109.106.239.71 Threat Intelligence - Serbia | IP Address Lookup

General

IP Address
109.106.239.71
IPv4 Address
Location
🇷🇸 Serbia
RS
Network
AS15958
CETIN Ltd. Belgrade
Threat Score
60/100
High Risk
0xrh0d4m1nadbauthentication-failureBlocklistbrute-forcebruteforcecowriecredential-dumping
Attack Intelligence
MITRE ATT&CK Techniques
T1021 - Remote Services, T1110 - Brute Force, T1190 - Exploit Public-Facing Application, T1210 - Exploitation of Remote Services, T1595 - Active Scanning
Noticed
35 times
Protocols Attacked
mssql portscan
Countries Attacked
China, Germany, Russian Federation, Türkiye, United Kingdom of Great Britain and Northern Ireland, United States of America
Open Ports Detected
17232000
Geographic Location
Country
Serbia
City
Unknown
Region
Unknown
Coordinates
44.8189, 20.4600
Network Information
ASN
AS15958
Organization
CETIN Ltd. Belgrade
Network
AS15958 CETIN Ltd. Belgrade
WHOIS Information
inetnum
109.106.239.0 - 109.106.239.255
netname
RS-CETIN-20091223
descr
Cetin doo Serbia address space for wholesale user Astra Telekom
country
RS
admin-c
VS11222-RIPE
tech-c
VS11222-RIPE
status
ASSIGNED PA
mnt-by
mnt-rs-cetin-1
created
2021-03-09T13:53:12Z
last-modified
2025-03-04T13:01:47Z
role
Visnja Simpraga
address
Omladinskih brigada 90
phone
+381 63 444 222
nic-hdl
VS11222-RIPE
route
109.106.224.0/20
origin
AS15958
Attack Logs
DateTarget LocationProtocolLink
2026-07-22 Toronto, Canada MSSQL View Log
2026-07-22 Vultrtokyo MSSQL View Log
2026-07-22 Vultrmelbournetest MSSQL View Log
Disclaimer
This page contains threat intelligence information for the IPv4 address 109.106.239.71 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only, and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.