139.59.36.57 Threat Intelligence and Host Information
General
This page contains threat intelligence information for the IPv4 address 139.59.36.57 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.
Likely Malicious Host 🟠 60/100
Host and Network Information
-
Mitre ATT&CK IDs: T1078 - Valid Accounts, T1083 - File and Directory Discovery, T1098.004 - SSH Authorized Keys, T1105 - Ingress Tool Transfer, T1110.004 - Credential Stuffing, T1110 - Brute Force
-
Tags: brute force, Bruteforce, Brute-Force, cowrie, scanners, ssh, SSH, TOR, VPN, vultr
-
View other sources: Spamhaus VirusTotal
- Country: India
- Network:
- Noticed: 47 times
- Protocols Attacked: ssh
- Countries Attacked: Australia, Poland, Spain, United States of America
- Passive DNS Results: e2e-dbaas-mongodb-yczqi-2d57da70.mongo.ondigitalocean.com www.upmssp.com upmssp.com www.digitaloceanfastpanel.sroywebstudio.cloudns.nz digitaloceanfastpanel.sroywebstudio.cloudns.nz c767e9ce-2c36-45ca-a821-6ccb4f75f7aa.unifi-hosting.ui.com 5a47ea8f-bb2d-496f-b124-ddd627701c09.unifi-hosting.dev.ui.com
Malware Detected on Host
Count: 8 a9331272b5197b4fb6d599b0d085bcadfb4c16cc6f0aec612378992c37de0ea7 47eb9a339e3556fa54aabdd2400cee823bbe68528efcfecfdb5f7bdf96b9b3af 42335639a7ed6c9bb208550fa904981d79082ebcccf29cf1e02d1e4a8078e32a 69321f1b923a979315fd33fabf9b8843687a716842218b8eaa640f10d78886d8 aba89324af638171199d66ad5f77708eec58a5497ceddef4d96bab7f88867243 ac6eaecd77ea705c5b6376264afc9619ec0bed044d3fcfe61dbbe61400380d4a dbc2b8ea8fd63187ea9fe58638eefa7797a11d32a93f9e0737efaf6786be1223 b125caadbada269af9b1c4b6191bc5a4a4c41ee72b32087f16962de5d9700d6e
Map
Whois Information
- NetRange: 139.59.0.0 - 139.59.255.255
- CIDR: 139.59.0.0/16
- NetName: APNIC-ERX-139-59-0-0
- NetHandle: NET-139-59-0-0-1
- Parent: NET139 (NET-139-0-0-0-0)
- NetType: Early Registrations, Transferred to APNIC
- OriginAS:
- Organization: Asia Pacific Network Information Centre (APNIC)
- RegDate: 2004-03-03
- Updated: 2009-10-08
- Comment: This IP address range is not registered in the ARIN database.
- Comment: This range was transferred to the APNIC Whois Database as
- Comment: part of the ERX (Early Registration Transfer) project.
- Comment: For details, refer to the APNIC Whois Database via
- Comment:
- Comment: ** IMPORTANT NOTE: APNIC is the Regional Internet Registry
- Comment: for the Asia Pacific region. APNIC does not operate networks
- Comment: using this IP address range and is not able to investigate
- Comment: spam or abuse reports relating to these addresses. For more
- Ref: https://rdap.arin.net/registry/ip/139.59.0.0
- OrgName: Asia Pacific Network Information Centre
- OrgId: APNIC
- Address: PO Box 3646
- City: South Brisbane
- StateProv: QLD
- PostalCode: 4101
- Country: AU
- RegDate:
- Updated: 2012-01-24
- Ref: https://rdap.arin.net/registry/entity/APNIC
- OrgAbuseHandle: AWC12-ARIN
- OrgAbuseName: APNIC Whois Contact
- OrgAbusePhone: +61 7 3858 3188
- OrgAbuseEmail: search-apnic-not-arin@apnic.net
- OrgAbuseRef: https://rdap.arin.net/registry/entity/AWC12-ARIN
- OrgTechHandle: AWC12-ARIN
- OrgTechName: APNIC Whois Contact
- OrgTechPhone: +61 7 3858 3188
- OrgTechEmail: search-apnic-not-arin@apnic.net
- OrgTechRef: https://rdap.arin.net/registry/entity/AWC12-ARIN
- inetnum: 139.59.32.0 - 139.59.47.255
- netname: DIGITALOCEAN-AP
- descr: DigitalOcean, LLC
- country: IN
- admin-c: DOIA2-AP
- tech-c: DOIA2-AP
- abuse-c: AD699-AP
- status: ASSIGNED NON-PORTABLE
- mnt-by: MAINT-DIGITALOCEAN-AP
- mnt-irt: IRT-DIGITALOCEAN-AP
- last-modified: 2020-05-31T21:35:25Z
- irt: IRT-DIGITALOCEAN-AP
- address: 105 Edgeview Drive, Suite 425, Broomfield, Colorado 80021
- e-mail: noc@digitalocean.com
- abuse-mailbox: abuse@digitalocean.com
- admin-c: DOIA2-AP
- tech-c: DOIA2-AP
- mnt-by: MAINT-DIGITALOCEAN-AP
- last-modified: 2025-12-10T13:07:01Z
- role: ABUSE DIGITALOCEANAP
- country: ZZ
- address: 105 Edgeview Drive, Suite 425, Broomfield, Colorado 80021
- phone: +000000000
- e-mail: noc@digitalocean.com
- admin-c: DOIA2-AP
- tech-c: DOIA2-AP
- nic-hdl: AD699-AP
- abuse-mailbox: abuse@digitalocean.com
- mnt-by: APNIC-ABUSE
- last-modified: 2025-12-10T13:07:40Z
- role: Digital Ocean Inc administrator
- address: 105 Edgeview Drive, Suite 425, Broomfield, Colorado 80021
- country: US
- phone: +1 646-827-4366
- fax-no: +1 646-827-4366
- e-mail: abuse@digitalocean.com
- admin-c: DOIA2-AP
- tech-c: DOIA2-AP
- nic-hdl: DOIA2-AP
- mnt-by: MAINT-DIGITALOCEAN-AP
- last-modified: 2025-04-11T18:24:27Z
Links to attack logs
bruteforce-ip-list-2023-08-21 vultrmadrid-ssh-bruteforce-ip-list-2023-08-27 ****** digitaloceanfrankfurt-ssh-bruteforce-ip-list-2023-08-25 bruteforce-ip-list-2023-08-15 ****** ****** vultrwarsaw-ssh-bruteforce-ip-list-2023-08-27
Share on: