139.59.109.41 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 139.59.109.41 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Likely Malicious Host 🟠 60/100

Host and Network Information

  • Mitre ATT&CK IDs: T1078 - Valid Accounts, T1083 - File and Directory Discovery, T1098.004 - SSH Authorized Keys, T1105 - Ingress Tool Transfer, T1110.004 - Credential Stuffing, T1110 - Brute Force

  • Tags: Bruteforce, Brute-Force, cowrie, cyber security, ioc, malicious, Nextray, phishing, port 22, scanners, ssh, SSH, tcp/22, vultr

  • JARM: 27d27d27d00027d00042d43d00041de2e563ee0d1902aeebdf8197560d8f75

  • View other sources: Spamhaus VirusTotal

  • Country: Singapore
  • Network:
  • Noticed: 50 times
  • Protocols Attacked: ssh
  • Countries Attacked: Australia, Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
  • Passive DNS Results: nocost.sibe-vpn.live www.wuzhuoyiblog404.cf sg2-test.sakuralou.tk www.dall7ball.one dall7ball.one www.kinheybkk.com seefah.com

Malware Detected on Host

Count: 424 b2d3694c1111a68680d9d8d6ffdcf60d104705d42b7c678d21985f391d4838c8 5d3bd7d89589ea0d17adc6fb8646d582e47b6f3c42c97c465a63ffdc655de5b1 400cafad8dfd9c7cc68fb9e26fa07f1edd58ab61338c7491b22962e27e65812d 179dd7691fd29f18300c744480b99c0e886d771c07ecc42bf9a4f596145f91c6 0e8422079f58c628b40b132d27a707817ccf66ab65199fdf84f1d45118584ca6 06ed9c10c7b04993b4a7392f10bfc4d7bf3f35ba2828f4a06e269af9365d65a7 5cfe54306a4f52892d176d66b6ce0c624820d865f7eaa94867c1bdb15c7d1708 8ef1e4050204e1be50536706e790bfada19e8ceceb3a3ea841cf13c8473b94ad a743fa898008077b9c7331547520cce94ec1cd8f95323c2bf3c91c4e7a66875d 95276f51959260cb55e9f476eb5b334301b789ed91dab04bf8572e5a8bcaf1b8

Open Ports Detected

110 143 21 22 25 443 465 53 587 7080 80 8090 993 995

Map

Whois Information

  • NetRange: 139.59.0.0 - 139.59.255.255
  • CIDR: 139.59.0.0/16
  • NetName: APNIC-ERX-139-59-0-0
  • NetHandle: NET-139-59-0-0-1
  • Parent: NET139 (NET-139-0-0-0-0)
  • NetType: Early Registrations, Transferred to APNIC
  • OriginAS:
  • Organization: Asia Pacific Network Information Centre (APNIC)
  • RegDate: 2004-03-03
  • Updated: 2009-10-08
  • Comment: This IP address range is not registered in the ARIN database.
  • Comment: This range was transferred to the APNIC Whois Database as
  • Comment: part of the ERX (Early Registration Transfer) project.
  • Comment: For details, refer to the APNIC Whois Database via
  • Comment:
  • Comment: ** IMPORTANT NOTE: APNIC is the Regional Internet Registry
  • Comment: for the Asia Pacific region. APNIC does not operate networks
  • Comment: using this IP address range and is not able to investigate
  • Comment: spam or abuse reports relating to these addresses. For more
  • Ref: https://rdap.arin.net/registry/ip/139.59.0.0
  • OrgName: Asia Pacific Network Information Centre
  • OrgId: APNIC
  • Address: PO Box 3646
  • City: South Brisbane
  • StateProv: QLD
  • PostalCode: 4101
  • Country: AU
  • RegDate:
  • Updated: 2012-01-24
  • Ref: https://rdap.arin.net/registry/entity/APNIC
  • OrgTechHandle: AWC12-ARIN
  • OrgTechName: APNIC Whois Contact
  • OrgTechPhone: +61 7 3858 3188
  • OrgTechEmail: search-apnic-not-arin@apnic.net
  • OrgTechRef: https://rdap.arin.net/registry/entity/AWC12-ARIN
  • OrgAbuseHandle: AWC12-ARIN
  • OrgAbuseName: APNIC Whois Contact
  • OrgAbusePhone: +61 7 3858 3188
  • OrgAbuseEmail: search-apnic-not-arin@apnic.net
  • OrgAbuseRef: https://rdap.arin.net/registry/entity/AWC12-ARIN
  • inetnum: 139.59.96.0 - 139.59.111.255
  • netname: DIGITALOCEAN-AP
  • descr: DigitalOcean, LLC
  • country: SG
  • admin-c: DOIA2-AP
  • tech-c: DOIA2-AP
  • abuse-c: AD699-AP
  • status: ASSIGNED NON-PORTABLE
  • mnt-by: MAINT-DIGITALOCEAN-AP
  • mnt-irt: IRT-DIGITALOCEAN-AP
  • last-modified: 2020-05-31T21:36:27Z
  • irt: IRT-DIGITALOCEAN-AP
  • address: 105 Edgeview Drive, Suite 425, Broomfield, Colorado 80021
  • e-mail: noc@digitalocean.com
  • abuse-mailbox: abuse@digitalocean.com
  • admin-c: DOIA2-AP
  • tech-c: DOIA2-AP
  • mnt-by: MAINT-DIGITALOCEAN-AP
  • last-modified: 2025-08-14T13:26:34Z
  • role: ABUSE DIGITALOCEANAP
  • country: ZZ
  • address: 105 Edgeview Drive, Suite 425, Broomfield, Colorado 80021
  • phone: +000000000
  • e-mail: noc@digitalocean.com
  • admin-c: DOIA2-AP
  • tech-c: DOIA2-AP
  • nic-hdl: AD699-AP
  • abuse-mailbox: abuse@digitalocean.com
  • mnt-by: APNIC-ABUSE
  • last-modified: 2025-08-14T13:27:09Z
  • role: Digital Ocean Inc administrator
  • address: 105 Edgeview Drive, Suite 425, Broomfield, Colorado 80021
  • country: US
  • phone: +1 646-827-4366
  • fax-no: +1 646-827-4366
  • e-mail: abuse@digitalocean.com
  • admin-c: DOIA2-AP
  • tech-c: DOIA2-AP
  • nic-hdl: DOIA2-AP
  • mnt-by: MAINT-DIGITALOCEAN-AP
  • last-modified: 2025-04-11T18:24:27Z

Links to attack logs

vultrparis-ssh-bruteforce-ip-list-2023-11-05 ****** digitaloceanfrankfurt-ssh-bruteforce-ip-list-2023-11-04 digitaloceantoronto-ssh-bruteforce-ip-list-2023-11-05 bruteforce-ip-list-2023-11-04 vultrmadrid-ssh-bruteforce-ip-list-2023-06-21 digitaloceanlondon-ssh-bruteforce-ip-list-2023-11-03 digitaloceantoronto-ssh-bruteforce-ip-list-2023-11-03 digitaloceanlondon-ssh-bruteforce-ip-list-2023-11-05 digitaloceansingapore-ssh-bruteforce-ip-list-2023-11-04 ****** bruteforce-ip-list-2023-11-05 digitaloceanfrankfurt-ssh-bruteforce-ip-list-2023-11-05 vultrparis-ssh-bruteforce-ip-list-2023-11-03 ****** dolondon-ssh-bruteforce-ip-list-2023-06-19

Share on: