156.225.72.76 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 156.225.72.76 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Possibly Malicious Host 🟢 5/100

Host and Network Information

  • Country: United States
  • Network:
  • Noticed: 1 times
  • Protocols Attacked: Anonymous Proxy
  • Passive DNS Results: dqd84yf8.icu r4e1fy55.icu y2r2nxzk.icu j58hx19m.icu ynsq66bv.icu 2le6iypt.icu cslbefmp.icu cyjn3tvf.icu 1jlagmjk.icu sa3hc04i.icu au0b14uk.icu 6p4bbn3q.icu 0u0nu5oc.icu ppi4xurd.icu o9ghbj4t.icu a0aey7pa.icu x3uq8iey.icu qbdj6fxz.icu mjlombcl.icu k4wflyui.icu gi3gcblf.icu 70tm2fa4.icu o1inqv2a.icu mwewig0b.icu jsy6or6u.icu f5woea3h.icu ff7r22hp.icu wfb3asyu.icu 4i99xzqt.icu 3ensienn.icu rjzn5rl9.icu 0oenznbt.icu 52e6j2f4.icu www.ucdpkzxq.icu ucdpkzxq.icu lhc37719.vip bxj00260.vip

Malware Detected on Host

Count: 1 39a716ecb8b2ef862109404a20c1bf2da16b4434f20a92760f2c63244114da70

Open Ports Detected

2082 2086 2087 2096 443 80 8080 8443 8880

Map

Whois Information

  • NetRange: 156.225.0.0 - 156.225.255.255
  • CIDR: 156.225.0.0/16
  • NetName: AFRINIC-ERX-156-225-0-0
  • NetHandle: NET-156-225-0-0-1
  • Parent: NET156 (NET-156-0-0-0-0)
  • NetType: Transferred to AfriNIC
  • OriginAS:
  • Organization: African Network Information Center (AFRINIC)
  • RegDate: 2010-11-03
  • Updated: 2010-11-17
  • Comment: This IP address range is under AFRINIC responsibility.
  • Comment: Please see http://www.afrinic.net/ for further details,
  • Ref: https://rdap.arin.net/registry/ip/156.225.0.0
  • OrgName: African Network Information Center
  • OrgId: AFRINIC
  • Address: Level 11ABC
  • Address: Raffles Tower
  • Address: Lot 19, Cybercity
  • City: Ebene
  • StateProv:
  • PostalCode:
  • Country: MU
  • RegDate: 2004-05-17
  • Updated: 2015-05-04
  • Comment: AfriNIC - http://www.afrinic.net
  • Comment: The African & Indian Ocean Internet Registry
  • Ref: https://rdap.arin.net/registry/entity/AFRINIC
  • OrgAbuseHandle: GENER11-ARIN
  • OrgAbuseName: Generic POC
  • OrgAbusePhone: +230 4666616
  • OrgAbuseEmail: abusepoc@afrinic.net
  • OrgAbuseRef: https://rdap.arin.net/registry/entity/GENER11-ARIN
  • OrgTechHandle: GENER11-ARIN
  • OrgTechName: Generic POC
  • OrgTechPhone: +230 4666616
  • OrgTechEmail: abusepoc@afrinic.net
  • OrgTechRef: https://rdap.arin.net/registry/entity/GENER11-ARIN
  • inetnum: 156.225.72.0 - 156.225.72.255
  • netname: GS_TECHNOLOGIES_LIMITED
  • descr: GS TECHNOLOGIES LIMITED
  • country: US
  • admin-c: CIS1-AFRINIC
  • tech-c: CIS1-AFRINIC
  • status: ASSIGNED PA
  • mnt-by: CIL1-MNT
  • mnt-by: LARUS-SERVICE-MNT
  • parent: 156.224.0.0 - 156.255.255.255
  • person: Cloud Innovation Support
  • address: Ebene
  • address: MU
  • address: Mahe
  • address: Seychelles
  • phone: tel:+248-4-610-795
  • nic-hdl: CIS1-AFRINIC
  • abuse-mailbox: abuse@cloudinnovation.org
  • mnt-by: CIL1-MNT
  • route: 156.225.72.0/24
  • descr: GS TECHNOLOGIES LIMITED
  • origin: AS209242
  • mnt-by: LARUS-SERVICE-MNT

Links to attack logs

anonymous-proxy-ip-list-2025-06-23 anonymous-proxy-ip-list-2025-06-22 anonymous-proxy-ip-list-2025-06-24

Share on: