143.92.32.93 Threat Intelligence and Host Information

Share on:

General

This page contains threat intelligence information for the IPv4 address 143.92.32.93 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Potentially Malicious Host 🟡 35/100

Host and Network Information

  • Mitre ATT&CK IDs: T1110 - Brute Force
  • Tags: Bruteforce, IMAP, Nextray, Office 365, SMTP, cyber security, ioc, malicious, phishing, scanners, ssh, vultr
  • JARM: 3fd3fd0003fd3fd21c42d42d000000bdfc58c9a46434368cf60aa440385763

  • View other sources: Spamhaus VirusTotal

  • Country: Hong Kong
  • Network: AS64050 bgpnet global asn
  • Noticed: 1 times
  • Protcols Attacked: ssh
  • Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Spain, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
  • Passive DNS Results: rvvn.cn sdhf888.com cdlpnj.top www.xr456.xyz xr456.xyz iiii18.xyz iiii20.xyz iiii22.xyz www.iiii22.xyz iiii17.xyz www.iiii17.xyz www.iiii16.xyz iiii16.xyz www.iiii19.xyz iiii19.xyz iiii21.xyz www.iiii21.xyz xr123.xyz www.xr123.xyz bvc18.xyz bvc22.xyz www.bvc22.xyz bvc21.xyz www.bvc21.xyz www.bvc20.xyz bvc20.xyz www.bvc19.xyz bvc19.xyz bvc17.xyz www.bvc17.xyz bvc16.xyz www.bvc16.xyz bvb0021.xyz bvb0018.xyz bvb0017.xyz bvb0022.xyz www.bvb0020.xyz bvb0020.xyz bvb0019.xyz www.bvb0019.xyz bvb0016.xyz www.bvb0016.xyz www.bvb21.xyz www.bvb17.xyz www.bvb18.xyz bvb18.xyz bvb21.xyz bvb17.xyz bvb22.xyz www.bvb22.xyz bvb20.xyz www.bvb20.xyz www.bvb19.xyz bvb19.xyz bvb16.xyz www.bvb16.xyz fcf22.xyz www.fcf22.xyz www.fcf21.xyz fcf21.xyz www.fcf20.xyz fcf20.xyz www.fcf17.xyz fcf17.xyz 50508.site 3735.site 22123.site 6265.site 7576.site 9863.site www.7676.site www.52565.site http.52565.site 52565.site http.50508.site www.50508.site http.22123.site 21202.site http.8277.site https.8277.site 8277.site https.7576.site http.21202.site www.21202.site https.21202.site http.6265.site www.6265.site www.4887.site https.4887.site 4887.site https.9863.site https.5752.site 5752.site http.5752.site www.5752.site 7278.site https.3735.site 568538.com amsj.site http.amsj.site https.amsj.site http.2157.site https.2157.site www.2157.site 2157.site http.568538.me https.568538.me 568538.me https.77555.site www.77555.site http.77555.site m.77555.site 77555.site m.6163.site www.6163.site https.6163.site 6163633.com 659359b.com 659359c.com 595232a.com 595232c.com 995626.com www.995626.com http.tkcp.site http.659359b.com https.659359b.com www.659359a.com http.659359a.com www.595232a.com https.595232c.com www.595232c.com 662373c.com 595232b.com http.5ktk.us https.5ktk.cc 49cl.net 2aaggcc.com x6p.net www.9lzqq.com www.v6szl.com www.966cm.com www.x6p.net www.ackjz.com https.5kzhifu.site www.55kkpay.net www.55kkpay.com 55kkpay.com 55kkpay.net www.74tm.com www.00853ks.com www.626ck.site www.626kj.site 316868.com 999888.site tu5lem.waf.cx

Malware Detected on Host

Count: 1 2b5deac6176124ee1f7d237f070c39b03c964fce9a9fba0aaa1bce102710d2e0

Open Ports Detected

22 80

CVEs Detected

CVE-2016-20012 CVE-2017-15906 CVE-2018-15473 CVE-2018-15919 CVE-2018-20685 CVE-2019-6109 CVE-2019-6110 CVE-2019-6111 CVE-2020-14145 CVE-2020-15778 CVE-2021-36368 CVE-2021-41617

Map

Whois Information

  • NetRange: 143.92.0.0 - 143.92.127.255
  • CIDR: 143.92.0.0/17
  • NetName: APNIC-ERX-143-92-0-0
  • NetHandle: NET-143-92-0-0-1
  • Parent: NET143 (NET-143-0-0-0-0)
  • NetType: Early Registrations, Transferred to APNIC
  • OriginAS:
  • Organization: Asia Pacific Network Information Centre (APNIC)
  • RegDate: 2003-11-12
  • Updated: 2019-01-03
  • Comment: This IP address range is not registered in the ARIN database.
  • Comment: This range was transferred to the APNIC Whois Database as
  • Comment: part of the ERX (Early Registration Transfer) project.
  • Comment: For details, refer to the APNIC Whois Database via
  • Comment:
  • Comment: ** IMPORTANT NOTE: APNIC is the Regional Internet Registry
  • Comment: for the Asia Pacific region. APNIC does not operate networks
  • Comment: using this IP address range and is not able to investigate
  • Comment: spam or abuse reports relating to these addresses. For more
  • Ref: https://rdap.arin.net/registry/ip/143.92.0.0
  • OrgName: Asia Pacific Network Information Centre
  • OrgId: APNIC
  • Address: PO Box 3646
  • City: South Brisbane
  • StateProv: QLD
  • PostalCode: 4101
  • Country: AU
  • RegDate:
  • Updated: 2012-01-24
  • Ref: https://rdap.arin.net/registry/entity/APNIC
  • OrgAbuseHandle: AWC12-ARIN
  • OrgAbuseName: APNIC Whois Contact
  • OrgAbusePhone: +61 7 3858 3188
  • OrgAbuseEmail: [email protected]
  • OrgAbuseRef: https://rdap.arin.net/registry/entity/AWC12-ARIN
  • OrgTechHandle: AWC12-ARIN
  • OrgTechName: APNIC Whois Contact
  • OrgTechPhone: +61 7 3858 3188
  • OrgTechEmail: [email protected]
  • OrgTechRef: https://rdap.arin.net/registry/entity/AWC12-ARIN
  • inetnum: 143.92.32.0 - 143.92.47.255
  • netname: CTG92-32-HK
  • descr: CTG Server Ltd.
  • country: HK
  • admin-c: RCPL3-AP
  • tech-c: RCPL3-AP
  • abuse-c: AC2487-AP
  • status: ALLOCATED NON-PORTABLE
  • mnt-by: MAINT-RCPL-SG
  • mnt-irt: IRT-CTG-HK
  • last-modified: 2021-10-04T01:27:00Z
  • irt: IRT-CTG-HK
  • address: 202 ,2/F Kam Sang BLDG 257,Des Voeux RD Central Hong Kong
  • e-mail: [email protected]
  • abuse-mailbox: [email protected]
  • admin-c: RCPL3-AP
  • tech-c: RCPL3-AP
  • mnt-by: MAINT-RCPL-SG
  • last-modified: 2023-05-19T03:06:20Z
  • role: ABUSE CTGHK
  • address: 202 ,2/F Kam Sang BLDG 257,Des Voeux RD Central Hong Kong
  • country: ZZ
  • phone: +000000000
  • e-mail: [email protected]
  • admin-c: RCPL3-AP
  • tech-c: RCPL3-AP
  • nic-hdl: AC2487-AP
  • abuse-mailbox: [email protected]
  • mnt-by: APNIC-ABUSE
  • last-modified: 2023-05-19T03:07:10Z
  • role: RACKIP CONSULTANCY PTE LTD administrator
  • address: 399 Chai Wan Road, Chai Wan, Hong Kong
  • country: SG
  • phone: +603-7806-1316
  • fax-no: +603-7806-1316
  • e-mail: [email protected]
  • admin-c: RCPL3-AP
  • tech-c: RCPL3-AP
  • nic-hdl: RCPL3-AP
  • mnt-by: MAINT-RCPL-SG
  • last-modified: 2021-08-30T06:13:42Z
  • route: 143.92.32.0/24
  • origin: AS64050
  • descr: RACKIP CONSULTANCY PTE. LTD.
  • mnt-by: MAINT-RCPL-SG
  • last-modified: 2020-05-20T05:21:31Z

Links to attack logs

vultrwarsaw-ssh-bruteforce-ip-list-2022-09-26 vultrparis-ssh-bruteforce-ip-list-2022-10-12 vultrmadrid-ssh-bruteforce-ip-list-2022-09-22