154.120.227.206 Threat Intelligence and Host Information
General
This page contains threat intelligence information for the IPv4 address 154.120.227.206 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.
Potentially Malicious Host 🟡 38/100
Host and Network Information
-
Tags: address, ca execution, contacted ip, contacted urls, country, document, emotet, ip detections, malware, mon may, ms word, overview ip, parents, sat oct, service, soar, team, thu aug, thu jul, thu may, thu sep, tue jan, tue oct, type name, wed jul, wed oct
-
View other sources: Spamhaus VirusTotal
- Country: Zimbabwe
- Network: AS30844 liquid telecommunications ltd
- Noticed: 4 times
- Protocols Attacked: SSH
Malware Detected on Host
Count: 1378 044b4d07ad21f470daccbf82659184d39ea7303fb8b023c4391d7009d5ad7e18 1562ca19270f2b971fc069dcc122b221ba1d0123cc55b4f0ed724094d87cac34 92196a24c28a047e5d1fc606c7f180511962fe9f89467c1146476e069faff04f 5414bfd42e338135b507299e1c3afa671ad1bc0795dd75980b9eb516199d1e46 664effbdca294a821ff8334c37ea0fcf6d52fd3224ded9bfac69d93ec376ff18 9bb11197ac4ae886e16054212db69de498bf896de914b1b5076e04021affbaef 0ed84f4c0acb65db8362fe4c9d29342c52985783840419c73e5667a7a24773d9 0e10849e45e4c54829263969a0c86529b073429d5802c71a8ab40defac2b2857 c80becbb273db0bfbc8562a6a0ab09d2b9f42a7fc4e2a317728f6ea9399dbca4 3ae7ba675ab0801471ce801ad3a011767945c5be96ec32554831bce61c023a2c
Map
Whois Information
- inetnum: 154.120.224.0 - 154.120.255.255
- netname: LIQUID-ZW-OPS
- descr: Liquid Zimbabwe
- country: ZW
- admin-c: AA110-AFRINIC
- tech-c: AA110-AFRINIC
- status: ASSIGNED PA
- mnt-by: LIQUID-TOL-MNT
- parent: 154.120.192.0 - 154.120.255.255
- person: Andrew Alston
- address: Block A, Sameer Business Park,
- address: Mombasa Road,
- address: Nairobi
- address: Kenya
- phone: tel:+254-20-5000000
- nic-hdl: AA110-AFRINIC
- mnt-by: AA110-MNTR
- route: 154.120.227.0/24
- descr: Maintainer Liquid Telecommunications Operations Limited
- origin: AS30844
- org: ORG-LTOL1-AFRINIC
- mnt-lower: LIQUID-TOL-MNT
- mnt-by: AFRINIC-HM-MNT
- organisation: ORG-LTOL1-AFRINIC
- org-name: Liquid Telecommunications Operations Limited
- org-type: LIR
- country: MU
- address: 10th Floor,
- address: Raffles Tower,
- address: 19 Cybercity
- address: Ebene
- phone: tel:+254-733-222204
- phone: tel:+230-466-7620
- phone: tel:+263-8677-033306
- phone: tel:+254-731-033754
- admin-c: RD10-AFRINIC
- admin-c: DH19-AFRINIC
- admin-c: CM53-AFRINIC
- admin-c: AS116-AFRINIC
- tech-c: DV5-AFRINIC
- tech-c: DH19-AFRINIC
- tech-c: CM53-AFRINIC
- tech-c: MC69-AFRINIC
- tech-c: AA110-AFRINIC
- tech-c: AS116-AFRINIC
- mnt-ref: AFRINIC-HM-MNT
- mnt-ref: LIQUID-TOL-MNT
- mnt-by: AFRINIC-HM-MNT
Links to attack logs
****** emotet-iocs ****** ******
Share on: