103.252.89.75 Threat Intelligence and Host Information

General

IP Address
103.252.89.75
IPv4 Address
Location
🇩🇪 Germany
DE
Network
AS44486
SYNLINQ
Threat Score
47/100
Medium Risk
2026-012026-0232-bitAdbhoneyArkeiStealerAsyncRATAutomatedBRAT
Attack Intelligence
MITRE ATT&CK Techniques
T1595 - Active Scanning
Open Ports Detected
21
Geographic Location
Country
Germany
City
Unknown
Region
Unknown
Coordinates
51.2993, 9.4910
Network Information
ASN
AS44486
Organization
SYNLINQ
Network
AS44486 SYNLINQ
WHOIS Information
inetnum
103.252.88.0 - 103.252.91.255
netname
STUB-103-252-88SLASH22
descr
Transferred to the RIPE region on 2016-11-15T01:28:16Z.
country
ZZ
admin-c
STUB-AP
tech-c
STUB-AP
abuse-c
AS2444-AP
status
ALLOCATED PORTABLE
mnt-by
APNIC-HM
mnt-irt
IRT-STUB-AP
last-modified
2019-09-23T04:53:33Z
irt
IRT-STUB-AP
address
N/A
e-mail
no-email@apnic.net
abuse-mailbox
no-email@apnic.net
role
ABUSE STUBAP
phone
+00 0000 0000
nic-hdl
STUB-AP
person
STUB PERSON

  • Country: Germany
  • Network:
  • Noticed: 1 times
  • Protocols Attacked: SSH
  • Countries Attacked: Australia

Malware Detected on Host

Count: 10 e3dbf99f183b730dc29db817ee5ec20005c78f8ccd0900b9778e8d0fe861e4b9 88818a3fb001fea321c200157c436100e0a33de5d1fb12533564400fbfc7a017 afcc19f473fab8b4e506abefe624796f92378dcbd99d0831ad2960faec492b73 719a7dc3992791fa8d03ea20cba8fc23ffd79dd70fb3bf904ac0d76715f18d14 cf06e258e721169d18401a20085bd449c39dacea2b2da351703394f83a604d5e eb9813e8037237af6d8b71418596988755147a025b885c1627d4c07b2802b00d e55ee7ca95beca998c6bc5f728ec0c2d1fa8af88a3bc54c2a61c7ad3df1a1eaa 438a75aad3f2b6291e1f978af12db06792b3e1a32c621e2c150007142a17b3d3 a8b816e56772fb6afee6c99622c5014b7fa75e4c7f3deb6863dcde1a3f1f6de4 6d7f5dcbbdda3ae9840e08937f02daa2a7f1546777684c4336b10a1fe31ca50c

CVEs Detected

CVE-2006-20001 CVE-2007-4723 CVE-2009-0796 CVE-2009-2299 CVE-2011-1176 CVE-2011-2688 CVE-2012-3526 CVE-2012-4001 CVE-2012-4360 CVE-2013-0941 CVE-2013-0942 CVE-2013-2765 CVE-2013-4365 CVE-2022-22719 CVE-2022-22720 CVE-2022-22721 CVE-2022-23943 CVE-2022-26377 CVE-2022-28330 CVE-2022-28614 CVE-2022-28615 CVE-2022-29404 CVE-2022-30556 CVE-2022-31813 CVE-2022-36760 CVE-2022-37436 CVE-2023-25690 CVE-2023-27522 CVE-2023-31122 CVE-2023-38709 CVE-2023-44487 CVE-2023-45802 CVE-2024-24795 CVE-2024-27316 CVE-2024-38472 CVE-2024-38473 CVE-2024-38474 CVE-2024-38475 CVE-2024-38476 CVE-2024-38477 CVE-2024-39573 CVE-2024-40898 CVE-2024-42516 CVE-2024-43204 CVE-2024-43394 CVE-2024-47252 CVE-2025-23048 CVE-2025-49630 CVE-2025-49812 CVE-2025-53020 CVE-2025-55753 CVE-2025-58098 CVE-2025-59775 CVE-2025-65082 CVE-2025-66200 CVE-2026-24072 CVE-2026-29169 CVE-2026-33006 CVE-2026-33007 CVE-2026-33523 CVE-2026-33857 CVE-2026-34032 CVE-2026-34059

Similar IP Addresses Detected

103.252.17.146 103.252.92.145 103.252.92.215 103.252.92.234 103.252.92.6 103.252.93.118 103.252.93.143 103.252.93.39 103.252.94.49 103.252.95.89

Share on:
Disclaimer
This page contains threat intelligence information for the IPv4 address 103.252.89.75 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.