134.122.188.16 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 134.122.188.16 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Potentially Malicious Host 🟡 45/100

Host and Network Information

  • Mitre ATT&CK IDs: T1021.004 - SSH, T1110 - Brute Force

  • Tags: Bruteforce, Nextray, SSH, brute force, bruteforce, cyber security, digital ocean, ioc, malicious, phishing, scanners, ssh, vultr

  • View other sources: Spamhaus VirusTotal

  • Contained within other IP sets: blocklist_de, blocklist_de_ssh, blocklist_net_ua, greensnow

  • Country: Singapore
  • Network: AS64050 bgpnet global asn
  • Noticed: 1 times
  • Protcols Attacked: ssh
  • Countries Attacked: Australia, Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Spain, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
  • Passive DNS Results: 261qf.com 875qf.com 923qf.com 836qf.com 680qf.com quanfa1.cyou quanfa.cyou quanfa2.cyou qf0755vip.com www.qf022vip.com qf022vip.com www.qf028vip.com qf028vip.com www.qf020vip.com qf020vip.com www.qf010vip.com qf010vip.com qf11.vip qf33.vip qf55.vip qf00.vip qf22.vip 726007.com 721550.com 722910.com 726880.com 729100.com 91sese.xyz kf2szdq6.n.cdn-ss.cc www.wns086.cn cdn.wns758.cn nbwktx.com www.nbwktx.com origtime.com

Open Ports Detected

100 111 443 4430 5222 7002 80 8088 8089 8099 8443 8888 9999

Map

Whois Information

  • NetRange: 134.122.128.0 - 134.122.255.255
  • CIDR: 134.122.128.0/17
  • NetName: APNIC
  • NetHandle: NET-134-122-128-0-1
  • Parent: NET134 (NET-134-0-0-0-0)
  • NetType: Early Registrations, Transferred to APNIC
  • OriginAS:
  • Organization: Asia Pacific Network Information Centre (APNIC)
  • RegDate: 2019-11-11
  • Updated: 2019-11-11
  • Ref: https://rdap.arin.net/registry/ip/134.122.128.0
  • OrgName: Asia Pacific Network Information Centre
  • OrgId: APNIC
  • Address: PO Box 3646
  • City: South Brisbane
  • StateProv: QLD
  • PostalCode: 4101
  • Country: AU
  • RegDate:
  • Updated: 2012-01-24
  • Ref: https://rdap.arin.net/registry/entity/APNIC
  • OrgAbuseHandle: AWC12-ARIN
  • OrgAbuseName: APNIC Whois Contact
  • OrgAbusePhone: +61 7 3858 3188
  • OrgAbuseEmail: search-apnic-not-arin@apnic.net
  • OrgAbuseRef: https://rdap.arin.net/registry/entity/AWC12-ARIN
  • OrgTechHandle: AWC12-ARIN
  • OrgTechName: APNIC Whois Contact
  • OrgTechPhone: +61 7 3858 3188
  • OrgTechEmail: search-apnic-not-arin@apnic.net
  • OrgTechRef: https://rdap.arin.net/registry/entity/AWC12-ARIN
  • inetnum: 134.122.160.0 - 134.122.191.255
  • netname: BGP160-JP
  • descr: BGP Network Limited Co.,Ltd
  • country: JP
  • admin-c: BCPL4-AP
  • tech-c: BCPL4-AP
  • abuse-c: AR825-AP
  • status: ALLOCATED NON-PORTABLE
  • mnt-by: MAINT-RCPL-SG
  • mnt-irt: IRT-RCPL-SG
  • last-modified: 2022-03-01T03:10:26Z
  • irt: IRT-RCPL-SG
  • address: 399 Chai Wan Road, Chai Wan, Hong Kong
  • e-mail: abuse@rackip.com
  • abuse-mailbox: abuse@rackip.com
  • admin-c: RCPL3-AP
  • tech-c: RCPL3-AP
  • mnt-by: MAINT-RCPL-SG
  • last-modified: 2023-04-12T03:58:02Z
  • role: ABUSE RCPLSG
  • address: 399 Chai Wan Road, Chai Wan, Hong Kong
  • country: ZZ
  • phone: +000000000
  • e-mail: abuse@rackip.com
  • admin-c: RCPL3-AP
  • tech-c: RCPL3-AP
  • nic-hdl: AR825-AP
  • abuse-mailbox: abuse@rackip.com
  • mnt-by: APNIC-ABUSE
  • last-modified: 2023-04-12T03:58:22Z
  • role: BGP CONSULTANCY PTE LTD administrator
  • address: 399 Chai Wan Road, Chai Wan, Hong Kong
  • country: HK
  • phone: +603-7806-1316
  • e-mail: abuse@rackip.com
  • admin-c: RCPL3-AP
  • tech-c: RCPL3-AP
  • nic-hdl: BCPL4-AP
  • mnt-by: MAINT-RCPL-SG
  • last-modified: 2017-03-14T09:18:17Z
  • route: 134.122.188.0/24
  • origin: AS64050
  • descr: RACKIP CONSULTANCY PTE. LTD.
  • mnt-by: MAINT-RCPL-SG
  • last-modified: 2020-05-20T05:23:33Z

Links to attack logs

****** dofrank-ssh-bruteforce-ip-list-2023-03-11 vultrmadrid-ssh-bruteforce-ip-list-2023-03-27

Share on: