129.146.47.199 Threat Intelligence and Host Information
General
This page contains threat intelligence information for the IPv4 address 129.146.47.199 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.
Potentially Malicious Host 🟡 35/100
Host and Network Information
-
Tags: cyber security, ioc, malicious, Nextray, phishing
-
View other sources: Spamhaus VirusTotal
- Country: United States
- Network:
- Noticed: 29 times
- Protocols Attacked: SSH
- Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
- Passive DNS Results: ofhc1.2615948.xyz www.secure05b-user2fa.misecure.com secure05b-user2fa.misecure.com secure02-uservalidate.serveuser.com www.secure02-uservalidate.serveuser.com amazn-secureshop.dns04.com www.amazn-secureshop.dns04.com amazn-secure02.serveirc.com secure07b-userauth.serveirc.com secure03b-userauth.serveirc.com secure05b-userauth.serveirc.com paypl-secure02.serveirc.com masterconnectsecure.serveirc.com oracle1.160310.xyz
Malware Detected on Host
Count: 1 902d76bf75366494694e30ffc5a22ea80d422add3fac51a1c3149a4d1f806957
Open Ports Detected
21 22 2443 2444 2453 2455 2480 2525 2548 2549 2550 2553 2554 2555 2557 2558 2559 2560 2561 2562 2563 2567 2568 2570 2572 2598 2602 2626 2628 2650 2701 2709 2761 2762 2806 2850 2985 3000 3001 3005 3006 3007 3011 3013 3014 3015 3016 3018 3019 3021 3022 3030 3042 3047 3048 3049 3050 3051 3052 3054 3055 3056 3061 3062 3063 3065 3066 3067 3068 3069 3071 3072 3076 3077 3078 3080 3084 3085 3088 3090 3091 3093 3094 3096 3097 3101 3102 3103 3104 3106 3107 3109 3110 3111 3112 3113 3115 3117 3118 3119 3122 3124 3125 3126 3128 3129 3131 3132 3136 3137 3139 3141 3144 3145 3147 3149 3151 3154 3155 3157 3158 3159 3161 3165 3166 3167 3168 3169 3171 3172 3174 3175 3176 3177 3180 3181 3182 3183 3186 3188 3189 3195 3198 3199 3260 3268 3269 3270 3299 3301 3306 3307 3310 3311 3333 3337 3341 3349 3365 3388 3389 3390 3400 3401 3405 3407 3443
Map
Whois Information
- NetRange: 129.144.0.0 - 129.159.255.255
- CIDR: 129.144.0.0/12
- NetName: OPC1
- NetHandle: NET-129-144-0-0-1
- Parent: NET129 (NET-129-0-0-0-0)
- NetType: Direct Allocation
- OriginAS:
- Organization: Oracle Corporation (ORACLE-4)
- RegDate: 1991-08-21
- Updated: 2016-10-10
- Ref: https://rdap.arin.net/registry/ip/129.144.0.0
- OrgName: Oracle Corporation
- OrgId: ORACLE-4
- Address: 2300 Oracle Way
- Address: Attn: Domain Administrator
- City: Austin
- StateProv: TX
- PostalCode: 78741
- Country: US
- RegDate: 1988-04-29
- Updated: 2024-11-07
- Ref: https://rdap.arin.net/registry/entity/ORACLE-4
- OrgTechHandle: ORACL1-ARIN
- OrgTechName: ORACLE NIS
- OrgTechPhone: +1-800-633-0738
- OrgTechEmail: domain-contact_ww_grp@oracle.com
- OrgTechRef: https://rdap.arin.net/registry/entity/ORACL1-ARIN
- OrgRoutingHandle: ORACL2-ARIN
- OrgRoutingName: ORACLEROUTING
- OrgRoutingPhone: +1-800-392-2999
- OrgRoutingEmail: network-contact_ww@oracle.com
- OrgRoutingRef: https://rdap.arin.net/registry/entity/ORACL2-ARIN
- OrgAbuseHandle: NISAM-ARIN
- OrgAbuseName: Network Information Systems Abuse Management
- OrgAbusePhone: +1-800-633-0738
- OrgAbuseEmail: network-contact_ww_grp@oracle.com
- OrgAbuseRef: https://rdap.arin.net/registry/entity/NISAM-ARIN
Links to attack logs
telnet-bruteforce-ip-list-2021-01-02 ****** ****** ******
Share on: