang.net
Open Ports Detected
Map
Whois Information
- inetnum: 103.159.64.0 - 103.159.64.255
- netname: SHOCK-SG
- descr: SHOCK-SG
- country: SG
- admin-c: SHLA5-AP
- tech-c: SHLA5-AP
- abuse-c: AS2896-AP
- status: ALLOCATED NON-PORTABLE
- mnt-by: MAINT-SHOCKHOSTINGLLC-AP
- mnt-irt: IRT-SHOCKHOSTINGLLC-AP
- last-modified: 2022-06-24T06:16:52Z
- irt: IRT-SHOCKHOSTINGLLC-AP
- address: 371 Hoes Lane, Suite 200, Piscataway New Jersey 08854
- e-mail: abuse@shockhosting.net
- abuse-mailbox: abuse@shockhosting.net
- admin-c: SHLA5-AP
- tech-c: SHLA5-AP
- mnt-by: MAINT-SHOCKHOSTINGLLC-AP
- last-modified: 2023-06-20T13:15:21Z
- role: ABUSE SHOCKHOSTINGLLCAP
- address: 371 Hoes Lane, Suite 200, Piscataway New Jersey 08854
- country: ZZ
- phone: +000000000
- e-mail: abuse@shockhosting.net
- admin-c: SHLA5-AP
- tech-c: SHLA5-AP
- nic-hdl: AS2896-AP
- abuse-mailbox: abuse@shockhosting.net
- mnt-by: APNIC-ABUSE
- last-modified: 2023-06-20T13:15:43Z
- role: Shock Hosting LLC administrator
- address: 371 Hoes Lane, Suite 200, Piscataway New Jersey 08854
- country: US
- phone: +1-732-812-8020
- e-mail: abuse@shockhosting.net
- admin-c: SHLA5-AP
- tech-c: SHLA5-AP
- nic-hdl: SHLA5-AP
- mnt-by: MAINT-SHOCKHOSTINGLLC-AP
- last-modified: 2020-11-25T05:31:24Z
- route: 103.159.64.0/24
- origin: AS395092
- descr: Shock Hosting LLC
- mnt-by: MAINT-SHOCKHOSTINGLLC-AP
- last-modified: 2021-11-26T10:52:46Z
Links to attack logs
awsau-ntp-bruteforce-ip-list-2021-11-03 awsbah-ntp-bruteforce-ip-list-2021-11-03
Share on: