117.106.3.79 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 117.106.3.79 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Potentially Malicious Host 🟡 37/100

Host and Network Information

  • Tags: cyber security, ioc, malicious, Nextray, phishing

  • View other sources: Spamhaus VirusTotal

  • Country: China
  • Network: AS4847 china networks inter-exchange
  • Noticed: 26 times
  • Protocols Attacked: mssql
  • Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America

Malware Detected on Host

Count: 2 5c655270231ef2ef3ab55e75db106cd1270c3c91cd21746464759372a63aba7e 71ccd01f474aa9ac4fe8fc84e59b397f4ddd8bb72995567262bc488a1f6ed278

Map

Whois Information

  • inetnum: 117.106.0.0 - 117.106.255.255
  • netname: BJENET
  • descr: Beijing Education Information Network
  • descr: Service Center Corporation
  • descr: NO.39 Xueyuan Road,Haidian District ,Beijing, PRC
  • country: CN
  • admin-c: ZM776-AP
  • tech-c: BW887-AP
  • abuse-c: AC1601-AP
  • status: ALLOCATED PORTABLE
  • mnt-by: MAINT-CNNIC-AP
  • mnt-irt: IRT-BJENET-CN
  • mnt-lower: MAINT-CNNIC-AP
  • last-modified: 2023-11-28T00:56:57Z
  • irt: IRT-BJENET-CN
  • address: NO.39 Xueyuan Road,Haidian District ,Beijing, PRC
  • e-mail: ip@bjedu.com.cn
  • abuse-mailbox: ip@bjedu.com.cn
  • admin-c: ZM776-AP
  • tech-c: BW887-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2021-08-17T02:30:56Z
  • role: ABUSE CNNICCN
  • address: Beijing, China
  • country: ZZ
  • phone: +000000000
  • e-mail: ipas@cnnic.cn
  • admin-c: IP50-AP
  • tech-c: IP50-AP
  • nic-hdl: AC1601-AP
  • abuse-mailbox: ipas@cnnic.cn
  • mnt-by: APNIC-ABUSE
  • last-modified: 2020-05-14T11:19:01Z
  • person: Xing Yanhong
  • address: NO.39 Xueyuan Road,Haidian District ,Beijing, PRC
  • country: cn
  • phone: +86-010-82364916
  • fax-no: +86-010-62308338
  • e-mail: XYH@BJEDU.COM.CN
  • nic-hdl: BW887-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2014-12-26T03:04:02Z
  • person: Dongliang Wang
  • address: NO.39 Xueyuan Road,Haidian District ,Beijing, PRC
  • phone: +86-010-82364918
  • fax-no: +86-010-62308338
  • country: cn
  • e-mail: wdl@bjedu.com.cn
  • nic-hdl: ZM776-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2014-12-26T03:04:01Z

Links to attack logs

****** dosing-mssql-bruteforce-ip-list-2021-03-03 ****** ******

Share on: