144.91.120.237 Threat Intelligence and Host Information

Share on:

General

This page contains threat intelligence information for the IPv4 address 144.91.120.237 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Likely Malicious Host 🟠 65/100

Host and Network Information

  • Mitre ATT&CK IDs: T1078 - Valid Accounts, T1083 - File and Directory Discovery, T1098.004 - SSH Authorized Keys, T1105 - Ingress Tool Transfer, T1110.004 - Credential Stuffing, T1110 - Brute Force
  • Tags: Bruteforce, cowrie, cyber security, digital ocean, ioc, malicious, Nextray, phishing, scanners, ssh, tsec

  • View other sources: Spamhaus VirusTotal
  • Contained within other IP sets: haley_ssh

  • Country: Germany
  • Network: AS51167 contabo gmbh
  • Noticed: 38 times
  • Protocols Attacked: ssh
  • Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
  • Passive DNS Results: www.alomazot.dvzgrup.com alomazot.dvzgrup.com oznehirsu.com www.bevanda.com.tr www.qways.ch www.praxis-anatolien.ch www.msds.dvzgrup.com msds.dvzgrup.com www.antikaparalar.com www.aracaksesuarlari.com www.baktomix.com www.albayrak.auction ongrouplogistics.com www.meridyensoft.com crm.petamobil.com www.crm.petamobil.com www.osidbilisim.com www.annededi.com www.massiamo.net medikalestetikurfa.com www.medikalestetikurfa.com mos.dvzgrup.com turizm3.dvzgrup.com vet.dvzgrup.com umman.dvzgrup.com www.16eylul.sylvanlearningturkey.com 16eylul.sylvanlearningturkey.com www.anadoluklinigi.ch anadoluklinigi.ch www.fcmtarim.com.tr www.pirincdunyasi.com www.antepshopping.com www.waterlife.ch waterlife.ch www.sylvanlearningturkey.com cansu.dvzgrup.com servis.dvzgrup.com turizm.dvzgrup.com market.dvzgrup.com whm.dvzgrup.com tiklashop.dvzgrup.com erp.dvzgrup.com smm.dvzgrup.com trendyol.dvzgrup.com lys.dvzgrup.com ocdemo.dvzgrup.com netkasam.dvzgrup.com hurdatakip.dvzgrup.com www.sarionder.dvzgrup.com sarionder.dvzgrup.com sportivor.com www.sportivor.com www.elitexmedikal.com elitexmedikal.com farabi.omersenturk.com.tr www.farabi.omersenturk.com.tr www.demo26.dvzgrup.com demo26.dvzgrup.com www.mozarugs.dvzgrup.com mozarugs.dvzgrup.com yeni.sylvanlearningturkey.com www.yeni.sylvanlearningturkey.com sylvanlearningturkey.com www.petamobil.com rashidibrahimov.com www.takip.ayyildizgeridonusum.com www.turizm4.dvzgrup.com turizm4.dvzgrup.com site.portfiltre.com.tr www.site.portfiltre.com.tr pirincdunyasi.com www.yesilbahceanaokulu.com www.rainbowservis.com www.sismankitapci.com www.tuzlasifasehiterdogankomutasm.com www.teknetasima.com www.xn–tekinhalykama-bbcb.com www.oznehirsu.com www.sancargyd.com www.kitabimevde.com www.guzelreklam.com www.genclikkitapci.com www.ercanakar.com.tr www.danddtextile.com www.teknetasima.com.tr www.yoresun.com www.veterinertakip.com www.oyuncakistoc.com www.kormeks.com www.massiamo.com www.mahmutyesilal.com www.grupmetalmakine.com.tr www.haydiyolacik.com www.eleleyardimlasmadernegi.org.tr www.trendyol.dvzgrup.com www.bursahamamsauna.com www.cassani.com.tr www.bordamarine.com www.butterflytextile.com www.yattasima.com whm.zgsistem.com www.zgsistem.com www.weddinghousebybasarir.com www.water-life.ch www.platformmuzik.com www.mirmarsaunatasarim.com www.melvanyaslibakim.com www.mehmetbicer.net www.inanccambalkon.com www.konyaliotocekici.com www.iselbiseleri.site whm.iselbiseleri.site www.kitaparasta.com www.kitapagaci.net www.indirimbulvari.com www.hediyepotasi.com www.avcidan.com www.dutmedya.com yattasima.com rainbowservis.com www.tuzla.org tuzla.org tuzla.net www.tuzla.net benveo.com.tr www.ithsab.net ithsab.net indirimbulvari.com idakitabevi.com www.idakitabevi.com www.garageotokurtarma.com garageotokurtarma.com www.store.yesilbahceanaokulu.com store.yesilbahceanaokulu.com www.demo11.dvzgrup.com demo11.dvzgrup.com www.bo.omersenturk.com.tr www.benveo.dvzgrup.com benveo.dvzgrup.com praxis-anatolien.ch gokdumanspor.com www.gokdumanspor.com www.demo14.dvzgrup.com demo14.dvzgrup.com www.pilotcarturkey.com pilotcarturkey.com qways.ch yesilbahceanaokulu.com water-life.ch iselbiseleri.site konyaliotocekici.com www.muzikplatform.com muzikplatform.com www.tasarimspor.com tasarimspor.com platformmuzik.com teknetasima.com.tr mehmetbicer.net siparis.dvzgrup.com www.siparis.dvzgrup.com teknetasima.com b2b.portfiltre.com.tr inanccambalkon.com www.erkekayakkabilari.com takip.ayyildizgeridonusum.com www.tiklashop.dvzgrup.com www.umman.dvzgrup.com massiamo.net www.troils.omersenturk.com.tr www.benveo.omersenturk.com.tr genclikkitapci.com servis.osidbilisim.com incatour.net bevanda.com.tr pt.meridyensoft.com www.pt.meridyensoft.com kitapagaci.net kitabimevde.com incatour.site www.b2b.portfiltre.com.tr portfiltre.com.tr www.erp.dvzgrup.com www.hurdatakip.dvzgrup.com www.lys.dvzgrup.com www.app.petamobil.com app.petamobil.com petamobil.com www.buluttakip.com skyfiltre.com.tr dutmedya.com kitaparasta.com www.servis.osidbilisim.com www.akgil.dvzgrup.com akgil.dvzgrup.com wiolina.dvzgrup.com www.wiolina.dvzgrup.com www.hepsimaske.erkekayakkabilari.com hepsimaske.erkekayakkabilari.com www.dvzgrup.com ucuzha.com kormeks.com avcidan.com cassani.com.tr butterflytextile.com aracaksesuarlari.com baktomix.com xn–tekinhalykama-bbcb.com weddinghousebybasarir.com mahmutyesilal.com pembelacivert.com oyuncakistoc.com www.aynurtumen.meridyensoft.com aynurtumen.meridyensoft.com printerdesigner.com demo25.dvzgrup.com www.demo25.dvzgrup.com www.demo27.dvzgrup.com demo27.dvzgrup.com www.demo9.dvzgrup.com demo9.dvzgrup.com osidbilisim.com demo13.dvzgrup.com www.demo13.dvzgrup.com admerspor.meridyensoft.com www.admerspor.meridyensoft.com www.test.otolastikal.com otolastikal.com www.vet.dvzgrup.com www.turizm3.dvzgrup.com www.mos.dvzgrup.com www.smm.dvzgrup.com www.turizm.dvzgrup.com www.netkasam.dvzgrup.com www.ocdemo.dvzgrup.com www.market.dvzgrup.com www.servis.dvzgrup.com www.turizm2.dvzgrup.com eleleyardimlasmadernegi.org.tr www.demo.meridyensoft.com demo.meridyensoft.com ns2.dvzgrup.com ns1.dvzgrup.com tupperwarependik.com merkezinokta.com veterinertakip.com tuzlasifasehiterdogankomutasm.com sismankitapci.com ercanakar.com.tr melvanyaslibakim.com massiamo.com maf.com.tr grupmetalmakine.com.tr fcmtarim.com.tr www.cansu.dvzgrup.com www.kuafor.dvzgrup.com dvzgrup.com bursahamamsauna.com ns6.portbilisim.com ns1.portbilisim.com ns2.portbilisim.com ns5.portbilisim.com annededi.com antepshopping.com www.gym.ekobiticaret.com ekobiticaret.com www.sarionder.ekobiticaret.com danddtextile.com buraginbahcesi.com buluttakip.com bordamarine.com bektaslilar.com www.new.bektaslilar.com www.otomasyon.bektaslilar.com www.yeni.bektaslilar.com avrasyavize.com asirarabuluculukmerkezi.com antikaparalar.com wikrogoldstore.com wikrogold.com omersenturk.com.tr oyuncakspot.com sancargyd.com meridyensoft.com hediyepotasi.com guzelreklam.com haydiyolacik.com allegroconcept.com ns2.zgsistem.com ns1.zgsistem.com yoresun.com zgsistem.com www.hali.dvzgrup.com hali.dvzgrup.com erkekayakkabilari.com mirmarsaunatasarim.com albayrak.auction www.gugudesign.dvzgrup.com gugudesign.dvzgrup.com portbilisim.com

Open Ports Detected

22 8080 8443

CVEs Detected

CVE-2007-2768 CVE-2008-3844 CVE-2016-20012 CVE-2017-15906 CVE-2018-15473 CVE-2018-15919 CVE-2018-20685 CVE-2019-6109 CVE-2019-6110 CVE-2019-6111 CVE-2020-14145 CVE-2020-15778 CVE-2021-36368 CVE-2021-41617 CVE-2023-38408 CVE-2023-48795 CVE-2023-51384 CVE-2023-51385 CVE-2023-51767

Map

Whois Information

  • NetRange: 144.91.64.0 - 144.91.127.255
  • CIDR: 144.91.64.0/18
  • NetName: RIPE
  • NetHandle: NET-144-91-64-0-1
  • Parent: NET144 (NET-144-0-0-0-0)
  • NetType: Early Registrations, Transferred to RIPE NCC
  • OriginAS:
  • Organization: RIPE Network Coordination Centre (RIPE)
  • RegDate: 2019-06-26
  • Updated: 2019-06-26
  • Ref: https://rdap.arin.net/registry/ip/144.91.64.0
  • OrgName: RIPE Network Coordination Centre
  • OrgId: RIPE
  • Address: P.O. Box 10096
  • City: Amsterdam
  • StateProv:
  • PostalCode: 1001EB
  • Country: NL
  • RegDate:
  • Updated: 2013-07-29
  • Ref: https://rdap.arin.net/registry/entity/RIPE
  • OrgAbuseHandle: ABUSE3850-ARIN
  • OrgAbuseName: Abuse Contact
  • OrgAbusePhone: +31205354444
  • OrgAbuseEmail: [email protected]
  • OrgAbuseRef: https://rdap.arin.net/registry/entity/ABUSE3850-ARIN
  • OrgTechHandle: RNO29-ARIN
  • OrgTechName: RIPE NCC Operations
  • OrgTechPhone: +31 20 535 4444
  • OrgTechEmail: [email protected]
  • OrgTechRef: https://rdap.arin.net/registry/entity/RNO29-ARIN
  • inetnum: 144.91.96.0 - 144.91.127.255
  • netname: CONTABO
  • descr: Contabo GmbH
  • country: DE
  • org: ORG-GG22-RIPE
  • admin-c: MH7476-RIPE
  • tech-c: MH7476-RIPE
  • status: ASSIGNED PA
  • mnt-by: MNT-CONTABO
  • created: 2019-06-27T12:39:20Z
  • last-modified: 2019-06-27T12:39:20Z
  • organisation: ORG-GG22-RIPE
  • org-name: Contabo GmbH
  • country: DE
  • org-type: LIR
  • address: Aschauer Strasse 32a
  • address: 81549
  • address: Munchen
  • address: GERMANY
  • phone: +498921268372
  • fax-no: +498921665862
  • abuse-c: MH12453-RIPE
  • mnt-ref: RIPE-NCC-HM-MNT
  • mnt-ref: MNT-CONTABO
  • mnt-ref: MNT-OCIRIS
  • mnt-by: RIPE-NCC-HM-MNT
  • mnt-by: MNT-CONTABO
  • created: 2009-12-09T13:41:08Z
  • last-modified: 2021-09-14T10:49:04Z
  • person: Wilhelm Zwalina
  • address: Contabo GmbH
  • address: Aschauer Str. 32a
  • address: 81549 Muenchen
  • phone: +49 89 21268372
  • fax-no: +49 89 21665862
  • nic-hdl: MH7476-RIPE
  • mnt-by: MNT-CONTABO
  • mnt-by: MNT-GIGA-HOSTING
  • created: 2010-01-04T10:41:37Z
  • last-modified: 2020-04-24T16:09:30Z
  • route: 144.91.120.0/23
  • descr: CONTABO
  • origin: AS51167
  • mnt-by: MNT-CONTABO
  • created: 2019-06-28T06:38:05Z
  • last-modified: 2019-06-28T06:38:05Z

Links to attack logs

** dotoronto-ssh-bruteforce-ip-list-2022-06-29 ** **