144.91.83.1 Threat Intelligence and Host Information

Share on:

General

This page contains threat intelligence information for the IPv4 address 144.91.83.1 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Possibly Malicious Host 🟢 15/100

Host and Network Information

  • View other sources: Spamhaus VirusTotal

  • Country: Germany
  • Network: AS51167 contabo gmbh
  • Noticed: 1 times
  • Protocols Attacked: Anonymous Proxy
  • Passive DNS Results: tpg.rocketvan.dev jssinvestment.rocketvan.io pregnatim.com app.pregnatim.com texgorebarcode.rocketvan.dev www.lav.cat lav.cat www.em21.es em21.es www.trollaventura.com trollaventura.com rocketvan.net umbrella.rocketvan.dev docker.rocketvan.dev algodiferente.rocketvan.dev www.footankletreatments.co.uk www.pharmatalent.com pharmatalent.com api.rocketvan.dev inmitec.rocketvan.dev centremedic.rocketvan.dev centremedicadmin.rocketvan.dev arsports.rocketvan.dev digital.rocketvan.dev trollaventura.rocketvan.dev ultimate.rocketvan.dev ultimatefest.rocketvan.dev texgore.rocketvan.dev www.karaolink.com karaolink.com texgorebarcode.texgore.es www.podostec.com podostec.com www.melendezginecologia.com melendezginecologia.com www.elracodefarners.cat elracodefarners.cat www.akonen.com akonen.com l2-companies.com www.jssinvestment.app jssinvestment.app micuenta.jssinvestment.net calcigarro.cat www.calcigarro.cat footankletreatments.co.uk www.yinkaakinfenwa.com yinkaakinfenwa.com calcigarro.rocketvan.dev blanes.rocketvan.dev croquetascopy.rocketvan.dev akonen.rocketvan.dev solar.rocketvan.dev digitalfibreadmin.rocketvan.dev elracodefarners.rocketvan.dev indigi.rocketvan.dev infraflex.rocketvan.dev karaolink.rocketvan.dev mlyon.rocketvan.dev podostec.rocketvan.dev lav.rocketvan.dev virtualsports.rocketvan.dev watlingcentre.rocketvan.dev imediatool.rocketvan.dev footandankle.rocketvan.dev devapi.rocketvan.io www.teamaircare.com teamaircare.com elevenobi.rocketvan.io rocketvan.dev l2equities.com www.l2equities.com pharma.rocketvan.io c2.rocketvan.io elevenobi.com www.elevenobi.com thatsme.imediavan.com api.rocketvan.io cofaceitfirst.rocketvan.io www.pharmatalent.io pharmatalent.io montreux.rocketvan.io stripeit.rocketvan.io office.rocketvan.io www.office.rocketvan.io pharmatalent.rocketvan.io accountforms.cofaceitfirst.co.uk akame.rocketvan.io www.easyresearch.online easyresearch.online production.rocketvan.io access-tomorrow.com uploadbook.com www.uploadbook.com www.cpanel2.rocketvan.io cpanel2.rocketvan.io www.github.rocketvan.io github.rocketvan.io www.build-tomorrow.today build-tomorrow.today www.accesstomorrow.today accesstomorrow.today meat.rocketvan.io svntool.rocketvan.io apartments.airebros.com liquidbarrier.rocketvan.io forwardcreative.imediavan.com syscom.uploadbook.com illa-riudaura.com www.illa-riudaura.com www.elmolidelaplana.cat elmolidelaplana.cat trueta.rocketvan.io cpanel.rocketvan.io elevacion.airebros.com diedriki.com www.diedriki.com www.forwardcreative.tw forwardcreative.tw diedriki.imediavan.com www.diedriki.imediavan.com mfam.imediavan.com www.tishirting.com tishirting.com www.imediavan.com imediavan.com webtest.rocketvan.io www.rocketvan.io rocketvan.io www.mxt.co.uk mxt.co.uk www.jssinvestment.net jssinvestment.net michaeljacobs1.com www.michaeljacobs1.com lanandlander.uploadbook.com onetruenorth.uploadbook.com mxt.uploadbook.com capoeira-ceara.co.uk pharmatalent.airebros.com test.uploadbook.com www.sangamcentre.org.uk sangamcentre.org.uk airebros.com coface.imediavan.com test.osteopatiagracia.com rubiesteticamalgrat.com oursvn.imediavan.com www.osteopatiagracia.com osteopatiagracia.com www.davidlan.net davidlan.net www.cofaceitfirst.com cofaceitfirst.co.uk cofaceitfirst.com www.cofaceitfirst.co.uk www.dsigual.com dsigual.com agencelxp.imediavan.com www.agencelxp.imediavan.com www.coface.imediavan.com gnomo-park.com www.gnomo-park.com www.rubiesteticamalgrat.com www.development.imediavan.com development.imediavan.com lagioia.cat vmi444293.contaboserver.net www.beemuzic.ml beemuzic.ml admin.beemuzic.ml autoconfig.beemuzic.ml navohosting.net rayntyofficial.ml admin.rayntyofficial.ml autoconfig.rayntyofficial.ml www.rayntyofficial.ml admin.gaditc.com autoconfig.gaditc.com www.gaditc.com gaditc.com

Open Ports Detected

111 21 22 3306 443 53 80 8443 8880

CVEs Detected

CVE-2007-2768 CVE-2008-3844 CVE-2016-20012 CVE-2017-15906 CVE-2018-15473 CVE-2018-15919 CVE-2018-20685 CVE-2019-6109 CVE-2019-6110 CVE-2019-6111 CVE-2020-14145 CVE-2020-15778 CVE-2021-36368 CVE-2021-41617 CVE-2023-38408 CVE-2023-48795 CVE-2023-51384 CVE-2023-51385 CVE-2023-51767

Map

Whois Information

  • NetRange: 144.91.64.0 - 144.91.127.255
  • CIDR: 144.91.64.0/18
  • NetName: RIPE
  • NetHandle: NET-144-91-64-0-1
  • Parent: NET144 (NET-144-0-0-0-0)
  • NetType: Early Registrations, Transferred to RIPE NCC
  • OriginAS:
  • Organization: RIPE Network Coordination Centre (RIPE)
  • RegDate: 2019-06-26
  • Updated: 2019-06-26
  • Ref: https://rdap.arin.net/registry/ip/144.91.64.0
  • OrgName: RIPE Network Coordination Centre
  • OrgId: RIPE
  • Address: P.O. Box 10096
  • City: Amsterdam
  • StateProv:
  • PostalCode: 1001EB
  • Country: NL
  • RegDate:
  • Updated: 2013-07-29
  • Ref: https://rdap.arin.net/registry/entity/RIPE
  • OrgTechHandle: RNO29-ARIN
  • OrgTechName: RIPE NCC Operations
  • OrgTechPhone: +31 20 535 4444
  • OrgTechEmail: [email protected]
  • OrgTechRef: https://rdap.arin.net/registry/entity/RNO29-ARIN
  • OrgAbuseHandle: ABUSE3850-ARIN
  • OrgAbuseName: Abuse Contact
  • OrgAbusePhone: +31205354444
  • OrgAbuseEmail: [email protected]
  • OrgAbuseRef: https://rdap.arin.net/registry/entity/ABUSE3850-ARIN
  • inetnum: 144.91.64.0 - 144.91.95.255
  • netname: CONTABO
  • descr: Contabo GmbH
  • country: DE
  • org: ORG-GG22-RIPE
  • admin-c: MH7476-RIPE
  • tech-c: MH7476-RIPE
  • status: ASSIGNED PA
  • mnt-by: MNT-CONTABO
  • created: 2019-06-27T12:39:01Z
  • last-modified: 2019-06-27T12:39:01Z
  • organisation: ORG-GG22-RIPE
  • org-name: Contabo GmbH
  • country: DE
  • org-type: LIR
  • address: Aschauer Strasse 32a
  • address: 81549
  • address: Munchen
  • address: GERMANY
  • phone: +498921268372
  • fax-no: +498921665862
  • abuse-c: MH12453-RIPE
  • mnt-ref: RIPE-NCC-HM-MNT
  • mnt-ref: MNT-CONTABO
  • mnt-ref: MNT-OCIRIS
  • mnt-by: RIPE-NCC-HM-MNT
  • mnt-by: MNT-CONTABO
  • created: 2009-12-09T13:41:08Z
  • last-modified: 2021-09-14T10:49:04Z
  • person: Wilhelm Zwalina
  • address: Contabo GmbH
  • address: Aschauer Str. 32a
  • address: 81549 Muenchen
  • phone: +49 89 21268372
  • fax-no: +49 89 21665862
  • nic-hdl: MH7476-RIPE
  • mnt-by: MNT-CONTABO
  • mnt-by: MNT-GIGA-HOSTING
  • created: 2010-01-04T10:41:37Z
  • last-modified: 2020-04-24T16:09:30Z
  • route: 144.91.82.0/23
  • descr: CONTABO
  • origin: AS51167
  • mnt-by: MNT-CONTABO
  • created: 2019-06-28T06:35:52Z
  • last-modified: 2019-06-28T06:35:52Z

Links to attack logs

anonymous-proxy-ip-list-2024-03-06 ** anonymous-proxy-ip-list-2024-02-23 anonymous-proxy-ip-list-2024-03-08 anonymous-proxy-ip-list-2024-02-27 anonymous-proxy-ip-list-2024-02-26 bruteforce-ip-list-2020-10-12 anonymous-proxy-ip-list-2024-02-29 anonymous-proxy-ip-list-2024-03-02 ** ** anonymous-proxy-ip-list-2024-02-24 anonymous-proxy-ip-list-2024-02-25 anonymous-proxy-ip-list-2024-02-28 anonymous-proxy-ip-list-2024-03-07