144.91.105.157 Threat Intelligence and Host Information

Share on:

General

This page was generated as a result of this host being detected actively attacking or scanning another host. See below for information related to the host network, location, number of days noticed, protocols attacked and other information including reverse DNS and whois.

Possibly Malicious Host 🟢 19/100

Host and Network Information

  • Tags: scanners, ssh, vultr
  • View other sources: Spamhaus VirusTotal

  • Country: Germany
  • Network: AS51167 contabo gmbh
  • Noticed: 1 times
  • Protcols Attacked: ssh
  • Countries Attacked: Spain
  • Passive DNS Results: vmi353776.contaboserver.net

Open Ports Detected

10000 10134 1024 10243 1028 10443 10554 1063 110 11000 11112 1119 11210 11211 11371 1153 1167 1177 12000 123 1234 12345 1290 1311 1337 135 13579 14147 143 1471 1500 1515 1521 1588 1599 1604 161 1660 16992 16993 17000 1723 1741 1801 18081 18245 1883 19000 1911 1935 1950 1962 1990 2000 20000 2002 2003 2006 2008 2018 2021 2030 2048 2049 2051 2055 2057 2067 2069 2080 2081 2082 2083 2086 2087 2096 2100 21025 2121 2126 2181 2222 22222 2223 2233 2250 2259 23023 2320 2323 2332 2345 2375 2376 2443 2455 25 25001 25105 2548 2550 2551 2552 2555 2556 25565 2558 2561 2562 2563 2568 2601 2602 2626 2628 2650 27015 2761 28015 28017 2985 3000 3001 3048 3050 3051 3053 3058 3061 3062 3066 3068 3070 3072 3073 3074 3075 3076 3078 3079 3081 3082 3086 3088 3089 3092 3102 3105 3108 3109 3110 3112 3113 3114 3116 3117 3119 3129 31337 3221 3260 3268 3269 3270 3299 3301 3306 33060 3311 3333 3389 3401 3403 3404 3405 3406 3408 3443 3460 35000 3503 3542 3550 3551 3554 3555 3556 3557 3559 3569 3570 3689 3690 37215 3749 37777 3780 3790 3791 3838 3910 3951 3953 3954 4000 4010 4040 4042 4063 4064 4157 41800 4200 4243 4282 4321 4369 44158 443 4433 4444 4482 4506 4523 4545 4567 4643 4664 4734 4747 4808 4840 4848 4911 49152 49153 4949 50000 5001 5002 5003 5005 50050 5006 5007 50070 5009 5010 50100 5050 5060 5090 51106 5122 51235 5172 5190 5201 5209 5269 5280 52869 53 5357 5400 54138 5432 5494 5500 55000 5542 55442 55443 5560 5590 5593 5596 5597 5598 5601 5605 5607 5608 5609 5672 5673 5800 5801 5822 5858 5900 5901 5906 5908 5909 5910 5984 5985 5986 6000 6001 6002 6006 60129 6080 61613 61616 623 6262 631 6379 6443 6464 6550 6560 6561 6580 6588 6590 6601 6605 6633 6650 6653 6662 6664 6667 6668 6748 6789 6955 7001 7003 7070 7071 7218 7415 7443 7444 7474 7493 7500 7510 7535 7537 7547 7548 7654 7776 7777 7778 7779 7989 7998 80 8002 8004 8005 8008 8009 8010 8012 8013 8014 8015 8016 8019 8020 8022 8027 8028 8029 8031 8035 8037 8038 8041 8044 8045 8048 8049 8050 8052 8055 8056 8060 8064 8066 8080 8081 8082 8083 8086 8087 8089 8091 8093 8096 8099 8101 8102 8104 8105 8106 8110 8112 8123 8139 8140 8159 8182 8239 8248 8249 8251 8282 8291 8333 8334 8383 8405 8408 8413 8415 8417 8421 8422 8423 8424 8428 8430 8431 8432 8442 8443 8444 8445 8446 8447 8500 8513 8553 8554 8590 8602 8621 8622 8637 8649 8663 8666 8686 8688 8700 8728 8779 8782 8787 8790 8791 8800 8801 8804 8807 8809 8810 8811 8812 8822 8823 8824 8826 8827 8828 8829 8830 8834 8836 8837 8840 8845 8847 8848 8849 8850 8853 8855 8860 8861 8863 8865 8866 8867 8868 8869 8871 8872 8873 8875 8878 8879 8880 8881 8885 8887 8891 8899 8988 8990 8993 9000 9001 9002 9003 9004 9008 9009 9011 9013 9017 9024 9026 9029 9033 9035 9036 9037 9041 9043 9044 9047 9048 9049 9050 9051 9070 9080 9082 9084 9091 9092 9097 9100 9104 9105 9106 9109 9110 9136 9151 9160 9189 9191 9200 9201 9202 9203 9206 9213 9216 9217 9219 9222 9251 9295 9299 9300 9303 9306 9307 9308 9310 9389 9418 9433 9445 9530 9550 9633 9761 9765 9800 9861 9869 9898 993 9943 9944 9950 9981 9988 9999

CVEs Detected

CVE-2020-1938

Map

Whois Information

  • NetRange: 144.91.64.0 - 144.91.127.255
  • CIDR: 144.91.64.0/18
  • NetName: RIPE
  • NetHandle: NET-144-91-64-0-1
  • Parent: NET144 (NET-144-0-0-0-0)
  • NetType: Early Registrations, Transferred to RIPE NCC
  • OriginAS:
  • Organization: RIPE Network Coordination Centre (RIPE)
  • RegDate: 2019-06-26
  • Updated: 2019-06-26
  • Ref: https://rdap.arin.net/registry/ip/144.91.64.0
  • OrgName: RIPE Network Coordination Centre
  • OrgId: RIPE
  • Address: P.O. Box 10096
  • City: Amsterdam
  • StateProv:
  • PostalCode: 1001EB
  • Country: NL
  • RegDate:
  • Updated: 2013-07-29
  • Ref: https://rdap.arin.net/registry/entity/RIPE
  • OrgAbuseHandle: ABUSE3850-ARIN
  • OrgAbuseName: Abuse Contact
  • OrgAbusePhone: +31205354444
  • OrgAbuseEmail: [email protected]
  • OrgAbuseRef: https://rdap.arin.net/registry/entity/ABUSE3850-ARIN
  • OrgTechHandle: RNO29-ARIN
  • OrgTechName: RIPE NCC Operations
  • OrgTechPhone: +31 20 535 4444
  • OrgTechEmail: [email protected]
  • OrgTechRef: https://rdap.arin.net/registry/entity/RNO29-ARIN
  • inetnum: 144.91.96.0 - 144.91.127.255
  • netname: CONTABO
  • descr: Contabo GmbH
  • country: DE
  • org: ORG-GG22-RIPE
  • admin-c: MH7476-RIPE
  • tech-c: MH7476-RIPE
  • status: ASSIGNED PA
  • mnt-by: MNT-CONTABO
  • created: 2019-06-27T12:39:20Z
  • last-modified: 2019-06-27T12:39:20Z
  • organisation: ORG-GG22-RIPE
  • org-name: Contabo GmbH
  • country: DE
  • org-type: LIR
  • address: Aschauer Strasse 32a
  • address: 81549
  • address: Munchen
  • address: GERMANY
  • phone: +498921268372
  • fax-no: +498921665862
  • abuse-c: MH12453-RIPE
  • mnt-ref: RIPE-NCC-HM-MNT
  • mnt-ref: MNT-CONTABO
  • mnt-ref: MNT-OCIRIS
  • mnt-by: RIPE-NCC-HM-MNT
  • mnt-by: MNT-CONTABO
  • created: 2009-12-09T13:41:08Z
  • last-modified: 2021-09-14T10:49:04Z
  • person: Wilhelm Zwalina
  • address: Contabo GmbH
  • address: Aschauer Str. 32a
  • address: 81549 Muenchen
  • phone: +49 89 21268372
  • fax-no: +49 89 21665862
  • nic-hdl: MH7476-RIPE
  • mnt-by: MNT-CONTABO
  • mnt-by: MNT-GIGA-HOSTING
  • created: 2010-01-04T10:41:37Z
  • last-modified: 2020-04-24T16:09:30Z
  • route: 144.91.104.0/23
  • descr: CONTABO
  • origin: AS51167
  • mnt-by: MNT-CONTABO
  • created: 2019-06-28T06:37:09Z
  • last-modified: 2019-06-28T06:37:09Z

Links to attack logs

vultrmadrid-ssh-bruteforce-ip-list-2023-04-30