112.213.105.236 Threat Intelligence and Host Information
General
This page contains threat intelligence information for the IPv4 address 112.213.105.236 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.
Possibly Malicious Host 🟢 29/100
Host and Network Information
-
Tags: blacklist, botnet, Malicious IP, mirai, nmap, port-scan, scan, smb, tcp
-
View other sources: Spamhaus VirusTotal
- Country: Hong Kong
- Network: AS64050 bgpnet global asn
- Noticed: 2 times
- Protocols Attacked: SSH
- Countries Attacked: Australia
- Passive DNS Results: www.91kan.net cfdn.wn231.com pic.tv123.cc www.eamkevc8.org eamkevc8.org img.eamkevc8.org m.szyunbo.com m.haojuwu.cc www.haojuwu.cc hkan.cc m.hkan.cc img.hkan.cc quankanwang.com skm3u8.wyi.cc ddos.wn231.com haojuwu.cc 84889.wyi.cc cdn.v66.top scdn.wn231.com www.wn231.com m.234dyw.cc img.234dyw.cc open.wn231.com m3u8.wn231.com www.007dy.cc m.007dy.cc img.007dy.cc 007dy.cc qqovd.cc m.qqovd.cc www.qqovd.cc img.qqovd.cc www.234dyw.cc 234dyw.cc m.quankanwang.com m.8xigua.com 8xigua.com img.8xigua.com zkyyxy999.com www.zkyyxy999.com img.quankanwang.com www.djhuo.cc m.djhuo.cc img.djhuo.cc djhuo.cc img.gzpzqc.com m.gzpzqc.com gzpzqc.com www.gzpzqc.com img.lyliano.com lyliano.com m.lyliano.com www.8xigua.com m.tabdnkyy.com www.tabdnkyy.com img.tabdnkyy.com tabdnkyy.com www.jkzoc.com jkzoc.com img.jkzoc.com m.jkzoc.com asanall.com m.asanall.com www.tv123.cc tv123.cc m.tv123.cc www.quankanwang.com www.dfsjbn.com dfsjbn.com yclfw.cn xiangleyuan.net anicca-solutions.com
Malware Detected on Host
Count: 1 dc58cd0800469837f8bc7789ab2e65e608d9f3d89aa283ce34588a60cb1d52da
Map
Whois Information
- inetnum: 112.213.105.0 - 112.213.105.255
- netname: MEGA-II
- descr: MEGA-II IDC
- country: HK
- admin-c: DA179-AP
- tech-c: DA179-AP
- abuse-c: AS2098-AP
- status: ALLOCATED NON-PORTABLE
- mnt-by: MAINT-HK-SUN
- mnt-irt: IRT-SUN-HK
- last-modified: 2020-05-17T23:03:19Z
- irt: IRT-SUN-HK
- address: MEGA-II IDC
- e-mail: INFO@MEGA-II.COM
- abuse-mailbox: INFO@MEGA-II.COM
- admin-c: DA179-AP
- tech-c: DA179-AP
- mnt-by: MAINT-HK-SNW
- last-modified: 2023-11-14T16:16:03Z
- role: ABUSE SUNHK
- address: MEGA-II IDC
- country: ZZ
- phone: +000000000
- e-mail: INFO@MEGA-II.COM
- admin-c: DA179-AP
- tech-c: DA179-AP
- nic-hdl: AS2098-AP
- abuse-mailbox: INFO@MEGA-II.COM
- mnt-by: APNIC-ABUSE
- last-modified: 2023-11-14T16:17:00Z
- person: DNS Administrator
- nic-hdl: DA179-AP
- e-mail: INFO@MEGAIIHK.COM
- address: SHA TIN
- phone: +852-2135-9374
- country: HK
- mnt-by: MAINT-HK-SNW
- abuse-mailbox: ABUSE@MEGAIIHK.COM
- last-modified: 2020-05-17T14:55:38Z
- route: 112.213.96.0/19
- descr: MEGA-II IDC
- origin: AS38197
- mnt-by: MAINT-HK-SUN
- last-modified: 2020-05-29T05:18:46Z
Links to attack logs
****** nmap-scanning-list-2022-08-01 ****** ******
Share on: