159.253.120.245 Threat Intelligence and Host Information

Share on:

General

This page contains threat intelligence information for the IPv4 address 159.253.120.245 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Possibly Malicious Host 🟢 10/100

Host and Network Information

  • View other sources: Spamhaus VirusTotal

  • Country:
  • Network:
  • Noticed: times
  • Protocols Attacked: telnet
  • Passive DNS Results: www.frieowns.cam frieowns.cam frosty-pare.159-253-120-245.plesk.page

Malware Detected on Host

Count: 10 3bc4115ef0681c31c50f047c5134355191a80a15496731bff98da751d445dfec a2bae529bee6a22eb9d1ffe00003b01150cefe902794d85974f22291e0f93bac 9f36cd7e914a0192527406e2e81285ea06b69da74f5e26a7817b6ceb4e17ba38 d742fbd22c5b2f18796ac279acc51b96021a7ec37709cce8e8b8f570ad8a149d c8ff240fd6dcaf931d8339dad65b1a715e82d4560df84e2740b9199b64b7addc dc77e955c5010a29c0d0f1696ebe52cb626579d321651aaf1c5ed2cd9c15bca9 c72ef8eed4338fbd620b8156aa3a0b10a64d547bc29db31f4943f981d377471f bf8de2c3ca53a596dccb2868089d408493a5db57f6d7bd96d6de480ce9b8edc6 4302af9bd3f5e23accc14c798f7dd30e19b0657bcb28e45358510485c2f38502 9d136820a9ceb39b2f185ae604b4fcb38c1b957f30a4671794345abeac4d74ed

Map

Whois Information

  • NetRange: 159.253.0.0 - 159.253.255.255
  • CIDR: 159.253.0.0/16
  • NetName: RIPE-ERX-159-253-0-0
  • NetHandle: NET-159-253-0-0-1
  • Parent: NET159 (NET-159-0-0-0-0)
  • NetType: Early Registrations, Transferred to RIPE NCC
  • OriginAS:
  • Organization: RIPE Network Coordination Centre (RIPE)
  • RegDate: 2010-11-03
  • Updated: 2010-11-17
  • Comment: These addresses have been further assigned to users in
  • Comment: the RIPE NCC region. Contact information can be found in
  • Ref: https://rdap.arin.net/registry/ip/159.253.0.0
  • OrgName: RIPE Network Coordination Centre
  • OrgId: RIPE
  • Address: P.O. Box 10096
  • City: Amsterdam
  • StateProv:
  • PostalCode: 1001EB
  • Country: NL
  • RegDate:
  • Updated: 2013-07-29
  • Ref: https://rdap.arin.net/registry/entity/RIPE
  • OrgAbuseHandle: ABUSE3850-ARIN
  • OrgAbuseName: Abuse Contact
  • OrgAbusePhone: +31205354444
  • OrgAbuseEmail: [email protected]
  • OrgAbuseRef: https://rdap.arin.net/registry/entity/ABUSE3850-ARIN
  • OrgTechHandle: RNO29-ARIN
  • OrgTechName: RIPE NCC Operations
  • OrgTechPhone: +31 20 535 4444
  • OrgTechEmail: [email protected]
  • OrgTechRef: https://rdap.arin.net/registry/entity/RNO29-ARIN
  • inetnum: 159.253.120.128 - 159.253.120.255
  • org: ORG-AS895-RIPE
  • netname: AlexHost
  • country: MD
  • admin-c: SZ3268-RIPE
  • tech-c: SZ3268-RIPE
  • status: ASSIGNED PA
  • mnt-by: IPSMAIN
  • created: 2022-09-20T13:12:04Z
  • last-modified: 2022-09-20T13:12:04Z
  • mnt-domains: IPSMAIN
  • mnt-domains: CLOUDATAMD-MNT
  • mnt-lower: CLOUDATAMD-MNT
  • mnt-routes: CLOUDATAMD-MNT
  • mnt-routes: IPSMAIN
  • organisation: ORG-AS895-RIPE
  • org-name: ALEXHOST SRL
  • org-type: OTHER
  • address: str. C. Brancusi nr. 3, Chisinau, Moldova
  • abuse-c: AR18916-RIPE
  • mnt-ref: MNT-GLBTX
  • mnt-ref: FREENET-MNT
  • mnt-ref: IPSMAIN
  • mnt-by: IPSMAIN
  • created: 2021-02-08T19:58:24Z
  • last-modified: 2022-03-09T16:27:19Z
  • person: AlexHost SRL
  • address: str. Constantin Brancusi nr. 3, Chisinau, Moldova
  • phone: +37379600002
  • nic-hdl: SZ3268-RIPE
  • mnt-by: CLOUDATAMD-MNT
  • created: 2014-03-21T14:17:01Z
  • last-modified: 2023-03-03T08:12:53Z
  • route: 159.253.120.0/24
  • origin: AS200019
  • mnt-by: VPLAB-MNT
  • created: 2022-09-17T11:24:32Z
  • last-modified: 2022-09-17T11:24:32Z

Links to attack logs

dolondon-telnet-bruteforce-ip-list-2022-10-07 ** ** **