128.14.231.118 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 128.14.231.118 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

🟠 Elevated — 45/100

Geographic Location

Host and Network Information

  • View other sources: Spamhaus VirusTotal Shodan AbuseIPDB
  • Country: United States
  • Noticed: 50 times
  • Protocols Attacked: portscan
  • Countries Attacked: Anguilla, Aruba, Australia, Bahamas, Barbados, Canada, Cayman Islands, Costa Rica, Curaçao, Finland, France, Georgia, Germany, Guatemala, Japan, Mexico, Netherlands, Panama, Philippines, Poland, Saint Kitts and Nevis, Saint Martin (French part), Saint Vincent and the Grenadines, Sint Maarten (Dutch part), Tanzania United Republic of, Trinidad and Tobago, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
  • Open Ports: 22
  • Tor Node: No

Tags

  • 01.10.2025
  • 2025
  • 2026-01
  • 2026-02
  • akamaias
  • akamaiasn1
  • amazon02
  • as15169
  • as16509
  • as20940
  • as3359
  • as8075
  • as852
  • attacker ip
  • auto-generated security
  • Automated
  • blacklist
  • block list
  • botnet
  • china mobile
  • cisco
  • columns
  • company limited
  • cowrie
  • cuba
  • DDoS
  • digital ocean
  • dionaea
  • facebook
  • fatt
  • geoip
  • ghost
  • google
  • heralding
  • hk abusehandler
  • HoneyNet Connect
  • honeytrap
  • hong kong
  • hurricane us
  • indonesia
  • LAMP
  • level3
  • mailoney
  • malicious
  • Malicious IP
  • media
  • mexico
  • mini
  • mirai
  • network
  • nxdomain
  • OpenCTI
  • p0f
  • pgp sign
  • portscan
  • proton
  • public url
  • RTBH
  • scan
  • scanners
  • sensor-tagged
  • sentrypeer
  • seznam
  • sftp
  • smb
  • ssh
  • suricata
  • tanner
  • tcp
  • telecom
  • timeout
  • tpot
  • twitter
  • ukraine
  • unknown
  • us abuse
  • us none
  • vultr
  • win32
  • win64

MITRE ATT&CK TTPs

  • T1498 - Network Denial of Service

Associated CVEs

  • CVE-2007-2768

Whois Information

NetRange: 128.14.0.0 - 128.14.255.255 CIDR: 128.14.0.0/16 NetName: ZL-LAX3-004 NetHandle: NET-128-14-0-0-1 Parent: NET128 (NET-128-0-0-0-0) NetType: Direct Allocation OriginAS: Organization: Zenlayer Inc (ZENLA-7) RegDate: 2016-09-07 Updated: 2018-01-12 Ref: https://rdap.arin.net/registry/ip/128.14.0.0 OrgName: Zenlayer Inc OrgId: ZENLA-7 Address: 21680 Gateway Center Dr. Suite 350 City: Diamond Bar StateProv: CA PostalCode: 91765 Country: US RegDate: 2017-12-27 Updated: 2025-09-04 Ref: https://rdap.arin.net/registry/entity/ZENLA-7 OrgTechHandle: IPADM641-ARIN OrgTechName: IP ADMIN OrgTechPhone: +1-909-718-3558 OrgTechEmail: ipadmin@zenlayer.com OrgTechRef: https://rdap.arin.net/registry/entity/IPADM641-ARIN OrgNOCHandle: IPNOC27-ARIN OrgNOCName: IPNOC OrgNOCPhone: +1-800-858-7986 OrgNOCEmail: ipnoc-t3@zenlayer.com OrgNOCRef: https://rdap.arin.net/registry/entity/IPNOC27-ARIN OrgTechHandle: IPNOC27-ARIN OrgTechName: IPNOC OrgTechPhone: +1-800-858-7986 OrgTechEmail: ipnoc-t3@zenlayer.com OrgTechRef: https://rdap.arin.net/registry/entity/IPNOC27-ARIN OrgNOCHandle: IPADM641-ARIN OrgNOCName: IP ADMIN OrgNOCPhone: +1-909-718-3558 OrgNOCEmail: ipadmin@zenlayer.com OrgNOCRef: https://rdap.arin.net/registry/entity/IPADM641-ARIN OrgAbuseHandle: SOCOP-ARIN OrgAbuseName: SOC Ops OrgAbusePhone: +1-909-718-3558 OrgAbuseEmail: abuse@zenlayer.com OrgAbuseRef: https://rdap.arin.net/registry/entity/SOCOP-ARIN OrgTechHandle: TANGR16-ARIN OrgTechName: Tang, Ruifan OrgTechPhone: +1-800-858-7986 OrgTechEmail: ruifan.tang@zenlayer.com OrgTechRef: https://rdap.arin.net/registry/entity/TANGR16-ARIN NetRange: 128.14.231.0 - 128.14.231.255 CIDR: 128.14.231.0/24 NetName: ZL-LAX-UCLOUD-0008 NetHandle: NET-128-14-231-0-1 Parent: ZL-LAX3-004 (NET-128-14-0-0-1) NetType: Reassigned OriginAS: Organization: UCLOUD (UCLOU-1) RegDate: 2019-02-28 Updated: 2019-02-28 Comment: Abuse please contact:unoc@ucloud.cn ,unom@ucloud.cn,hegui@ucloud.cn Ref: https://rdap.arin.net/registry/ip/128.14.231.0 OrgName: UCLOUD OrgId: UCLOU-1 Address: FLAT/RM 603 6/ FLAWS COMMERCIAL PLAZA 788 CHEUNG SHA WAN ROAD KL City: Hong Kong StateProv: PostalCode: Country: HK RegDate: 2019-02-28 Updated: 2019-02-28 Ref: https://rdap.arin.net/registry/entity/UCLOU-1 OrgAbuseHandle: IAU2-ARIN OrgAbuseName: IP ABUSE Ucloud OrgAbusePhone: +86 4000188113 OrgAbuseEmail: unom@ucloud.cn OrgAbuseRef: https://rdap.arin.net/registry/entity/IAU2-ARIN OrgTechHandle: IAU2-ARIN OrgTechName: IP ABUSE Ucloud OrgTechPhone: +86 4000188113 OrgTechEmail: unom@ucloud.cn OrgTechRef: https://rdap.arin.net/registry/entity/IAU2-ARIN