104.248.10.134 Threat Intelligence and Host Information

Share on:

General

This page contains threat intelligence information for the IPv4 address 104.248.10.134 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Likely Malicious Host 🟠 65/100

Host and Network Information

  • Mitre ATT&CK IDs: T1078 - Valid Accounts, T1083 - File and Directory Discovery, T1098.004 - SSH Authorized Keys, T1105 - Ingress Tool Transfer, T1110.004 - Credential Stuffing, T1110 - Brute Force
  • Tags: cowrie, cyber security, ioc, malicious, Nextray, phishing, ssh

  • View other sources: Spamhaus VirusTotal
  • Contained within other IP sets: blocklist_de, blocklist_de_ssh

  • Country: United States
  • Network: AS14061 digitalocean llc
  • Noticed: 34 times
  • Protcols Attacked: SSH
  • Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
  • Passive DNS Results: e2e-dbaas-mongodb-o4pt5-r-18846d7c.mongo.ondigitalocean.com auth-numberid2987.ddnsking.com auth-numberid9112.ddnsking.com auth-numberid9888.ddnsking.com cosmos-idnumber9103.ddnsking.com auth-numberid12993.ddnsking.com auth-numberid1902.ddnsking.com duty-numberid6193.ddnsking.com auth-numberid1922.ddnsking.com auth-numberid9892.ddnsking.com truk-numberid9173.ddnsking.com auth-numberid9378.ddnsking.com auth-numberid96494.ddnsking.com www.104-248-10-134.cprapid.com 104-248-10-134.cprapid.com api.bacpac.net

Open Ports Detected

10000 10001 10243 10250 10443 10554 10911 11112 11210 11300 11371 12000 13579 14147 14265 1521 1554 1599 16010 16030 1604 16992 16993 17000 1723 1741 1801 18081 1820 18245 1883 19000 19071 1911 1925 1926 1935 1962 2000 20000 2002 2006 2008 2010 2020 2021 2022 2051 2053 2054 20547 2057 2061 2062 2063 2079 2081 2083 2086 2087 2095 21025 2111 2121 21379 2154 2181 22 2200 2201 2222 2323 2332 2333 23424 2345 2352 2375 2376 2379 2404 2455 2480 25001 2506 25105 2548 2550 25565 2557 2560 27015 2761 2762 28015 28017 2806 3000 30002 30003 3001 3002 3050 3051 3054 3055 3056 3058 3061 3063 3079 3094 3098 3105 3106 3107 3112 3114 3116 3119 3121 3128 31337 32400 3260 3268 3269 32764 3299 3301 3306 33060 3310 3333 3388 3389 3401 3402 3404 3406 3410 35000 3541 3542 3549 3550 3551 3555 3559 3560 3566 3689 37215 3749 37777 3780 3790 3910 3954 4000 4022 4040 4063 4117 41800 4242 4282 4321 44158 4433 4443 4444 44818 4500 4506 4523 4567 4664 4734 4782 4786 47990 4840 4848 4899 4911 49152 49153 4949 5000 50000 5001 5004 5005 50050 5006 5007 50070 5009 5010 50100 5025 5080 51106 51235 5172 5201 5209 5222 5269 5280 52869 5357 5431 5432 5435 55000 55442 55443 5555 55553 55554 5560 5568 5591 5598 5601 5607 5800 5801 5822 5858 5900 5901 5906 5907 5908 5909 5938 5984 5985 5986 6000 60001 6001 60010 6002 60030 6007 6008 6010 6080 6264 6352 6372 6379 6443 6560 6565 6633 6653 6664 6666 6667 6668 6697 6887 7001 7004 7005 7010 7071 7080 7170 7171 7218 7401 7434 7443 7474 7493 7547 7634 7654 7657 7676 7777 7779 7989 7998 7999 8000 8001 8005 8007 8008 8009 8010 8015 8021 8024 8025 8027 8029 8031 8033 8050 8055 8060 8069 8080 8083 8085 8086 8089 8090 8094 8098 8099 8104 8107 8108 8111 8112 8118 8123 8126 8139 8140 8181 8200 8236 8243 8291 8333 8334 8402 8408 8409 8411 8412 8413 8415 8419 8427 8429 8430 8432 8443 8445 8500 8545 8554 8575 8585 8621 8622 8649 8728 8765 8767 8782 8784 8805 8810 8815 8818 8834 8835 8837 8840 8843 8844 8846 8853 8854 8867 8870 8871 8878 8880 8881 8888 8889 8891 8899 8969 8988 8991 8999 9000 9001 9009 9014 9015 9017 9023 9028 9031 9033 9036 9042 9046 9047 9051 9080 9082 9090 9091 9092 9095 9100 9102 9109 9110 9151 9160 9191 9199 9200 9208 9217 9218 9221 9251 9295 9301 9304 9306 9309 9418 9443 9444 9445 9530 9550 9595 9600 9761 9800 9869 9876 9943 9944 9966 9981 9990 9994 9998 9999

Map

Whois Information

  • NetRange: 104.248.0.0 - 104.248.255.255
  • CIDR: 104.248.0.0/16
  • NetName: DIGITALOCEAN-104-248-0-0
  • NetHandle: NET-104-248-0-0-1
  • Parent: NET104 (NET-104-0-0-0-0)
  • NetType: Direct Allocation
  • OriginAS: AS14061
  • Organization: DigitalOcean, LLC (DO-13)
  • RegDate: 2018-08-06
  • Updated: 2020-04-03
  • Comment: Routing and Peering Policy can be found at https://www.as14061.net
  • Comment:
  • Ref: https://rdap.arin.net/registry/ip/104.248.0.0
  • OrgName: DigitalOcean, LLC
  • OrgId: DO-13
  • Address: 101 Ave of the Americas
  • Address: FL2
  • City: New York
  • StateProv: NY
  • PostalCode: 10013
  • Country: US
  • RegDate: 2012-05-14
  • Updated: 2023-10-23
  • Ref: https://rdap.arin.net/registry/entity/DO-13
  • OrgNOCHandle: NOC32014-ARIN
  • OrgNOCName: Network Operations Center
  • OrgNOCPhone: +1-347-875-6044
  • OrgNOCEmail: [email protected]
  • OrgNOCRef: https://rdap.arin.net/registry/entity/NOC32014-ARIN
  • OrgAbuseHandle: ABUSE5232-ARIN
  • OrgAbuseName: Abuse, DigitalOcean
  • OrgAbusePhone: +1-347-875-6044
  • OrgAbuseEmail: [email protected]
  • OrgAbuseRef: https://rdap.arin.net/registry/entity/ABUSE5232-ARIN
  • OrgTechHandle: NOC32014-ARIN
  • OrgTechName: Network Operations Center
  • OrgTechPhone: +1-347-875-6044
  • OrgTechEmail: [email protected]
  • OrgTechRef: https://rdap.arin.net/registry/entity/NOC32014-ARIN

Links to attack logs

** bruteforce-ip-list-2021-02-07 bruteforce-ip-list-2021-02-10 ** **