125.212.243.139 Threat Intelligence and Host Information

Share on:

General

This page contains threat intelligence information for the IPv4 address 125.212.243.139 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Known Malicious Host 🔴 80/100

Host and Network Information

  • Mitre ATT&CK IDs: T1078 - Valid Accounts, T1083 - File and Directory Discovery, T1098.004 - SSH Authorized Keys, T1105 - Ingress Tool Transfer, T1110 - Brute Force, T1110.004 - Credential Stuffing
  • Tags: Brute-Force, Bruteforce, Nextray, SSH, aws, bruteforce, cowrie, cyber security, digital ocean, ioc, malicious, phishing, scanners, ssh, vultr

  • View other sources: Spamhaus VirusTotal
  • Contained within other IP sets: b3b0, blocklist_de, blocklist_de_ssh, greensnow, haley_ssh

  • Country: Vietnam
  • Network: AS38731 vietel - cht company
  • Noticed: 1 times
  • Protcols Attacked: ssh
  • Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Singapore, Spain, Turkey, Ukraine, United Kingdom, United Kingdom of Great Britain and Northern Ireland, United States of America
  • Passive DNS Results: www.inanvictory.com hondaotomienbac5s.com tongkhosannhuaspc.com baovietyenbai.com luxua.vn www.luxua.vn www.inducook.vn inducook.vn goldenhomemassage.com www.nongduocxanhvn.com noithathonghuong.com www.daoplattrangia.com www.bdsnhuyquangngai.com thacotruonghaihcm.com taxiphumy-bariavungtau.com taxilientinhbamien.com solariagardensocson.com sinhphamcompany.com solarcameratayninh.com bdsnhuyquangngai.com glossnailsalon.com nhagoanviet.com nongduocxanhvn.com kudomaxstore.com www.cuacuonhanoi247.com cuacuonhanoi247.com www.taxithotnot65.com www.vnibinhphuoc.com mitsubishiquangtri.net taxithotnot65.com vnibinhphuoc.com hailamtravel.com datxelientinhgiare.net khoruoutot.net daoplattrangia.com ltc-qt.com 9tripphuquoc.com kolosshop.com www.kolosshop.com suativibacgiang.net www.suativibacgiang.net www.atsc.vn atsc.vn toyotathanglongcaugiay.com dienlanhhungthinhphat.net xaydungminhthang.net grabcongnghe24h.com anhdungbdsnhatrang.com taxicongnghelientinh.com xuananhstore.com cuacuonthanhquang.com vattudonghang.com mydalat.com gonamhung.com tralabang.vn www.tralabang.vn dongminhhome.com www.dongminhhome.com anhtaycompany.com thuysankimlong.com thinhphatmb.com thegioidenhot.com thvina.com dunghaland.com coffeebinhduong.com vantaivictory.com happynailsanddayspa.com minhhoanggarden.com ngukimmp.com www.thuysannamhaiduong.com thuysannamhaiduong.com tplagri.com www.tplagri.com www.panel-giare.com panel-giare.com toanxetai.com www.toanxetai.com taxisanbaycamranh.org www.lpl686.com www.karaokenew194tdh.com tochucsukienhuyanh.com trisonnest.com tamsuthamkin.com trtvn.com dienhoahalong.com moitruongxanh24h.com lpl686.com lotushomemassage.com oasisnailsalliston.com karaokenew194tdh.com thaonguyencoconut.com mcgoldenspice.com quangcaothinhquang.com luminousperfume.com www.moitruonglongphuoc.com moitruonglongphuoc.com xkld-duhoc-uytin.com temnhanthaison.com bdsnkland.com gomsutruonglam.com tinnews1.com newjourneyvn.com trannguyenluat.vn www.trannguyenluat.vn www.mitsubishilongbien.net mitsubishilongbien.net maysofavtv.com www.maysofavtv.com www.kiemdinhxaydungmiennam.com www.vitinhminhvu.com vanepxaydung.com monsterxvn.com acsl.vn giatribaohiem.com toyotaso1.net www.kaindl.vn www.nchr.vn www.suakhoanhanhhanoi.com www.vesinhmoitruongthanhtrung.com www.quanglonghf.com www.dieukhactruongthanh.com www.codiendinhgia.com www.anninhminhnguyet.com bigsun.com.vn www.myphamlenguyen.com www.dietmoiminhquan.vn kiemdinhxaydungmiennam.com hqv.vn vsglasshailong.com phanthienbuilder.com ftivoice.com vaythechapbdseximbank.com gaonongdien.com nchr.vn kaindl.vn dietmoiminhquan.vn vinfastmydinh.top nhomkinhbachviet.com dichvuxesanbay.com smylora.com xaydungquangthanh.com zannystyle.com thucphamngoxuan.com tongkhodathienson.com smsbrandnamefpt.com panlinkvn.com maytheudangkhoi.com chuyennhathanhhung68.com dichvuvantaihg.com bdsbaotoan.com lcfarm.vn chongsethaiduong.com blissenglish.edu.vn aucodalat.vn ecof.com.vn suakhoadidong.com hanghainhatquang.com www.hanghainhatquang.com suakhoanhanhhanoi.com vesinhmoitruongthanhtrung.com tongdailyxetai.net baominhsilicate.com www.baominhsilicate.com bachhoaha.com www.bachhoaha.com khudothidanko.com dienlanhducphuc.com.vn phadodaomong24h.com ivybolly.com inanvictory.com waterpointnamlongvn.com vayvonshinhanhcm.com otohondakiengiang.net ngantamshop.com colubevn.com dichvunhadatduyhoabinhduong.com vachkinhphongtam.vn vitinhminhvu.com botnhangsinhphu.com taichinh86.com solarthaiduong.com quanglonghf.com namhandanang.com ketoanabc.com hoangminhgift.com chuagouthaiphong.com dichvutrongoiadz.com vaneplambao.com cuahangapt.com anninhminhnguyet.com xeghepxuthanh.com vnptbienhoa.com kimthanhnam.com dietmoiminhquan.com dieukhactruongthanh.com asianlandvn.com chamsocxecsx.com hotrungngoc.com bdfoodvn.com cokhianhhungthinh.com 39mstudio.com ducthanhxaydung.vn chuyenphatnhanhbmexpress.com chuyennhavanphonggiarehn.com tapchikinhdoanhvn.com noithatdepok.com guanglonghf.com noithatdogogiare.com diendandoanhnhanvn.com www.diendandoanhnhanvn.com codiendinhgia.com tngfarm.com myphamlenguyen.com thichdudua.info

Open Ports Detected

21 443 53 80

CVEs Detected

CVE-2019-12815 CVE-2019-19269 CVE-2019-19271 CVE-2019-19272 CVE-2020-9272 CVE-2021-46854

Map

Whois Information

  • inetnum: 125.212.128.0 - 125.212.255.255
  • netname: VIETTEL-VN
  • descr: Viettel Group
  • descr: No 1, Tran Huu Duc street, My Dinh 2 ward, Nam Tu Liem district, Ha Noi City
  • country: VN
  • admin-c: TVT8-AP
  • tech-c: NDT9-AP
  • mnt-by: MAINT-VN-VNNIC
  • status: ALLOCATED PORTABLE
  • mnt-irt: IRT-VNNIC-AP
  • last-modified: 2017-11-11T09:41:33Z
  • irt: IRT-VNNIC-AP
  • address: Ha Noi, VietNam
  • phone: +84-24-35564944
  • fax-no: +84-24-37821462
  • e-mail: [email protected]
  • abuse-mailbox: [email protected]
  • admin-c: NTTT1-AP
  • tech-c: NTTT1-AP
  • mnt-by: MAINT-VN-VNNIC
  • last-modified: 2017-11-08T09:40:06Z
  • person: Nguyen Dang Tiep
  • address: Viettel Network Corporation
  • address: No 1, Tran Huu Duc street, My Dinh 2 ward, Nam Tu Liem district, Ha Noi City
  • country: VN
  • phone: +84-24-62989898
  • e-mail: [email protected]
  • nic-hdl: NDT9-AP
  • mnt-by: MAINT-VN-VIETEL
  • last-modified: 2017-11-11T09:40:35Z
  • person: Tran Van Thanh
  • address: Viettel Network Corporation
  • address: No 1, Tran Huu Duc street, My Dinh 2 ward, Nam Tu Liem district, Ha Noi City
  • country: VN
  • phone: +84-24-62989898
  • e-mail: [email protected]
  • nic-hdl: TVT8-AP
  • mnt-by: MAINT-VN-VIETEL
  • last-modified: 2018-08-21T09:57:13Z
  • route: 125.212.128.0/17
  • descr: Viettel Corporation
  • descr: Internet service/exchange provider
  • descr: VIETEL-AS-AP
  • country: VN
  • origin: AS7552
  • member-of: rs-viettel
  • mnt-by: MAINT-VN-VIETEL
  • last-modified: 2013-12-11T07:28:18Z

Links to attack logs

aws-ssh-bruteforce-ip-list-2021-04-17 dofrank-ssh-bruteforce-ip-list-2023-01-09 bruteforce-ip-list-2021-05-19 dosing-ssh-bruteforce-ip-list-2022-09-27 vultrmadrid-ssh-bruteforce-ip-list-2022-09-28 dofrank-ssh-bruteforce-ip-list-2022-11-03 bruteforce-ip-list-2022-12-29 dotoronto-ssh-bruteforce-ip-list-2023-02-01 dofrank-ssh-bruteforce-ip-list-2023-05-10 bruteforce-ip-list-2021-06-12 vultrparis-ssh-bruteforce-ip-list-2022-08-31 dosing-ssh-bruteforce-ip-list-2022-12-04 vultrwarsaw-ssh-bruteforce-ip-list-2023-04-30 vultrmadrid-ssh-bruteforce-ip-list-2023-05-18 bruteforce-ip-list-2022-04-20 dotoronto-ssh-bruteforce-ip-list-2022-07-02 vultrmadrid-ssh-bruteforce-ip-list-2022-07-15 dofrank-ssh-bruteforce-ip-list-2022-07-18 bruteforce-ip-list-2022-08-18 dofrank-ssh-bruteforce-ip-list-2022-09-17 dosing-ssh-bruteforce-ip-list-2023-03-05 dofrank-ssh-bruteforce-ip-list-2023-03-23 dotoronto-ssh-bruteforce-ip-list-2022-06-28 bruteforce-ip-list-2021-05-18 bruteforce-ip-list-2021-06-05 dosing-ssh-bruteforce-ip-list-2022-08-25 vultrwarsaw-ssh-bruteforce-ip-list-2022-09-30 vultrparis-ssh-bruteforce-ip-list-2023-04-02 dosing-ssh-bruteforce-ip-list-2022-09-23 dolondon-ssh-bruteforce-ip-list-2023-04-05 vultrmadrid-ssh-bruteforce-ip-list-2023-02-24 vultrmadrid-ssh-bruteforce-ip-list-2022-08-27 vultrparis-ssh-bruteforce-ip-list-2022-11-12 vultrwarsaw-ssh-bruteforce-ip-list-2023-05-11 dotoronto-ssh-bruteforce-ip-list-2022-10-03 vultrmadrid-ssh-bruteforce-ip-list-2022-06-24 bruteforce-ip-list-2022-08-21 vultrwarsaw-ssh-bruteforce-ip-list-2022-08-22 vultrwarsaw-ssh-bruteforce-ip-list-2022-12-31 vultrparis-ssh-bruteforce-ip-list-2023-03-14 vultrparis-ssh-bruteforce-ip-list-2023-04-21 vultrparis-ssh-bruteforce-ip-list-2022-11-14 bruteforce-ip-list-2023-05-09 bruteforce-ip-list-2022-03-20 dosing-ssh-bruteforce-ip-list-2022-09-10 vultrwarsaw-ssh-bruteforce-ip-list-2023-02-04