148.72.176.16 Threat Intelligence and Host Information

Share on:

General

This page was generated as a result of this host being detected actively attacking or scanning another host. See below for information related to the host network, location, number of days noticed, protocols attacked and other information including reverse DNS and whois.

Host and Network Information

  • Tags: Malicious IP, Nextray, Port scan, blacklist, botnet, bruteforce, cyber security, digital ocean, ioc, malicious, mirai, mssql, phishing, scan, smb, tcp, vultr
  • View other sources: Spamhaus VirusTotal

  • Country: United States of America
  • Network: AS30083 godaddy.com llc
  • Noticed: 13 times
  • Protcols Attacked: mssql
  • Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Singapore, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
  • Passive DNS Results: eonproduccion.net moosespartan.com www.surprisesubscriptions.com ftp.surprisesubscriptions.com surprisesubscriptions.com cwp.surprisesubscriptions.com fortnesca.co.uk

Open Ports Detected

1433 443 5985 80 9001

CVEs Detected

CVE-2006-20001 CVE-2022-1292 CVE-2022-2068 CVE-2022-2097 CVE-2022-26377 CVE-2022-28330 CVE-2022-28614 CVE-2022-28615 CVE-2022-29404 CVE-2022-30522 CVE-2022-30556 CVE-2022-31813 CVE-2022-36760 CVE-2022-37436 CVE-2022-4304 CVE-2022-4450 CVE-2023-0215 CVE-2023-0286

Map

Whois Information

  • NetRange: 148.72.0.0 - 148.72.255.255
  • CIDR: 148.72.0.0/16
  • NetName: GO-DADDY-COM-LLC
  • NetHandle: NET-148-72-0-0-1
  • Parent: NET148 (NET-148-0-0-0-0)
  • NetType: Direct Allocation
  • OriginAS:
  • Organization: GoDaddy.com, LLC (GODAD)
  • RegDate: 2015-10-26
  • Updated: 2015-10-26
  • Ref: https://rdap.arin.net/registry/ip/148.72.0.0
  • OrgName: GoDaddy.com, LLC
  • OrgId: GODAD
  • Address: 2155 E GoDaddy Way
  • City: Tempe
  • StateProv: AZ
  • PostalCode: 85284
  • Country: US
  • RegDate: 2007-06-01
  • Updated: 2022-08-02
  • Comment: Please send abuse complaints to [email protected]
  • Ref: https://rdap.arin.net/registry/entity/GODAD
  • OrgNOCHandle: NOC124-ARIN
  • OrgNOCName: Network Operations Center
  • OrgNOCPhone: +1-480-505-8809
  • OrgNOCEmail: [email protected]
  • OrgNOCRef: https://rdap.arin.net/registry/entity/NOC124-ARIN
  • OrgTechHandle: NOC124-ARIN
  • OrgTechName: Network Operations Center
  • OrgTechPhone: +1-480-505-8809
  • OrgTechEmail: [email protected]
  • OrgTechRef: https://rdap.arin.net/registry/entity/NOC124-ARIN
  • OrgAbuseHandle: ABUSE51-ARIN
  • OrgAbuseName: Abuse Department
  • OrgAbusePhone: +1-480-624-2505
  • OrgAbuseEmail: [email protected]
  • OrgAbuseRef: https://rdap.arin.net/registry/entity/ABUSE51-ARIN
  • NetRange: 148.72.176.0 - 148.72.191.255
  • CIDR: 148.72.176.0/20
  • NetName: NET-148-72-176-0-1
  • NetHandle: NET-148-72-176-0-1
  • Parent: GO-DADDY-COM-LLC (NET-148-72-0-0-1)
  • NetType: Reallocated
  • OriginAS: AS30083
  • Organization: HEG US Inc. (SERVE-6)
  • RegDate: 2018-10-11
  • Updated: 2018-10-11
  • Comment: Tech POC - GEN13-ARIN
  • Comment: Abuse POC - HUAD-ARIN
  • Ref: https://rdap.arin.net/registry/ip/148.72.176.0
  • OrgName: HEG US Inc.
  • OrgId: SERVE-6
  • Address: 210 North Tucker Blvd.
  • Address: Suite 910
  • City: Saint Louis
  • StateProv: MO
  • PostalCode: 63101
  • Country: US
  • RegDate: 2003-04-15
  • Updated: 2019-08-27
  • Ref: https://rdap.arin.net/registry/entity/SERVE-6
  • OrgTechHandle: GEN13-ARIN
  • OrgTechName: GoDaddy EMEA NOC
  • OrgTechPhone: +49220399340
  • OrgTechEmail: [email protected]
  • OrgTechRef: https://rdap.arin.net/registry/entity/GEN13-ARIN
  • OrgNOCHandle: GEN13-ARIN
  • OrgNOCName: GoDaddy EMEA NOC
  • OrgNOCPhone: +49220399340
  • OrgNOCEmail: [email protected]
  • OrgNOCRef: https://rdap.arin.net/registry/entity/GEN13-ARIN
  • OrgAbuseHandle: HUAD-ARIN
  • OrgAbuseName: HEG US Abuse Department
  • OrgAbusePhone: +1-314-266-3638
  • OrgAbuseEmail: [email protected]
  • OrgAbuseRef: https://rdap.arin.net/registry/entity/HUAD-ARIN

Links to attack logs

vultrparis-mssql-bruteforce-ip-list-2022-07-21 dosing-mssql-bruteforce-ip-list-2022-08-16