159.89.194.175 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 159.89.194.175 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Potentially Malicious Host 🟡 35/100

Host and Network Information

  • Tags: Nextray, cyber security, dionaea, ioc, last update, malicious, phishing, smb, unique count, windows server

  • JARM: 2ad2ad0002ad2ad22c2ad2ad2ad2adc2ddcfd203d071c45b4b0ffe3d7b4b89

  • View other sources: Spamhaus VirusTotal

  • Country: Singapore
  • Network: AS14061 digitalocean llc
  • Noticed: 1 times
  • Protcols Attacked: git
  • Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
  • Passive DNS Results: xosocity.com blueleafsupport.com.au

Open Ports Detected

10134 1023 1024 10243 1026 104 10443 11 11000 11112 11371 1177 12345 13 1311 13579 14147 14344 1471 1494 15 16010 1650 16992 16993 17 1741 1800 1801 18081 1830 19000 1901 19071 1925 1926 1935 20 2000 2003 2008 2020 2021 20547 2055 2058 2060 2067 2080 2082 2086 2087 2096 21025 2111 2126 22 2202 221 2221 23 2376 2379 2404 25105 2555 25565 2572 2701 27015 2761 28015 2806 3000 30002 3001 3050 3051 3053 3059 3061 3063 3075 3097 3099 3104 3105 3106 311 3114 3119 3128 32400 3268 3269 3301 33060 3333 340 3407 3479 3523 3524 3541 3542 3550 3551 3568 3570 37215 3749 3790 4010 4040 4064 4157 4200 427 4282 443 4433 444 4444 448 4500 4664 4786 4840 4848 49 491 4911 49153 4949 5010 50100 51 5150 5172 5201 5222 541 54138 5432 5446 55000 55443 5569 5593 5599 5673 5938 5984 6000 60001 6001 60030 6004 6006 60129 6036 6080 62078 6262 6464 6510 6560 6600 6653 6668 6748 675 6998 7001 7171 7415 7493 7510 7535 7548 7634 7657 7700 79 7989 800 8000 8009 8012 8013 8020 8026 8028 8036 8038 8043 8046 8049 8052 8066 8069 8071 8072 8081 8085 8087 8099 8100 8103 8111 8126 8140 8143 8200 8236 8238 8248 83 8334 84 8406 8431 8432 8443 8444 8513 8545 8554 8585 8590 8728 8789 88 8802 8822 8825 8834 8841 8848 8871 8874 8878 8879 8887 8888 8889 8988 8991 90 9000 9003 9007 9009 9015 9017 902 9031 9038 9040 9041 9042 9047 9080 9090 9091 9093 9094 9095 9102 9103 9107 9108 9109 9119 9151 9160 92 9206 9210 9215 9217 9310 9418 943 9443 95 96 9633 9690 9765 98 9800 993 9944 995 999 9999

CVEs Detected

CVE-2016-20012 CVE-2017-15906 CVE-2018-15473 CVE-2018-15919 CVE-2018-20685 CVE-2019-6109 CVE-2019-6110 CVE-2019-6111 CVE-2020-14145 CVE-2020-15778 CVE-2021-3618 CVE-2021-36368 CVE-2021-41617 CVE-2023-38408

Map

Whois Information

Links to attack logs

awsau-git-bruteforce-ip-list-2022-02-09 bruteforce-ip-list-2021-12-14 bruteforce-ip-list-2021-12-06 bruteforce-ip-list-2022-02-20

Share on: