15.152.47.137 Threat Intelligence and Host Information
General
This page contains threat intelligence information for the IPv4 address 15.152.47.137 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.
Potentially Malicious Host 🟡 45/100
Host and Network Information
-
Tags: bruteforce, cyber security, digital ocean, ioc, malicious, Nextray, phishing, telnet
-
View other sources: Spamhaus VirusTotal
- Country: Japan
- Network:
- Noticed: 30 times
- Protocols Attacked: telnet
- Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Singapore, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
Open Ports Detected
10081 10243 104 10533 10934 11434 12136 12304 1235 12373 12487 12980 1311 14084 1443 1456 16025 18021 18093 189 1900 195 1972 20010 2054 20547 2081 2082 21252 21379 22556 23023 2379 25105 3001 3057 3093 3101 311 32102 3408 3410 36983 37215 4002 4190 4282 4300 44345 45788 4664 49210 5000 50002 51235 5246 5247 5269 5672 5900 5901 6061 6080 6405 6512 666 7001 79 8019 8035 8080 8111 8148 8200 8300 832 8382 8728 8989 9104 9151 9194 9202 9295 9939 9981
CVEs Detected
CVE-1999-1053 CVE-2000-0505 CVE-2000-1204 CVE-2000-1205 CVE-2000-1206 CVE-2001-1449 CVE-2001-1556 CVE-2002-0061 CVE-2002-0392 CVE-2002-0839 CVE-2002-0840 CVE-2002-0843 CVE-2002-1658 CVE-2002-2103 CVE-2003-0020 CVE-2003-0083 CVE-2003-0460 CVE-2003-0542 CVE-2003-0987 CVE-2003-0993 CVE-2004-0174 CVE-2004-0263 CVE-2004-0940 CVE-2004-0942 CVE-2004-1082 CVE-2004-2343 CVE-2005-3352 CVE-2006-20001 CVE-2006-3918 CVE-2006-5752 CVE-2007-3304 CVE-2007-4723 CVE-2007-5000 CVE-2007-6388 CVE-2007-6750 CVE-2008-2939 CVE-2009-0796 CVE-2009-2299 CVE-2009-2940 CVE-2009-3555 CVE-2009-3720 CVE-2010-0010 CVE-2011-1176 CVE-2011-2688 CVE-2011-3368 CVE-2011-4317 CVE-2012-3526 CVE-2012-4001 CVE-2012-4360 CVE-2012-6708 CVE-2013-0941 CVE-2013-0942 CVE-2013-2765 CVE-2013-4365 CVE-2013-5697 CVE-2015-0228 CVE-2015-9251 CVE-2016-8612 CVE-2017-9788 CVE-2017-9798 CVE-2018-1301 CVE-2018-1302 CVE-2018-1303 CVE-2019-10768 CVE-2019-11358 CVE-2020-11022 CVE-2020-11023 CVE-2020-29396 CVE-2020-7656 CVE-2020-7676 CVE-2021-32052 CVE-2021-34798 CVE-2021-39275 CVE-2021-40438 CVE-2021-44790 CVE-2022-22719 CVE-2022-22720 CVE-2022-22721 CVE-2022-28330 CVE-2022-28614 CVE-2022-28615 CVE-2022-29404 CVE-2022-30556 CVE-2022-31813 CVE-2022-37436 CVE-2023-31122 CVE-2023-36632 CVE-2023-38709 CVE-2024-21490 CVE-2024-40898 CVE-2024-8372 CVE-2024-8373 CVE-2025-49812
Map
Whois Information
- NetRange: 15.152.0.0 - 15.158.255.255
- CIDR: 15.158.0.0/16, 15.156.0.0/15, 15.152.0.0/14
- NetName: AT-88-Z
- NetHandle: NET-15-152-0-0-1
- Parent: NET15 (NET-15-0-0-0-0)
- NetType: Direct Allocation
- OriginAS:
- Organization: Amazon Technologies Inc. (AT-88-Z)
- RegDate: 2020-03-25
- Updated: 2021-02-10
- Ref: https://rdap.arin.net/registry/ip/15.152.0.0
- OrgName: Amazon Technologies Inc.
- OrgId: AT-88-Z
- Address: 410 Terry Ave N.
- City: Seattle
- StateProv: WA
- PostalCode: 98109
- Country: US
- RegDate: 2011-12-08
- Updated: 2024-01-24
- Comment: All abuse reports MUST include:
- Comment: * src IP
- Comment: * dest IP (your IP)
- Comment: * dest port
- Comment: * Accurate date/timestamp and timezone of activity
- Comment: * Intensity/frequency (short log extracts)
- Comment: * Your contact details (phone and email) Without these we will be unable to identify the correct owner of the IP address at that point in time.
- Ref: https://rdap.arin.net/registry/entity/AT-88-Z
- OrgNOCHandle: AANO1-ARIN
- OrgNOCName: Amazon AWS Network Operations
- OrgNOCPhone: +1-206-555-0000
- OrgNOCEmail: amzn-noc-contact@amazon.com
- OrgNOCRef: https://rdap.arin.net/registry/entity/AANO1-ARIN
- OrgRoutingHandle: ARMP-ARIN
- OrgRoutingName: AWS RPKI Management POC
- OrgRoutingPhone: +1-206-555-0000
- OrgRoutingEmail: aws-rpki-routing-poc@amazon.com
- OrgRoutingRef: https://rdap.arin.net/registry/entity/ARMP-ARIN
- OrgRoutingHandle: IPROU3-ARIN
- OrgRoutingName: IP Routing
- OrgRoutingPhone: +1-206-555-0000
- OrgRoutingEmail: aws-routing-poc@amazon.com
- OrgRoutingRef: https://rdap.arin.net/registry/entity/IPROU3-ARIN
- OrgTechHandle: ANO24-ARIN
- OrgTechName: Amazon EC2 Network Operations
- OrgTechPhone: +1-206-555-0000
- OrgTechEmail: amzn-noc-contact@amazon.com
- OrgTechRef: https://rdap.arin.net/registry/entity/ANO24-ARIN
- OrgAbuseHandle: AEA8-ARIN
- OrgAbuseName: Amazon EC2 Abuse
- OrgAbusePhone: +1-206-555-0000
- OrgAbuseEmail: trustandsafety@support.aws.com
- OrgAbuseRef: https://rdap.arin.net/registry/entity/AEA8-ARIN
- NetRange: 15.152.0.0 - 15.152.255.255
- CIDR: 15.152.0.0/16
- NetName: AMAZON-KIX
- NetHandle: NET-15-152-0-0-2
- Parent: AT-88-Z (NET-15-152-0-0-1)
- NetType: Reallocated
- OriginAS:
- Organization: Amazon Data Services Osaka (AT-9052)
- RegDate: 2020-07-24
- Updated: 2020-07-24
- Ref: https://rdap.arin.net/registry/ip/15.152.0.0
- OrgName: Amazon Data Services Osaka
- OrgId: AT-9052
- Address: Nakanoshima Mitsui Bldg.
- Address: 3-3-3 Nakanoshima, Kita-ku
- City: Osaka
- StateProv:
- PostalCode: 530-0005
- Country: JP
- RegDate: 2020-04-16
- Updated: 2020-04-16
- Ref: https://rdap.arin.net/registry/entity/AT-9052
- OrgAbuseHandle: AEA8-ARIN
- OrgAbuseName: Amazon EC2 Abuse
- OrgAbusePhone: +1-206-555-0000
- OrgAbuseEmail: trustandsafety@support.aws.com
- OrgAbuseRef: https://rdap.arin.net/registry/entity/AEA8-ARIN
- OrgTechHandle: ANO24-ARIN
- OrgTechName: Amazon EC2 Network Operations
- OrgTechPhone: +1-206-555-0000
- OrgTechEmail: amzn-noc-contact@amazon.com
- OrgTechRef: https://rdap.arin.net/registry/entity/ANO24-ARIN
Links to attack logs
****** ****** ****** dosing-telnet-bruteforce-ip-list-2022-09-05
Share on: