157.52.211.125 Threat Intelligence and Host Information
General
This page contains threat intelligence information for the IPv4 address 157.52.211.125 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.
Likely Malicious Host 🟠 55/100
Host and Network Information
-
Mitre ATT&CK IDs: T1078 - Valid Accounts, T1083 - File and Directory Discovery, T1098.004 - SSH Authorized Keys, T1105 - Ingress Tool Transfer, T1110.004 - Credential Stuffing, T1110 - Brute Force
-
Tags: cowrie, cyber security, ioc, malicious, Nextray, phishing, ssh
-
View other sources: Spamhaus VirusTotal
-
Contained within other IP sets: haley_ssh
- Country: United States
- Network: AS46573 layerhost
- Noticed: 33 times
- Protocols Attacked: ssh
- Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
- Passive DNS Results: 157.52.211.125 aslpls.buangons.site www.dgte.buangons.site dgte.buangons.site codestream.tk industrialis.tk fragrans.tk
Malware Detected on Host
Count: 1 d9defe09cbf197bd5ec65c5d4d7cfa62c64c433ded8d324235d0b9eea71df887
Whois Information
- NetRange: 157.52.128.0 - 157.52.255.255
- CIDR: 157.52.128.0/17
- NetName: AMAZO-4
- NetHandle: NET-157-52-128-0-1
- Parent: NET157 (NET-157-0-0-0-0)
- NetType: Direct Allocation
- OriginAS:
- Organization: Amazon.com, Inc. (AMAZO-4)
- RegDate: 2024-08-14
- Updated: 2024-08-14
- Ref: https://rdap.arin.net/registry/ip/157.52.128.0
- OrgName: Amazon.com, Inc.
- OrgId: AMAZO-4
- Address: Amazon Web Services, Inc.
- Address: P.O. Box 81226
- City: Seattle
- StateProv: WA
- PostalCode: 98108-1226
- Country: US
- RegDate: 2005-09-29
- Updated: 2022-09-30
- Comment: For details of this service please see
- Comment: http://ec2.amazonaws.com
- Ref: https://rdap.arin.net/registry/entity/AMAZO-4
- OrgRoutingHandle: ARMP-ARIN
- OrgRoutingName: AWS RPKI Management POC
- OrgRoutingPhone: +1-206-555-0000
- OrgRoutingEmail: aws-rpki-routing-poc@amazon.com
- OrgRoutingRef: https://rdap.arin.net/registry/entity/ARMP-ARIN
- OrgTechHandle: ANO24-ARIN
- OrgTechName: Amazon EC2 Network Operations
- OrgTechPhone: +1-206-555-0000
- OrgTechEmail: amzn-noc-contact@amazon.com
- OrgTechRef: https://rdap.arin.net/registry/entity/ANO24-ARIN
- OrgAbuseHandle: AEA8-ARIN
- OrgAbuseName: Amazon EC2 Abuse
- OrgAbusePhone: +1-206-555-0000
- OrgAbuseEmail: trustandsafety@support.aws.com
- OrgAbuseRef: https://rdap.arin.net/registry/entity/AEA8-ARIN
- OrgNOCHandle: AANO1-ARIN
- OrgNOCName: Amazon AWS Network Operations
- OrgNOCPhone: +1-206-555-0000
- OrgNOCEmail: amzn-noc-contact@amazon.com
- OrgNOCRef: https://rdap.arin.net/registry/entity/AANO1-ARIN
- OrgRoutingHandle: IPROU3-ARIN
- OrgRoutingName: IP Routing
- OrgRoutingPhone: +1-206-555-0000
- OrgRoutingEmail: aws-routing-poc@amazon.com
- OrgRoutingRef: https://rdap.arin.net/registry/entity/IPROU3-ARIN
- NetRange: 157.52.211.0 - 157.52.211.255
- CIDR: 157.52.211.0/24
- NetName: ROOT-LEVEL-TECHNOLOGY-INC
- NetHandle: NET-157-52-211-0-1
- Parent: AMAZO-4 (NET-157-52-128-0-1)
- NetType: Reassigned
- OriginAS: AS32421
- Customer: Root Level Technology Inc (C05723715)
- RegDate: 2015-05-13
- Updated: 2015-05-13
- Ref: https://rdap.arin.net/registry/ip/157.52.211.0
- CustName: Root Level Technology Inc
- Address: 17230 Huffmeister Rd
- City: Cypress
- StateProv: TX
- PostalCode: 77429
- Country: US
- RegDate: 2015-05-13
- Updated: 2015-05-13
- Ref: https://rdap.arin.net/registry/entity/C05723715
- OrgRoutingHandle: ARMP-ARIN
- OrgRoutingName: AWS RPKI Management POC
- OrgRoutingPhone: +1-206-555-0000
- OrgRoutingEmail: aws-rpki-routing-poc@amazon.com
- OrgRoutingRef: https://rdap.arin.net/registry/entity/ARMP-ARIN
- OrgTechHandle: ANO24-ARIN
- OrgTechName: Amazon EC2 Network Operations
- OrgTechPhone: +1-206-555-0000
- OrgTechEmail: amzn-noc-contact@amazon.com
- OrgTechRef: https://rdap.arin.net/registry/entity/ANO24-ARIN
- OrgAbuseHandle: AEA8-ARIN
- OrgAbuseName: Amazon EC2 Abuse
- OrgAbusePhone: +1-206-555-0000
- OrgAbuseEmail: trustandsafety@support.aws.com
- OrgAbuseRef: https://rdap.arin.net/registry/entity/AEA8-ARIN
- OrgNOCHandle: AANO1-ARIN
- OrgNOCName: Amazon AWS Network Operations
- OrgNOCPhone: +1-206-555-0000
- OrgNOCEmail: amzn-noc-contact@amazon.com
- OrgNOCRef: https://rdap.arin.net/registry/entity/AANO1-ARIN
- OrgRoutingHandle: IPROU3-ARIN
- OrgRoutingName: IP Routing
- OrgRoutingPhone: +1-206-555-0000
- OrgRoutingEmail: aws-routing-poc@amazon.com
- OrgRoutingRef: https://rdap.arin.net/registry/entity/IPROU3-ARIN
Links to attack logs
****** ****** aws-ssh-bruteforce-ip-list-2021-02-04 ****** ******
Share on: