144.172.118.90 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 144.172.118.90 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

🟠 Elevated — 52/100

Geographic Location

Host and Network Information

  • View other sources: Spamhaus VirusTotal Shodan AbuseIPDB
  • Country: United States
  • Network: AS398355 data ideas llc.
  • Noticed: 7 times
  • Protocols Attacked: SSH
  • Countries Attacked: United States of America
  • Tor Node: Yes

Tags

  • abuseipdb
  • badrequest
  • bruteforce
  • Bruteforce
  • Brute-Force
  • probing
  • scanning
  • SSH
  • webscan
  • webscanner
  • webscanner bruteforce web app attack

MITRE ATT&CK TTPs

  • T1046 - Network Service Scanning
  • T1498 - Network Denial of Service

Passive DNS

  • 21.221111.xyz

Attack Log References

Whois Information

NetRange: 144.172.64.0 - 144.172.127.255 CIDR: 144.172.64.0/18 NetName: PONYNET-12 NetHandle: NET-144-172-64-0-1 Parent: NET144 (NET-144-0-0-0-0) NetType: Direct Allocation OriginAS: AS53667 Organization: FranTech Solutions (SYNDI-5) RegDate: 2014-05-07 Updated: 2014-05-07 Ref: https://rdap.arin.net/registry/ip/144.172.64.0 OrgName: FranTech Solutions OrgId: SYNDI-5 Address: 1621 Central Ave City: Cheyenne StateProv: WY PostalCode: 82001 Country: US RegDate: 2010-07-21 Updated: 2017-01-28 Ref: https://rdap.arin.net/registry/entity/SYNDI-5 OrgTechHandle: FDI19-ARIN OrgTechName: Dias, Francisco OrgTechPhone: +1-778-977-8246 OrgTechEmail: admin@frantech.ca OrgTechRef: https://rdap.arin.net/registry/entity/FDI19-ARIN OrgAbuseHandle: FDI19-ARIN OrgAbuseName: Dias, Francisco OrgAbusePhone: +1-778-977-8246 OrgAbuseEmail: admin@frantech.ca OrgAbuseRef: https://rdap.arin.net/registry/entity/FDI19-ARIN NetRange: 144.172.118.0 - 144.172.119.255 CIDR: 144.172.118.0/23 NetName: DATA-IDEAS-LLC NetHandle: NET-144-172-118-0-1 Parent: PONYNET-12 (NET-144-172-64-0-1) NetType: Reallocated OriginAS: AS398355 Organization: Data Ideas llc. (DIL-134) RegDate: 2020-09-10 Updated: 2020-09-10 Ref: https://rdap.arin.net/registry/ip/144.172.118.0 OrgName: Data Ideas llc. OrgId: DIL-134 Address: P.O.Box 8434 City: The Woodlands StateProv: TX PostalCode: 77387 Country: US RegDate: 2020-02-07 Updated: 2021-01-08 Ref: https://rdap.arin.net/registry/entity/DIL-134 OrgDNSHandle: ADMIN7366-ARIN OrgDNSName: Admin OrgDNSPhone: +1-936-228-8005 OrgDNSEmail: admin@dataideas.com OrgDNSRef: https://rdap.arin.net/registry/entity/ADMIN7366-ARIN OrgRoutingHandle: ADMIN7366-ARIN OrgRoutingName: Admin OrgRoutingPhone: +1-936-228-8005 OrgRoutingEmail: admin@dataideas.com OrgRoutingRef: https://rdap.arin.net/registry/entity/ADMIN7366-ARIN OrgNOCHandle: ADMIN7366-ARIN OrgNOCName: Admin OrgNOCPhone: +1-936-228-8005 OrgNOCEmail: admin@dataideas.com OrgNOCRef: https://rdap.arin.net/registry/entity/ADMIN7366-ARIN OrgAbuseHandle: ABUSE7815-ARIN OrgAbuseName: Abuse OrgAbusePhone: +1-936-228-8005 OrgAbuseEmail: abuse@dataideas.com OrgAbuseRef: https://rdap.arin.net/registry/entity/ABUSE7815-ARIN OrgTechHandle: ADMIN7366-ARIN OrgTechName: Admin OrgTechPhone: +1-936-228-8005 OrgTechEmail: admin@dataideas.com OrgTechRef: https://rdap.arin.net/registry/entity/ADMIN7366-ARIN