104.140.17.85 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 104.140.17.85 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

🟠 Elevated — 60/100

Geographic Location

Host and Network Information

  • View other sources: Spamhaus VirusTotal Shodan AbuseIPDB
  • Country: United States
  • Noticed: 5 times
  • Protocols Attacked: ssh
  • Countries Attacked: Poland, Sweden
  • Open Ports: 22, 3000, 3001, 443, 80
  • Tor Node: No

Tags

  • Brute-Forc
  • Bruteforce
  • Brute-Force
  • cisco
  • cowrie
  • info
  • malicious
  • notice
  • portscan
  • sftp
  • ssh
  • SSH

MITRE ATT&CK TTPs

  • T1078 - Valid Accounts
  • T1083 - File and Directory Discovery
  • T1098.004 - SSH Authorized Keys
  • T1105 - Ingress Tool Transfer
  • T1110.004 - Credential Stuffing
  • T1110 - Brute Force

Associated CVEs

  • CVE-2006-20001

Passive DNS

  • lg-seattle.serverhub.com

Attack Log References

Whois Information

NetRange: 104.140.0.0 - 104.140.255.255 CIDR: 104.140.0.0/16 NetName: EONIX NetHandle: NET-104-140-0-0-1 Parent: NET104 (NET-104-0-0-0-0) NetType: Direct Allocation OriginAS: AS62904 Organization: Eonix Corporation (EONIX) RegDate: 2014-06-20 Updated: 2019-02-28 Comment: Please use the below contact information to report suspected security issues specific to traffic emanating from net blocks in this range, including the distribution of malicious content or other illicit or illegal material. Comment: Comment: For SPAM and other abuse issues, please contact: Comment: * net-abuse@eonix.net Comment: Comment: For legal and law enforcement-related requests, please contact: Comment: * legal@eonix.net Comment: Comment: For Routing, Peering or DNS issues, please contact: Comment: * noc@eonix.net Ref: https://rdap.arin.net/registry/ip/104.140.0.0 OrgName: Eonix Corporation OrgId: EONIX Address: 3773 Howard Hughes Pkwy. Suite 500S City: Las Vegas StateProv: NV PostalCode: 89169-6014 Country: US RegDate: 2006-05-31 Updated: 2024-11-25 Comment: Please use the below contact information to report suspected security issues specific to traffic emanating from net blocks in this range, including the distribution of malicious content or other illicit or illegal material. Comment: Comment: For SPAM and other abuse issues, please contact: Comment: * net-abuse@eonix.net Comment: Comment: For legal and law enforcement-related requests, please contact: Comment: * legal@eonix.net Comment: Comment: For Routing, Peering or DNS issues, please contact: Comment: * noc@eonix.net Ref: https://rdap.arin.net/registry/entity/EONIX OrgDNSHandle: EDM7-ARIN OrgDNSName: Eonix DNS Management OrgDNSPhone: +1-877-841-3341 OrgDNSEmail: 902214@serverhub.com OrgDNSRef: https://rdap.arin.net/registry/entity/EDM7-ARIN OrgNOCHandle: NOC31884-ARIN OrgNOCName: Network Operations Center OrgNOCPhone: +1-702-605-2981 OrgNOCEmail: noc@eonix.net OrgNOCRef: https://rdap.arin.net/registry/entity/NOC31884-ARIN OrgAbuseHandle: NTS22-ARIN OrgAbuseName: Network Trust and Safety OrgAbusePhone: +1-702-605-2981 OrgAbuseEmail: net-admin@eonix.net OrgAbuseRef: https://rdap.arin.net/registry/entity/NTS22-ARIN OrgTechHandle: EDM7-ARIN OrgTechName: Eonix DNS Management OrgTechPhone: +1-877-841-3341 OrgTechEmail: 902214@serverhub.com OrgTechRef: https://rdap.arin.net/registry/entity/EDM7-ARIN OrgTechHandle: NOC31884-ARIN OrgTechName: Network Operations Center OrgTechPhone: +1-702-605-2981 OrgTechEmail: noc@eonix.net OrgTechRef: https://rdap.arin.net/registry/entity/NOC31884-ARIN NetRange: 104.140.16.0 - 104.140.23.255 CIDR: 104.140.16.0/21 NetName: SHUB-NETBLK-SEA NetHandle: NET-104-140-16-0-1 Parent: EONIX (NET-104-140-0-0-1) NetType: Reallocated OriginAS: AS30693 Organization: ServerHub Seattle (SS-1112) RegDate: 2015-10-28 Updated: 2015-10-28 Comment: This IP address space is assigned statically to the Comment: registered customer. IP Addresses within this block are not portable. Comment: Please contact the reallocated customer for abuse complaints. If attempts Comment: to contact the reallocated customer are unsuccessful, please make an Comment: escalated complaint for UCE, SPAM and fraudulent activity that is strictly Comment: prohibited from this network by contacting the upstream at: Comment: abuse@eonix.net Ref: https://rdap.arin.net/registry/ip/104.140.16.0 OrgName: ServerHub Seattle OrgId: SS-1112 City: Seattle StateProv: WA PostalCode: 98121 Country: US RegDate: 2015-10-28 Updated: 2015-10-28 Ref: https://rdap.arin.net/registry/entity/SS-1112 OrgAbuseHandle: ADMIN5989-ARIN OrgAbuseName: Admin OrgAbusePhone: +1-702-968-9305 OrgAbuseEmail: noc@serverhub.com OrgAbuseRef: https://rdap.arin.net/registry/entity/ADMIN5989-ARIN OrgTechHandle: ADMIN5989-ARIN OrgTechName: Admin OrgTechPhone: +1-702-968-9305 OrgTechEmail: noc@serverhub.com OrgTechRef: https://rdap.arin.net/registry/entity/ADMIN5989-ARIN