129.226.148.192 Threat Intelligence and Host Information
General
This page contains threat intelligence information for the IPv4 address 129.226.148.192 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.
Potentially Malicious Host 🟡 35/100
Host and Network Information
-
Mitre ATT&CK IDs: T1498 - Network Denial of Service
-
Tags: attack ddos, botnet, Cyclops, ddos, Gamardeon, HermeticWiper, IsaacWiper, list ips, PartyTicket, russia, russian, ukraine, WhisperGate
-
View other sources: Spamhaus VirusTotal
-
Contained within other IP sets: stopforumspam_365d
- Country: Singapore
- Network: AS132203 tencent building kejizhongyi avenue
- Noticed: 6 times
- Protocols Attacked: Anonymous Proxy
- Countries Attacked: Russian Federation
Open Ports Detected
10000 10001 10134 10243 10250 10443 10554 10909 10911 11000 111 11112 11210 11211 11288 11371 11434 12000 12348 12767 13579 14147 14265 14344 16010 16030 16992 16993 17000 18080 18081 18245 19071 19305 20000 20256 20547 22 4000 4010 4022 4040 4042 4063 4064 4157 4242 4282 4321 4369 4430 4433 4434 4443 4505 4506 4567 4734 4782 4840 4848 4899 4911 4949 5000 5001 5005 5006 5007 5009 5010 5025 5150 5172 5201 5269 5280 5357 5432 5435 5454 5542 5555 5560 5567 5597 5601 5608 5609 5800 5858 5900 5901 5938 5984 5985 5986 6000 6001 6002 6004 6006 6080 6352 6363 6443 6543 6565 6600 6603 6605 6622 6633 6653 666 6662 6664 6666 6667 6668 6697 7001 7003 7071 7090 7170 7171 7218 7415 7434 7443 7444 7474 7500 7547 7548 7634 7657 7777 7979 7989 7999 8000 8001 8002 8005 8008 8009 8010 8013 8018 8021 8026 8031 8033 8034 8035 8037 8039 8044 8050 8052 8054 8058 8060 8069 8071 8072 8080 8081 8083 8085 8086 8087 8089 8090 8092 8094 8097 8098 8099 8103 8104 8109 8112 8123 8126 8139 8140 8181 8200 8238 8239 8249 8291 8333 8334 8405 8407 8417 8421 8427 8429 8432 8443 8445 8500 8545 8554 8575 8602 8649 8728 8733 8779 8790 8800 8801 8802 8803 8805 8808 8809 8810 8813 8815 8816 8820 8825 8827 8828 8834 8840 8845 8846 8848 8853 8855 8856 8860 8862 8865 8879 8880 8888 8889 8891 8969 8989 8991 9000 9001 9002 9007 9008 9009 9010 9011 9017 9018 9020 9021 9023 9025 9031 9035 9042 9045 9047 9048 9049 9051 9070 9080 9091 9095 9098 9100 9110 9111 9119 9151 9160 9191 9200 9201 9204 9206 9210 9212 9215 9219 9221 9295 9304 9306 9308 9311 9398 9443 9530 9595 9600 9633 9704 9761 9800 9861 9869 9898 9899 9943 9955 9981 9988 9993 9997 9998 9999
Map
Whois Information
- NetRange: 129.226.0.0 - 129.226.255.255
- CIDR: 129.226.0.0/16
- NetName: APNIC
- NetHandle: NET-129-226-0-0-1
- Parent: NET129 (NET-129-0-0-0-0)
- NetType: Early Registrations, Transferred to APNIC
- OriginAS:
- Organization: Asia Pacific Network Information Centre (APNIC)
- RegDate: 2018-03-26
- Updated: 2018-03-26
- Ref: https://rdap.arin.net/registry/ip/129.226.0.0
- OrgName: Asia Pacific Network Information Centre
- OrgId: APNIC
- Address: PO Box 3646
- City: South Brisbane
- StateProv: QLD
- PostalCode: 4101
- Country: AU
- RegDate:
- Updated: 2012-01-24
- Ref: https://rdap.arin.net/registry/entity/APNIC
- OrgAbuseHandle: AWC12-ARIN
- OrgAbuseName: APNIC Whois Contact
- OrgAbusePhone: +61 7 3858 3188
- OrgAbuseEmail: search-apnic-not-arin@apnic.net
- OrgAbuseRef: https://rdap.arin.net/registry/entity/AWC12-ARIN
- OrgTechHandle: AWC12-ARIN
- OrgTechName: APNIC Whois Contact
- OrgTechPhone: +61 7 3858 3188
- OrgTechEmail: search-apnic-not-arin@apnic.net
- OrgTechRef: https://rdap.arin.net/registry/entity/AWC12-ARIN
- inetnum: 129.226.144.0 - 129.226.159.255
- netname: ACE-SG
- country: SG
- admin-c: APA7-AP
- tech-c: APA7-AP
- status: ALLOCATED NON-PORTABLE
- mnt-by: MAINT-ACEVILLEPTELTD-SG
- mnt-irt: IRT-ACEVILLEPTELTD-SG
- abuse-c: AA1875-AP
- last-modified: 2023-10-21T09:25:06Z
- irt: IRT-ACEVILLEPTELTD-SG
- e-mail: qcloud_net_duty@tencent.com
- abuse-mailbox: qcloud_net_duty@tencent.com
- admin-c: APA7-AP
- tech-c: APA7-AP
- mnt-by: MAINT-ACEVILLEPTELTD-SG
- last-modified: 2024-05-22T13:07:48Z
- role: ABUSE ACEVILLEPTELTDSG
- country: ZZ
- phone: +000000000
- e-mail: qcloud_net_duty@tencent.com
- admin-c: APA7-AP
- tech-c: APA7-AP
- nic-hdl: AA1875-AP
- abuse-mailbox: qcloud_net_duty@tencent.com
- mnt-by: APNIC-ABUSE
- last-modified: 2024-05-22T13:08:48Z
- role: ACEVILLE PTELTD administrator
- country: SG
- phone: +8613923479936
- fax-no: +8613923479936
- e-mail: qcloud_net_duty@tencent.com
- admin-c: APA7-AP
- tech-c: APA7-AP
- nic-hdl: APA7-AP
- mnt-by: MAINT-ACEVILLEPTELTD-SG
- last-modified: 2023-03-17T12:36:41Z
- route: 129.226.0.0/16
- origin: AS132203
- descr: Tencent Cloud Computing (Beijing) Co., Ltd
- mnt-by: MAINT-TENCENT-CN
- last-modified: 2018-05-25T10:48:16Z
Links to attack logs
anonymous-proxy-ip-list-2024-07-14 anonymous-proxy-ip-list-2024-06-28
Share on: