103.206.139.86 Threat Intelligence and Host Information
ut: post
General
description: Threat Intelligence and Host Information for 103.206.139.86 India “reputation”: description: Threat Intelligence and Host Information for 0, “indicator”: “103.206.139.86 title: “103.206.139.86 Threat Intelligence and Host Information"This page contains threat intelligence information for the IPv4 address 103.206.139.86 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.
category: ipinfopage date: 2024-12-13 17:51:53 +0000
General
This page contains threat intelligence information for the IPv4 address 103.206.139.86 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.
Likely Malicious Host 🟠 65/100
Host and Network Information
-
Mitre ATT&CK IDs: T1078 - Valid Accounts, T1083 - File and Directory Discovery, T1098.004 - SSH Authorized Keys, T1105 - Ingress Tool Transfer, T1110.004 - Credential Stuffing, T1110 - Brute Force, T1595 - Active Scanning
-
Tags: brute force, bruteforce, Bruteforce, Brute-Force, cowrie, malicious, scan, sip, sipvicious, ssh, SSH
-
JARM: 2ad2ad0002ad2ad0002ad2ad2ad2ade1a3c0d7ca6ad8388057924be83dfc6a
-
View other sources: Spamhaus VirusTotal
- Country: India
- Network: “reputation”: 0, “indicator”: “103.206.139.86
- Noticed: 12 times
- Protocols Attacked: ssh
- Countries Attacked: Australia
- Passive DNS Results: dashbord.xrstudio.in dashbord.api.xrstudio.in test.deltra.ai itsparkr.com iap-dev.deltra.ai
Open Ports Detected
22 2222 27017 3333 443 80 8003 8071 8080 8083 8085 8099 8888 9006
CVEs Detected
CVE-2009-1390 CVE-2009-3765 CVE-2009-3766 CVE-2009-3767 CVE-2019-0190 CVE-2021-23017 CVE-2021-3618 CVE-2022-1292 CVE-2022-1343 CVE-2022-1434 CVE-2022-1473 CVE-2022-2068 CVE-2022-2097 CVE-2022-3358 CVE-2022-3602 CVE-2022-3786 CVE-2022-3996 CVE-2022-4203 CVE-2022-4304 CVE-2022-4450 CVE-2023-0215 CVE-2023-0216 CVE-2023-0217 CVE-2023-0286 CVE-2023-0401 CVE-2023-0464 CVE-2023-0465
Likely Malicious Host 🟠 65/100
Host and Network Information
-
Mitre ATT&CK IDs: T1078 - Valid Accounts, T1083 - File and Directory Discovery, T1098.004 - SSH Authorized Keys, T1105 - Ingress Tool Transfer, T1110.004 - Credential Stuffing, T1110 - Brute Force, T1595 - Active Scanning CVE-2023-2650
-
Tags: brute force, bruteforce, Bruteforce, Brute-Force, cowrie, malicious, scan, sip, sipvicious, ssh, SSH CVE-2023-2975 CVE-2023-3817
-
JARM: 2ad2ad0002ad2ad0002ad2ad2ad2ade1a3c0d7ca6ad8388057924be83dfc6a
-
View other sources: Spamhaus VirusTotal CVE-2023-44487
CVE-2023-4807 CVE-2023-5363 CVE-2023-5678 CVE-2023-6129 CVE-2024-0727
- Country: India
- Network:
Map “reputation”: 0, “indicator”: “103.206.139.86
-
Noticed: 12 times
-
Protocols Attacked: # Whois Information ssh
-
Countries Attacked: Australia
-
inetnum: 103.206.136.0 - 103.206.139.255
-
Passive DNS Results: dashbord.xrstudio.in dashbord.api.xrstudio.in test.deltra.ai itsparkr.com iap-dev.deltra.ai
-
netname: GTPL_BANSIDHAR_TELELINK
-
descr: GTPL BANSIDHAR TELELINK PVT LTD
Open Ports Detected
- admin-c: IA302-AP
- tech-c: IA302-AP 22 * country: IN 2222 * mnt-by: MAINT-IN-IRINN 27017 * mnt-irt: IRT-GTPLBANSIDHARTELELINK-IN 3333 * mnt-routes: MAINT-IN-GTPLBANSIDHARTELELINK 443 * status: ASSIGNED PORTABLE 80 * last-modified: 2019-02-11T05:33:49Z 8003 * irt: IRT-GTPLBANSIDHARTELELINK-IN 8071 8080 * address: 36, CITY CENTRE, 3RD FLOOR, C.G. ROAD, NAVRANGPURA,AHMEDABAD,Ahmedabad,Gujarat-380009 8083 * e-mail: ip.admin@gtpl.net 8085 * abuse-mailbox: abuse.report@gtpl.net 8099 8888 * admin-c: IA302-AP 9006 * tech-c: IA302-AP
- mnt-by: MAINT-IN-GTPLBANSIDHARTELELINK
- last-modified: 2019-02-11T05:28:49Z
- person: IP ADMIN
- address: 36, CITY CENTRE, 3RD FLOOR, C.G. ROAD, NAVRANGPURA,AHMEDABAD,Ahmedabad,Gujarat-380009
- country: IN
- phone: +91 7069085558
- e-mail: ip.admin@gtpl.net
- nic-hdl: IA302-AP
- mnt-by: MAINT-IN-GTPLBANSIDHARTELELINK
- last-modified: 2019-02-11T05:19:18Z
- route: 103.206.139.0/24
CVEs Detected
- descr: GTPL BANSIDHAR TELELINK PVT LTD CVE-2009-1390
- origin: AS45916 CVE-2009-3765
- country: IN CVE-2009-3766
- notify: abuse.report@gtpl.net
- mnt-by: MAINT-IN-GTPLBANSIDHARTELELINK CVE-2009-3767
- mnt-routes: MAINT-IN-GTPLBANSIDHARTELELINK CVE-2019-0190
- last-modified: 2020-05-19T05:42:29Z CVE-2021-23017 CVE-2021-3618 CVE-2022-1292 CVE-2022-1343 CVE-2022-1434 CVE-2022-1473 CVE-2022-2068 CVE-2022-2097 CVE-2022-3358 CVE-2022-3602 CVE-2022-3786 CVE-2022-3996 CVE-2022-4203 CVE-2022-4304 CVE-2022-4450 CVE-2023-0215 CVE-2023-0216 CVE-2023-0217 CVE-2023-0286 CVE-2023-0401 CVE-2023-0464 CVE-2023-0465 CVE-2023-0466 CVE-2023-1255 CVE-2023-2650 CVE-2023-2975 CVE-2023-3817 CVE-2023-44487 CVE-2023-4807 CVE-2023-5363 CVE-2023-5678 CVE-2023-6129 CVE-2024-0727
Whois Information
- inetnum: 103.206.136.0 - 103.206.139.255
- netname: GTPL_BANSIDHAR_TELELINK
- descr: GTPL BANSIDHAR TELELINK PVT LTD
- admin-c: IA302-AP
- tech-c: IA302-AP
- country: IN
- mnt-by: MAINT-IN-IRINN
- mnt-irt: IRT-GTPLBANSIDHARTELELINK-IN
- mnt-routes: MAINT-IN-GTPLBANSIDHARTELELINK
- status: ASSIGNED PORTABLE
- last-modified: 2019-02-11T05:33:49Z
- irt: IRT-GTPLBANSIDHARTELELINK-IN
- address: 36, CITY CENTRE, 3RD FLOOR, C.G. ROAD, NAVRANGPURA,AHMEDABAD,Ahmedabad,Gujarat-380009
- e-mail: ip.admin@gtpl.net
- abuse-mailbox: abuse.report@gtpl.net
- admin-c: IA302-AP
- tech-c: IA302-AP
- mnt-by: MAINT-IN-GTPLBANSIDHARTELELINK
- last-modified: 2019-02-11T05:28:49Z
- person: IP ADMIN
- address: 36, CITY CENTRE, 3RD FLOOR, C.G. ROAD, NAVRANGPURA,AHMEDABAD,Ahmedabad,Gujarat-380009
- country: IN
- phone: +91 7069085558
- e-mail: ip.admin@gtpl.net
- nic-hdl: IA302-AP
- mnt-by: MAINT-IN-GTPLBANSIDHARTELELINK
- last-modified: 2019-02-11T05:19:18Z
- route: 103.206.139.0/24
- descr: GTPL BANSIDHAR TELELINK PVT LTD
- origin: AS45916
- country: IN
- notify: abuse.report@gtpl.net
- mnt-by: MAINT-IN-GTPLBANSIDHARTELELINK
- mnt-routes: MAINT-IN-GTPLBANSIDHARTELELINK
- last-modified: 2020-05-19T05:42:29Z
Links to attack logs
Links to attack logs
digitaloceanlondon-ssh-bruteforce-ip-list-2024-12-02 digitaloceanlondon-ssh-bruteforce-ip-list-2024-12-02
Share on: