143.198.114.252 Threat Intelligence and Host Information

Share on:

General

This page contains threat intelligence information for the IPv4 address 143.198.114.252 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Possibly Malicious Host 🟢 25/100

Host and Network Information

  • Tags: Brute-Force, Bruteforce, SSH

  • View other sources: Spamhaus VirusTotal

  • Country: United States
  • Network: AS14061 digitalocean llc
  • Noticed: 1 times
  • Protcols Attacked: ssh
  • Passive DNS Results: sislab.punored.com angie.punored.com cuvino.punored.com demo.punored.com watanabe.punored.com mcedwin.com u183556.punored.com u174397.punored.com u217256.punored.com u216999.punored.com u153154.punored.com u171834.punored.com u151171.punored.com u217141.punored.com u180180.punored.com u217340.punored.com u217518.punored.com u180975.punored.com u215269.punored.com u215298.punored.com u183134.punored.com mcedwin.punored.com u217528.punored.com u217019.punored.com u215173.punored.com u215219.punored.com u215288.punored.com u217038.punored.com u215310.punored.com u217326.punored.com u185489.punored.com u104777.punored.com u215182.punored.com u181918.punored.com u123549.punored.com u215263.punored.com u215402.punored.com u217298.punored.com u182973.punored.com u217005.punored.com u055176.punored.com u217239.punored.com u217182.punored.com u217308.punored.com u186105.punored.com u175496.punored.com u175082.punored.com u215284.punored.com u215143.punored.com u202544.punored.com u217481.punored.com u186213.punored.com u217507.punored.com u215292.punored.com u214241.punored.com u217067.punored.com u217271.punored.com u215167.punored.com punored.com u185222.punored.com u180974.punored.com u180183.punored.com u171813.punored.com u161998.punored.com u185393.punored.com u217309.punored.com u217473.punored.com 143-198-114-252.ipv4.nknlabs.io

Open Ports Detected

22 25 3306 443 80 8004

CVEs Detected

CVE-2006-20001 CVE-2022-36760 CVE-2022-37436 CVE-2023-25690 CVE-2023-27522

Map

Whois Information

  • NetRange: 143.198.0.0 - 143.198.255.255
  • CIDR: 143.198.0.0/16
  • NetName: DIGITALOCEAN-143-198-0-0
  • NetHandle: NET-143-198-0-0-1
  • Parent: NET143 (NET-143-0-0-0-0)
  • NetType: Direct Allocation
  • OriginAS: AS14061
  • Organization: DigitalOcean, LLC (DO-13)
  • RegDate: 2020-01-24
  • Updated: 2020-04-03
  • Comment: Routing and Peering Policy can be found at https://www.as14061.net
  • Comment:
  • Ref: https://rdap.arin.net/registry/ip/143.198.0.0
  • OrgName: DigitalOcean, LLC
  • OrgId: DO-13
  • Address: 101 Ave of the Americas
  • Address: FL2
  • City: New York
  • StateProv: NY
  • PostalCode: 10013
  • Country: US
  • RegDate: 2012-05-14
  • Updated: 2023-07-07
  • Ref: https://rdap.arin.net/registry/entity/DO-13
  • OrgNOCHandle: NOC32014-ARIN
  • OrgNOCName: Network Operations Center
  • OrgNOCPhone: +1-347-875-6044
  • OrgNOCEmail: [email protected]
  • OrgNOCRef: https://rdap.arin.net/registry/entity/NOC32014-ARIN
  • OrgAbuseHandle: ABUSE5232-ARIN
  • OrgAbuseName: Abuse, DigitalOcean
  • OrgAbusePhone: +1-347-875-6044
  • OrgAbuseEmail: [email protected]
  • OrgAbuseRef: https://rdap.arin.net/registry/entity/ABUSE5232-ARIN
  • OrgTechHandle: NOC32014-ARIN
  • OrgTechName: Network Operations Center
  • OrgTechPhone: +1-347-875-6044
  • OrgTechEmail: [email protected]
  • OrgTechRef: https://rdap.arin.net/registry/entity/NOC32014-ARIN

Links to attack logs

** dosing-ssh-bruteforce-ip-list-2023-07-19