132.145.126.182 Threat Intelligence and Host Information
General
This page contains threat intelligence information for the IPv4 address 132.145.126.182 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.
Possibly Malicious Host 🟢 25/100
Host and Network Information
-
Tags: Brute-Force, Bruteforce, Nextray, SSH, cyber security, ioc, malicious, phishing
-
View other sources: Spamhaus VirusTotal
- Country: Japan
- Network: AS31898 oracle corporation
- Noticed: 1 times
- Protcols Attacked: ssh
- Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
- Passive DNS Results: torex.tk opc2.bluebizkit.top opc2.bluebizkit.site
Open Ports Detected
10000 10001 10134 1024 10443 1177 1234 12345 1337 13579 1400 14265 1433 14344 1521 1935 2000 20000 2082 2086 2087 2222 2345 2375 2376 2404 2480 25 25001 2628 2761 2762 3000 3001 3050 31337 3268 3269 3299 3389 3790 389 4000 4022 4040 4064 443 444 4443 4444 4500 4567 465 4848 4911 5000 50000 5001 5005 50050 5006 5007 5009 5010 5201 5222 5269 53 55000 554 5555 5560 5601 5672 5800 587 5900 5901 5985 6000 60001 6001 6080 631 636 6443 7001 7071 7171 7443 7547 7548 7777 7779 80 8000 8009 8010 8060 8069 8080 8081 8083 8085 8086 8090 8098 81 8112 8123 8126 8139 8140 8181 82 8200 83 84 8443 88 8800 8834 8880 8888 8889 9000 9001 9002 9009 9080 9090 9091 9095 9100 9191 9200 9306 9443 9530 9600 9800 9943 9999
Map
Whois Information
- NetRange: 132.145.0.0 - 132.145.255.255
- CIDR: 132.145.0.0/16
- NetName: OC-195
- NetHandle: NET-132-145-0-0-1
- Parent: NET132 (NET-132-0-0-0-0)
- NetType: Direct Allocation
- OriginAS:
- Organization: Oracle Corporation (ORACLE-4)
- RegDate: 2016-10-14
- Updated: 2017-11-27
- Ref: https://rdap.arin.net/registry/ip/132.145.0.0
- OrgName: Oracle Corporation
- OrgId: ORACLE-4
- Address: 500 Oracle Parkway
- Address: Attn: Domain Administrator
- City: Redwood Shores
- StateProv: CA
- PostalCode: 94065
- Country: US
- RegDate: 1988-04-29
- Updated: 2021-08-02
- Ref: https://rdap.arin.net/registry/entity/ORACLE-4
- OrgTechHandle: ORACL1-ARIN
- OrgTechName: ORACLE NIS
- OrgTechPhone: +1-650-506-2220
- OrgTechEmail: domain-contact_ww_grp@oracle.com
- OrgTechRef: https://rdap.arin.net/registry/entity/ORACL1-ARIN
- OrgAbuseHandle: NISAM-ARIN
- OrgAbuseName: Network Information Systems Abuse Management
- OrgAbusePhone: +1-650-506-2220
- OrgAbuseEmail: network-contact_ww_grp@oracle.com
- OrgAbuseRef: https://rdap.arin.net/registry/entity/NISAM-ARIN
- OrgRoutingHandle: ORACL2-ARIN
- OrgRoutingName: ORACLEROUTING
- OrgRoutingPhone: +1-800-392-2999
- OrgRoutingEmail: network-contact_ww@oracle.com
- OrgRoutingRef: https://rdap.arin.net/registry/entity/ORACL2-ARIN
- NetRange: 132.145.0.0 - 132.145.255.255
- CIDR: 132.145.0.0/16
- NetName: OC-195
- NetHandle: NET-132-145-0-0-2
- Parent: OC-195 (NET-132-145-0-0-1)
- NetType: Reassigned
- OriginAS:
- Organization: Oracle Public Cloud (OC-195)
- RegDate: 2017-12-01
- Updated: 2017-12-01
- Ref: https://rdap.arin.net/registry/ip/132.145.0.0
- OrgName: Oracle Public Cloud
- OrgId: OC-195
- Address: 1501 4th Ave
- City: Seattle
- StateProv: WA
- PostalCode: 98101
- Country: US
- RegDate: 2016-04-06
- Updated: 2021-01-13
- Ref: https://rdap.arin.net/registry/entity/OC-195
- OrgAbuseHandle: OBMO-ARIN
- OrgAbuseName: Oracle Bare Metal Operations
- OrgAbusePhone: +1-512-712-7403
- OrgAbuseEmail: domain-contact_ww_grp@oracle.com
- OrgAbuseRef: https://rdap.arin.net/registry/entity/OBMO-ARIN
- OrgTechHandle: OBMO-ARIN
- OrgTechName: Oracle Bare Metal Operations
- OrgTechPhone: +1-512-712-7403
- OrgTechEmail: domain-contact_ww_grp@oracle.com
- OrgTechRef: https://rdap.arin.net/registry/entity/OBMO-ARIN
- OrgRoutingHandle: ORACL2-ARIN
- OrgRoutingName: ORACLEROUTING
- OrgRoutingPhone: +1-800-392-2999
- OrgRoutingEmail: network-contact_ww@oracle.com
- OrgRoutingRef: https://rdap.arin.net/registry/entity/ORACL2-ARIN
Links to attack logs
dosing-ssh-bruteforce-ip-list-2022-11-17
Share on: