103.21.59.20 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 103.21.59.20 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Likely Malicious Host 🟠 64/100

Host and Network Information

  • Mitre ATT&CK IDs: T1021.001 - Remote Desktop Protocol, T1110 - Brute Force, T1184 - SSH Hijacking, T1192 - Spearphishing Link, T1194 - Spearphishing via Service, T1442 - Fake Developer Accounts, T1454 - Malicious SMS Message, T1566 - Phishing, T1583.001 - Domains, T1583.006 - Web Services, T1585.001 - Social Media Accounts, T1586 - Compromise Accounts, T1591.002 - Business Relationships

  • Tags: anydesk, as15169 as16509, as19871 as22612, as9002, business email compromise, c2, caas, fraud, hosting, identifying, parked domains, scams, ssh hijacking, typosquatting

  • JARM: 29d29d15d29d29d00042d42d0000009435214b849738c4ebab4534b5d158dd

  • View other sources: Spamhaus VirusTotal

  • Contained within other IP sets: hphosts_emd, hphosts_fsa, hphosts_psh

Malware Detected on Host

Count: 29 5eebc27b788e24513dde65544e42c64fb49da1e2ab2e2e4af83c80a71a330f4f d61f0c2b1f425eb550f1bd89ab141f85a79dc530f92dbf9f2495d0a032a88c15 8180b0843fbb9cfc16bf2c332c22ead035fe2755a9db718c5278311da658d178 20bb36f0abb4b58bb46239272dfc15e0ccc80d342862a6432e562c1587f62d73 b9c80d25a7c2bd91393698dfe51df6e410ebb5a3ecd1c8648e2443801d2e9be0 ef9d21a80ea979ee6ae94c9aa1416ffb78aaeb10d6f2a8878974395de9871bdf 607bf2c459faa62b12c87c8106c6fb91b55908928107c35b9c4d5433ea3f3c5f 529f02f3554492cb06ca4b63fe7b573d5a4ffa4eb9a3a2ab6a4cf20201a9ef43 0e8acca5bc2b595b9acbcb113a43893042ec586883ec57dd42a8b65a7ad4a1f7 7b16a9de98cf988e7b3a645d74cc6b34a0e5a8276fc8da430b7bc97b23ee80e0

Map

Whois Information

  • inetnum: 103.21.59.0 - 103.21.59.255
  • netname: PDRSOLUTIONSFZC-AP
  • descr: P.D.R Solutions FZC
  • country: IN
  • geoloc: 19.1140343 72.8921789
  • admin-c: PSFA1-AP
  • tech-c: PSFA1-AP
  • abuse-c: AI346-AP
  • status: ALLOCATED NON-PORTABLE
  • mnt-by: MAINT-IN-AP
  • mnt-irt: IRT-IN-GPX
  • last-modified: 2021-01-06T13:12:21Z
  • irt: IRT-IN-GPX
  • address: GPX India. Unit A-001 Boomerang Chandivali Farm Road Andheri East, Mumbai 400072, India
  • e-mail: ipadmin@publicdomainregistry.com
  • abuse-mailbox: abuse@publicdomainregistry.com
  • admin-c: PSFA1-AP
  • tech-c: PSFA1-AP
  • mnt-by: MAINT-IN-AP
  • last-modified: 2025-04-30T13:05:47Z
  • role: ABUSE INGPX
  • country: ZZ
  • address: GPX India. Unit A-001 Boomerang Chandivali Farm Road Andheri East, Mumbai 400072, India
  • phone: +000000000
  • e-mail: ipadmin@publicdomainregistry.com
  • admin-c: PSFA1-AP
  • tech-c: PSFA1-AP
  • nic-hdl: AI346-AP
  • abuse-mailbox: abuse@publicdomainregistry.com
  • mnt-by: APNIC-ABUSE
  • last-modified: 2025-04-30T13:05:47Z
  • role: PDR Solutions FZC administrator
  • address: P.D.R Solutions FZC,, F-20, Business Center 1,, Business Park, RAK Free Trade Zone, Ras Al Khaimah
  • country: AE
  • phone: +14152300648
  • fax-no: +14152300648
  • e-mail: abuse@publicdomainregistry.com
  • admin-c: PSFA1-AP
  • tech-c: PSFA1-AP
  • nic-hdl: PSFA1-AP
  • mnt-by: MAINT-PDRSOLUTIONSFZC-AP
  • last-modified: 2017-03-08T17:17:21Z

Links to attack logs

****** ****** ******

Share on: