114.129.98.159 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 114.129.98.159 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Likely Malicious Host 🟠 67/100

Host and Network Information

  • Mitre ATT&CK IDs: T1078 - Valid Accounts, T1083 - File and Directory Discovery, T1098.004 - SSH Authorized Keys, T1105 - Ingress Tool Transfer, T1110.004 - Credential Stuffing, T1110 - Brute Force

  • Tags: attack, blacklist, botnet, brute force, cowrie, cyber security, initiator ip, ioc, login, malicious, Malicious IP, mirai, Nextray, phishing, port 23, scan, scanner, ssh, SSH, tcp, tcp/23, telnet, Telnet

  • View other sources: Spamhaus VirusTotal

  • Contained within other IP sets: blocklist_de, blocklist_de_ssh, blocklist_net_ua

  • Country: South Korea
  • Network:
  • Noticed: 50 times
  • Protocols Attacked: ssh telnet
  • Countries Attacked: Australia, Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America

Malware Detected on Host

Count: 2 0c27391855bf1bdacb7d30ce1c3c07f8b90a30da1dba1218bd3dbe9935275780 59b13a3f2d70c49a1af3060ac786b488a7e89afa198b4476f56dd9f560d10fd1

Map

Whois Information

  • inetnum: 114.129.64.0 - 114.129.127.255
  • netname: LG-HELLOVISION
  • descr: LG HELLOVISION CORP.
  • country: KR
  • admin-c: IM697-AP
  • tech-c: IM697-AP
  • status: ASSIGNED PORTABLE
  • mnt-by: MNT-KRNIC-AP
  • mnt-irt: IRT-KRNIC-KR
  • last-modified: 2020-02-03T05:04:33Z
  • irt: IRT-KRNIC-KR
  • address: 9, Jinheung-gil, Naju-si, Jeollanam-do
  • e-mail: irt@nic.or.kr
  • abuse-mailbox: irt@nic.or.kr
  • admin-c: IM574-AP
  • tech-c: IM574-AP
  • mnt-by: MNT-KRNIC-AP
  • last-modified: 2025-09-04T01:00:01Z
  • person: IP Manager
  • address: Seoul Mapo-gu World Cup buk-ro 56-gil 19
  • country: KR
  • phone: +82-70-7373-1751
  • e-mail: lghvnoc@LGHelloVision365.onmicrosoft.com
  • nic-hdl: IM697-AP
  • mnt-by: MNT-KRNIC-AP
  • last-modified: 2024-05-07T00:44:36Z
  • abuse-mailbox: security_regular@LGHelloVision365.onmicrosoft.com
  • inetnum: 114.129.64.0 - 114.129.127.255
  • netname: LG-HELLOVISION-KR
  • descr: LG HelloVision Corp.
  • country: KR
  • admin-c: YK571-KR
  • tech-c: YK571-KR
  • status: ALLOCATED PORTABLE
  • mnt-by: MNT-KRNIC-AP
  • mnt-irt: IRT-KRNIC-KR
  • changed: hostmaster@nic.or.kr 20240912
  • person: IP Manager
  • address: Seoul Mapo-gu World Cup buk-ro 56-gil 19
  • address: 6 Floor
  • country: KR
  • phone: +82-70-7373-1751
  • e-mail: lghvnoc@LGHelloVision365.onmicrosoft.com
  • nic-hdl: YK571-KR
  • mnt-by: MNT-KRNIC-AP
  • changed: hostmaster@nic.or.kr 20240912

Links to attack logs

vultrmadrid-ssh-bruteforce-ip-list-2022-11-16 ****** digitaloceanlondon-telnet-bruteforce-ip-list-2023-09-01 dosing-telnet-bruteforce-ip-list-2022-10-10 dosing-telnet-bruteforce-ip-list-2022-10-09 vultrwarsaw-telnet-bruteforce-ip-list-2023-07-30 dotoronto-ssh-bruteforce-ip-list-2023-05-02 dotoronto-ssh-bruteforce-ip-list-2023-02-24 digitaloceantoronto-telnet-bruteforce-ip-list-2024-01-31 vultrmadrid-telnet-bruteforce-ip-list-2022-10-09 vultrparis-ssh-bruteforce-ip-list-2023-01-18 ****** digitaloceantoronto-telnet-bruteforce-ip-list-2023-10-23 ******

Share on: