148.72.247.138 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 148.72.247.138 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Likely Malicious Host 🟠 65/100

Host and Network Information

  • Mitre ATT&CK IDs: T1078 - Valid Accounts, T1083 - File and Directory Discovery, T1098.004 - SSH Authorized Keys, T1105 - Ingress Tool Transfer, T1110.004 - Credential Stuffing, T1110 - Brute Force

  • Tags: attack, Bruteforce, Brute-Force, cowrie, cyber security, ioc, kfsensor, login, malicious, Nextray, phishing, rdp, scanner, ssh, SSH, Telnet

  • JARM: 15d3fd16d29d29d00042d43d000000eed8083ffe0365e3dd86aa60eff5d3bb

  • View other sources: Spamhaus VirusTotal

  • Country: Singapore
  • Network:
  • Noticed: 50 times
  • Protocols Attacked: ssh
  • Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
  • Passive DNS Results: wowmagzine.com www.wowmagzine.com www.lotcommercialslot.com www.cubancigaradvocate.com www.lockedkeysincar.net www.bigfrenzycasino.com www.patenthealthcare.com jejakblog.net vicsc535.com waytohome.net lockedkeysincar.net albertacorn.com the420plugmaker.com deventercasino.com shoeaholicandmore.com globalbonercasino.com adultcherrycasino.com echiquier-poitevin.com lonniesmalley.net wkrev.com conbonuscasino.com www.conbonuscasino.com webbaohe.com lepassagehotelcasino.com livestakecasino.com lezhinx.net lotcommercialslot.com zhanmail.com engineercc.com casinosmetaverso.com bigfrenzycasino.com www.genxelectricscooters.com www.saitohifuka.com 138.247.72.148.host.secureserver.net patenthealthcare.com genxelectricscooters.com mailmarketer.net astralnetart.com texas-sportsman.com cocinasjesusmartin.com vi-jyot.com sta-overlamination.com luxurymiaminews.com bitiplexai.com bluegrassloudoun.com gayskip.com javascriptmenubuilder.com onthelakesports.com uditajain.com 20interactive.com hotellestilleuls-hasparren.com mashosting.net adamtechnologiespk.com techprostip.com designbydeleon.com busypic.com esbtv.com abatradertrains.com clicfactor.com charsokala.com visitorsproof.com hashtaggedmarketing.com meeting-shop.com botyouridea.com uwiscmr.com neweset.com shabakegostaran.net cubancigaradvocate.com saitohifuka.com latinobear.com zhenjiangdc.com yosee.net netneo.net trans-region.com cool5678.com snmm25.com shtatka.com 3pv1.com wsh178.com trt77.com tubthump.com cp8907.com bawanglong001.com 01yabo.com 169zone.com fjbangmai.com europacker.info adroittinfo.com swoocom.com hydraruxzphew4af.com josecliment.com centreforkala.com nammatraining.com affectionate-davinci.148-72-247-138.plesk.page ltconkj.com h5.ltconkj.com

Open Ports Detected

110 111 143 2082 2083 2086 2087 22 3306 443 465 53 587 80 993 995

CVEs Detected

CVE-2007-2768 CVE-2008-3844 CVE-2016-20012 CVE-2019-16905 CVE-2020-14145 CVE-2020-15778 CVE-2021-36368 CVE-2021-41617 CVE-2023-38408 CVE-2023-48795 CVE-2023-51385 CVE-2023-51767 CVE-2025-26465 CVE-2025-32728

Map

Whois Information

Links to attack logs

dolondon-ssh-bruteforce-ip-list-2022-11-01 ****** dosing-ssh-bruteforce-ip-list-2022-12-19 bruteforce-ip-list-2023-01-21 vultrwarsaw-ssh-bruteforce-ip-list-2022-11-03 vultrmadrid-ssh-bruteforce-ip-list-2022-12-29 vultrwarsaw-ssh-bruteforce-ip-list-2023-01-19 dolondon-ssh-bruteforce-ip-list-2023-01-01 dotoronto-ssh-bruteforce-ip-list-2023-01-20 dofrank-ssh-bruteforce-ip-list-2023-01-23 dofrank-ssh-bruteforce-ip-list-2022-12-27 vultrparis-ssh-bruteforce-ip-list-2022-12-29 vultrwarsaw-ssh-bruteforce-ip-list-2022-12-17 dotoronto-ssh-bruteforce-ip-list-2022-12-27 ****** dolondon-ssh-bruteforce-ip-list-2023-01-30 ****** bruteforce-ip-list-2022-12-26 vultrmadrid-ssh-bruteforce-ip-list-2023-01-17 bruteforce-ip-list-2022-11-02

Share on: