141.255.161.166 Threat Intelligence and Host Information

Share on:

General

This page contains threat intelligence information for the IPv4 address 141.255.161.166 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Likely Malicious Host 🟠 70/100

Host and Network Information

  • Tags: bruteforce, cyber security, ioc, malicious, Nextray, phishing, scanners, ssh, SSH, TOR, VPN, vultr
  • Known tor exit node

  • View other sources: Spamhaus VirusTotal
  • Contained within other IP sets: blocklist_net_ua, botscout_30d, dm_tor, et_tor, stopforumspam_180d, stopforumspam_1d, stopforumspam_30d, stopforumspam_365d, stopforumspam_7d, stopforumspam_90d, stopforumspam

  • Known TOR node
  • Country: Switzerland
  • Network: AS51852 private layer inc
  • Noticed: 44 times
  • Protocols Attacked: ssh
  • Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
  • Passive DNS Results: getcards.pw grabgiftcards.pw

Malware Detected on Host

Count: 43 e46cc606d9a72314d3e0e8899b1d6a3e7f827e590b2aa0fd5f81039567647263 0f08374b932348655cc3011bc99f0e489fa3f947b95ef63d2ec605938ef6cb1c d8f7adb539058d7233c39639f289171a64c876245d5d2b9348c44372af24bc7f 5695daf8b1a0075f5e292b983c44609c5108ae5603b1479b395d8d6c3df26407 92a627451a153edbcd26bc41d50db7af3185c0fe73fba3df18edd98822cadfcf b16411c0b7b98467d5864a71b6760f951816e0f26b2ff1379feedd0456701fce dcfd9d1235ca840bad9f54e1f85a9f6c30756f1bb5ba7871325fa9dbbc78acaf 04cd0ddbf67a6518b3460ef4a9c5e91ab103de73b4c3d2116e3b92b7f4b668eb 201739015bd590f3467756cb6c37caae1e338a9e4a81f85193c9dbb9b2f6971b 16355c31d833e42f3074d717a143d67f6b13f33fa3e3821a31e088274220e70f

Open Ports Detected

123

Map

Whois Information

  • NetRange: 141.0.0.0 - 141.255.255.255
  • CIDR: 141.0.0.0/8
  • NetName: RIPE-ERX-141
  • NetHandle: NET-141-0-0-0-0
  • Parent: ()
  • NetType: Early Registrations, Maintained by RIPE NCC
  • OriginAS:
  • Organization: RIPE Network Coordination Centre (RIPE)
  • RegDate: 1993-05-01
  • Updated: 2009-05-18
  • Comment: These addresses have been further assigned to users in
  • Comment: the RIPE NCC region. Contact information can be found in
  • Ref: https://rdap.arin.net/registry/ip/141.0.0.0
  • OrgName: RIPE Network Coordination Centre
  • OrgId: RIPE
  • Address: P.O. Box 10096
  • City: Amsterdam
  • StateProv:
  • PostalCode: 1001EB
  • Country: NL
  • RegDate:
  • Updated: 2013-07-29
  • Ref: https://rdap.arin.net/registry/entity/RIPE
  • OrgTechHandle: RNO29-ARIN
  • OrgTechName: RIPE NCC Operations
  • OrgTechPhone: +31 20 535 4444
  • OrgTechEmail: [email protected]
  • OrgTechRef: https://rdap.arin.net/registry/entity/RNO29-ARIN
  • OrgAbuseHandle: ABUSE3850-ARIN
  • OrgAbuseName: Abuse Contact
  • OrgAbusePhone: +31205354444
  • OrgAbuseEmail: [email protected]
  • OrgAbuseRef: https://rdap.arin.net/registry/entity/ABUSE3850-ARIN
  • inetnum: 141.255.161.160 - 141.255.161.191
  • netname: AIRVPSCOMP_VPSPROVIDER
  • country: CH
  • geoloc: 47.3769 8.5417
  • admin-c: AVCV1-RIPE
  • tech-c: AVCV1-RIPE
  • abuse-c: AVRA2-RIPE
  • mnt-by: KP73900-MNT
  • status: ASSIGNED PA
  • created: 2017-12-15T05:43:27Z
  • last-modified: 2017-12-15T05:43:27Z
  • person: Air VPS COMP VPS Provider
  • address: Edif. Ocean Business Plaza 1404 Marbella Panama City
  • phone: +41 75 414 2912
  • nic-hdl: AVCV1-RIPE
  • mnt-by: KP73900-MNT
  • created: 2017-12-15T05:35:25Z
  • last-modified: 2017-12-15T05:35:25Z
  • route: 141.255.160.0/21
  • descr: 141 Range
  • origin: AS51852
  • mnt-by: KP73900-MNT
  • created: 2014-04-26T11:42:33Z
  • last-modified: 2014-04-26T11:42:33Z

Links to attack logs

** dotoronto-ssh-bruteforce-ip-list-2022-11-18 vultrwarsaw-ssh-bruteforce-ip-list-2022-08-29 ** **