117.102.224.38 Threat Intelligence and Host Information

Share on:

General

This page was generated as a result of this host being detected actively attacking or scanning another host. See below for information related to the host network, location, number of days noticed, protocols attacked and other information including reverse DNS and whois.

Potentially Malicious Host 🟡 35/100

Host and Network Information

  • Mitre ATT&CK IDs: T1110 - Brute Force
  • Tags: vnc
  • View other sources: Spamhaus VirusTotal
  • Contained within other IP sets: proxylists_1d, proxylists_30d, proxylists_7d, socks_proxy_1d, socks_proxy_30d, socks_proxy_7d, stopforumspam, stopforumspam_180d, stopforumspam_365d, stopforumspam_90d

  • Country: Indonesia
  • Network: AS23756 padi internet
  • Noticed: 26 times
  • Protcols Attacked: SSH
  • Passive DNS Results: cloud.reveurhotels.com www.cloud.reveurhotels.com device-3f87c117-745e-4b5d-93d3-d7b683b36491.remotewd.com

Open Ports Detected

161 1701 1723 2000 443 9090

Map

Whois Information

  • inetnum: 117.102.224.0 - 117.102.255.255
  • netname: PADINET-ID
  • descr: Padi Internet, PT
  • descr: Internet Service Provider
  • descr: Mayjen Sungkono no.83
  • descr: Surabaya 60242
  • descr: Indonesia
  • country: ID
  • admin-c: PN108-AP
  • tech-c: PN108-AP
  • mnt-by: MNT-APJII-ID
  • mnt-lower: MAINT-ID-PADINET
  • mnt-irt: IRT-PADINET-ID
  • status: ALLOCATED PORTABLE
  • last-modified: 2013-09-25T04:04:33Z
  • irt: IRT-PADINET-ID
  • address: Jl. Mayjen Sungkono no.83
  • address: Surabaya 60242
  • address: Indonesia
  • e-mail: [email protected]
  • abuse-mailbox: [email protected]
  • admin-c: LL355-AP
  • tech-c: LL355-AP
  • mnt-by: MAINT-ID-PADINET
  • last-modified: 2018-05-31T22:30:19Z
  • role: PADINET NOC
  • address: Jl. Mayjen Sungkono 83
  • address: Surabaya 60224
  • country: ID
  • phone: +62-31-5616330
  • fax-no: +62-31-5616304
  • e-mail: [email protected]
  • admin-c: LL355-AP
  • admin-c: IS134-AP
  • admin-c: MZ631-AP
  • tech-c: LL355-AP
  • tech-c: IS134-AP
  • tech-c: MZ631-AP
  • nic-hdl: PN108-AP
  • notify: [email protected]
  • mnt-by: MAINT-ID-PADINET
  • last-modified: 2011-12-06T00:11:03Z
  • route: 117.102.224.0/24
  • descr: Route object of PT Padi Internet
  • descr: Corporate Internet Service Provider
  • descr: Surabaya
  • country: ID
  • origin: AS23756
  • notify: [email protected]
  • mnt-routes: MAINT-ID-PADINET
  • mnt-by: MAINT-ID-PADINET
  • last-modified: 2010-07-06T08:02:02Z
  • inetnum: 117.102.224.0 - 117.102.224.255
  • netname: PADINET-BTS-SURABAYA-117-102-224
  • descr: Surabaya PTP BTS Clients
  • descr: Padi Internet, PT
  • descr: Corporate IT Solution
  • descr: Jl. Mayjen Sungkono 83
  • descr: Surabaya
  • descr: Indonesia
  • country: ID
  • admin-c: PN108-AP
  • tech-c: PN108-AP
  • status: ASSIGNED NON-PORTABLE
  • notify: [email protected]
  • notify: [email protected]
  • mnt-by: MAINT-ID-PADINET
  • mnt-irt: IRT-PADINET-ID
  • last-modified: 2020-05-28T10:11:48Z
  • irt: IRT-PADINET-ID
  • address: PT. Padi Internet
  • address: Jl. Mayjen Sungkono no.83
  • address: Surabaya 60242
  • address: Indonesia
  • e-mail: [email protected]
  • abuse-mailbox: [email protected]
  • admin-c: LL355-AP
  • admin-c: MZ631-AP
  • admin-c: HAP1-AP
  • tech-c: LL355-AP
  • tech-c: MZ631-AP
  • tech-c: HAP1-AP
  • mnt-by: MAINT-ID-PADINET
  • last-modified: 2020-05-14T07:17:28Z
  • role: PADINET NOC
  • address: PT. Padi Internet
  • address: Jl. Mayjen Sungkono 83
  • address: Surabaya 60224
  • country: ID
  • phone: +62-31-5616330
  • fax-no: +62-31-5616304
  • e-mail: [email protected]
  • e-mail: [email protected]
  • admin-c: LL355-AP
  • admin-c: MZ631-AP
  • admin-c: HAP1-AP
  • tech-c: LL355-AP
  • tech-c: MZ631-AP
  • tech-c: HAP1-AP
  • nic-hdl: PN108-AP
  • notify: [email protected]
  • mnt-by: MAINT-ID-PADINET
  • last-modified: 2020-05-14T07:19:47Z
  • route: 117.102.224.0/24
  • descr: Route object of PT Padi Internet
  • descr: Corporate Internet Service Provider
  • descr: Surabaya
  • country: ID
  • origin: AS23756
  • notify: [email protected]
  • notify: [email protected]
  • mnt-routes: MAINT-ID-PADINET
  • mnt-by: MAINT-ID-PADINET
  • last-modified: 2020-05-14T07:34:41Z

Links to attack logs

roxy-ip-list-2023-05-03