160.251.96.177 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 160.251.96.177 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Host and Network Information

  • Country: Japan
  • Network: AS7506 gmo internet
  • Noticed: 1 times
  • Protocols Attacked: Anonymous Proxy
  • Passive DNS Results: casuawatch.xyz

Malware Detected on Host

Count:

Open Ports Detected

10000 10001 10073 10134 10143 1024 10243 10250 10554 10909 10911 1099 1111 11112 11210 11300 11434 1153 1177 12000 12235 1224 1234 12345 1337 13579 1400 1414 14147 14265 1433 14344 1471 1515 1521 1599 1604 16670 16992 17000 1723 1741 1800 1801 18081 18245 1880 1883 1911 1926 1935 1962 1981 2000 20000 2002 2008 2012 20256 20547 2058 2067 2081 2082 2087 21025 21027 2121 21379 2154 22 22000 22001 22067 22069 22070 2222 2245 2250 2259 23023 2323 23424 2345 2352 2375 2379 2404 2455 2480 25001 25105 2548 2628 27015 27017 2761 2762 28000 28015 28017 3000 30002 30003 3001 3002 30301 30303 3050 3061 3073 3075 3082 3111 3117 3128 31337 31401 32400 3260 3268 3269 3270 32764 3299 3301 3306 3310 3333 3388 3389 3443 3460 3541 3551 3561 3689 3749 3780 3790 3910 4000 4022 4063 4064 4118 4157 4242 4243 4282 4321 4369 443 4433 4434 4443 4444 4500 4506 4567 4782 4786 4840 4899 4911 4949 5000 5005 5007 5010 5025 5090 5172 5201 5222 5269 5432 5435 5542 5555 5560 5568 5594 5595 5598 5601 5634 5672 5697 5800 5801 5900 5901 5910 5938 5984 5985 6001 6002 6080 6265 6379 6443 6633 6653 6662 6697 6789 6887 7004 7070 7090 7171 7218 7316 7415 7434 7443 7474 7547 7548 7557 7654 7657 7676 7777 7779 7989 80 8001 8009 8010 8017 8023 8026 8031 8060 8072 8080 8081 8085 8086 8087 8089 8090 8098 8099 8109 8112 8123 8126 8139 8140 8143 8180 8181 8188 8200 8248 8291 8333 8383 8384 8406 8407 8430 8443 8500 8545 8554 8575 8666 8686 8728 8800 8821 8824 8832 8834 8842 8851 8858 8863 8865 8869 8871 8873 8876 8877 8880 8888 8889 8989 8990 9000 9002 9009 9021 9030 9034 9042 9045 9051 9070 9080 9090 9091 9092 9095 9097 9101 9102 9109 9160 9191 9200 9201 9215 9218 9220 9222 9295 9302 9305 9306 9367 9398 9443 9444 9595 9600 9633 9637 9690 9761 9800 9898 9943 9944 9981 9998 9999

Map

Whois Information

  • NetRange: 160.243.0.0 - 160.252.255.255
  • CIDR: 160.252.0.0/16, 160.243.0.0/16, 160.248.0.0/14, 160.244.0.0/14
  • NetName: APNIC-ERX-160-233-0-0
  • NetHandle: NET-160-243-0-0-1
  • Parent: NET160 (NET-160-0-0-0-0)
  • NetType: Early Registrations, Transferred to APNIC
  • OriginAS:
  • Organization: Asia Pacific Network Information Centre (APNIC)
  • RegDate: 2004-04-05
  • Updated: 2009-10-08
  • Comment: This IP address range is not registered in the ARIN database.
  • Comment: This range was transferred to the APNIC Whois Database as
  • Comment: part of the ERX (Early Registration Transfer) project.
  • Comment: For details, refer to the APNIC Whois Database via
  • Comment:
  • Comment: ** IMPORTANT NOTE: APNIC is the Regional Internet Registry
  • Comment: for the Asia Pacific region. APNIC does not operate networks
  • Comment: using this IP address range and is not able to investigate
  • Comment: spam or abuse reports relating to these addresses. For more
  • Ref: https://rdap.arin.net/registry/ip/160.243.0.0
  • OrgName: Asia Pacific Network Information Centre
  • OrgId: APNIC
  • Address: PO Box 3646
  • City: South Brisbane
  • StateProv: QLD
  • PostalCode: 4101
  • Country: AU
  • RegDate:
  • Updated: 2012-01-24
  • Ref: https://rdap.arin.net/registry/entity/APNIC
  • OrgTechHandle: AWC12-ARIN
  • OrgTechName: APNIC Whois Contact
  • OrgTechPhone: +61 7 3858 3188
  • OrgTechEmail: search-apnic-not-arin@apnic.net
  • OrgTechRef: https://rdap.arin.net/registry/entity/AWC12-ARIN
  • OrgAbuseHandle: AWC12-ARIN
  • OrgAbuseName: APNIC Whois Contact
  • OrgAbusePhone: +61 7 3858 3188
  • OrgAbuseEmail: search-apnic-not-arin@apnic.net
  • OrgAbuseRef: https://rdap.arin.net/registry/entity/AWC12-ARIN
  • inetnum: 160.251.0.0 - 160.251.255.255
  • netname: interQ
  • descr: GMO Internet Group, Inc.
  • descr: SAINTcity,3-1-1,kyomachi,Kokurakita-ku,Kitakyushu-shi,Fukuoka,802-0002,Japan
  • admin-c: JNIC1-AP
  • tech-c: JNIC1-AP
  • country: JP
  • mnt-by: MAINT-JPNIC
  • mnt-lower: MAINT-JPNIC
  • mnt-irt: IRT-JPNIC-JP
  • status: ALLOCATED PORTABLE
  • last-modified: 2022-11-10T02:22:05Z
  • irt: IRT-JPNIC-JP
  • address: Uchikanda OS Bldg 4F, 2-12-6 Uchi-Kanda
  • address: Chiyoda-ku, Tokyo 101-0047, Japan
  • e-mail: hostmaster@nic.ad.jp
  • abuse-mailbox: hostmaster@nic.ad.jp
  • phone: +81-3-5297-2311
  • fax-no: +81-3-5297-2312
  • admin-c: JNIC1-AP
  • tech-c: JNIC1-AP
  • mnt-by: MAINT-JPNIC
  • last-modified: 2022-06-14T04:26:58Z
  • role: Japan Network Information Center
  • address: Uchikanda OS Bldg 4F, 2-12-6 Uchi-Kanda
  • address: Chiyoda-ku, Tokyo 101-0047, Japan
  • country: JP
  • phone: +81-3-5297-2311
  • fax-no: +81-3-5297-2312
  • e-mail: hostmaster@nic.ad.jp
  • admin-c: JI13-AP
  • tech-c: JE53-AP
  • nic-hdl: JNIC1-AP
  • mnt-by: MAINT-JPNIC
  • last-modified: 2022-01-05T03:04:02Z
  • inetnum: 160.251.96.0 - 160.251.97.255
  • netname: CNODE-JP
  • descr: GMO Internet Group, Inc.
  • country: JP
  • admin-c: JP00080271
  • tech-c: JP00080271
  • last-modified: 2023-03-26T05:56:04Z

Links to attack logs

anonymous-proxy-ip-list-2024-09-15

Share on: