162.159.248.242 Threat Intelligence and Host Information

Share on:

General

This page contains threat intelligence information for the IPv4 address 162.159.248.242 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Possibly Malicious Host 🟢 10/100

Host and Network Information

  • View other sources: Spamhaus VirusTotal

  • Country:
  • Network: AS13335 cloudflare
  • Noticed: 1 times
  • Protcols Attacked: Anonymous Proxy
  • Passive DNS Results: ibest9.com www.epionline.org theautospas.com sripanwa.com weddingphuketevents.sripanwa.com www.peopleandwine.com.cdn.cloudflare.net hicustom.net www.koanga.org.nz www.technewsdaily.com cf-ssl59412-protected-core.tv-over.net

Malware Detected on Host

Count: 18 d68095f4f8c7ae7ec04184209c85b217c591aec1b61747197cc94dfb666d329a 414d65169a8047fac808424081f6d12746ffc13c7a1d4ed5377b551109e36963 8e32483636ca11d29b800e050583dc57125d486f9967aa1994c6e15435f469a0 c0b5e1c4f2378971fbab65c5083fbe3556a44ad521c39f4a8ac93dde628cd7c3 ad25451d40364a3eab4ca56f8b9093723ca8fd67aa82da160f61ab440e92336d 285519daaa53b2d6edb99b6f365eea0515d4ed9076fd14faeb3a9218bda9fdd1 9c9da11891a544a9b725e1780b15362c076283574cde83cc46757faea13cb7cd 06636e7bdce96bc33beb3325db21a6991eed7d0529d441ee30ccf15c747dfb40 2155a3a315194f5a861d66d1906c9a43060a5128193ecc13856c073a1a19d11c 6a616dde5e1a2aa6e1575aa14d7e05b7968e8e97ff3bd74b7f74d141667f113c

Open Ports Detected

2082 2083 2087 2095 443 80 8443

Map

Whois Information

  • NetRange: 162.158.0.0 - 162.159.255.255
  • CIDR: 162.158.0.0/15
  • NetName: CLOUDFLARENET
  • NetHandle: NET-162-158-0-0-1
  • Parent: NET162 (NET-162-0-0-0-0)
  • NetType: Direct Allocation
  • OriginAS: AS13335
  • Organization: Cloudflare, Inc. (CLOUD14)
  • RegDate: 2013-05-23
  • Updated: 2021-05-26
  • Comment: All Cloudflare abuse reporting can be done via https://www.cloudflare.com/abuse
  • Ref: https://rdap.arin.net/registry/ip/162.158.0.0
  • OrgName: Cloudflare, Inc.
  • OrgId: CLOUD14
  • Address: 101 Townsend Street
  • City: San Francisco
  • StateProv: CA
  • PostalCode: 94107
  • Country: US
  • RegDate: 2010-07-09
  • Updated: 2021-07-01
  • Ref: https://rdap.arin.net/registry/entity/CLOUD14
  • OrgAbuseHandle: ABUSE2916-ARIN
  • OrgAbuseName: Abuse
  • OrgAbusePhone: +1-650-319-8930
  • OrgAbuseEmail: [email protected]
  • OrgAbuseRef: https://rdap.arin.net/registry/entity/ABUSE2916-ARIN
  • OrgNOCHandle: CLOUD146-ARIN
  • OrgNOCName: Cloudflare-NOC
  • OrgNOCPhone: +1-650-319-8930
  • OrgNOCEmail: [email protected]
  • OrgNOCRef: https://rdap.arin.net/registry/entity/CLOUD146-ARIN
  • OrgRoutingHandle: CLOUD146-ARIN
  • OrgRoutingName: Cloudflare-NOC
  • OrgRoutingPhone: +1-650-319-8930
  • OrgRoutingEmail: [email protected]
  • OrgRoutingRef: https://rdap.arin.net/registry/entity/CLOUD146-ARIN
  • OrgTechHandle: ADMIN2521-ARIN
  • OrgTechName: Admin
  • OrgTechPhone: +1-650-319-8930
  • OrgTechEmail: [email protected]
  • OrgTechRef: https://rdap.arin.net/registry/entity/ADMIN2521-ARIN
  • RNOCHandle: NOC11962-ARIN
  • RNOCName: NOC
  • RNOCPhone: +1-650-319-8930
  • RNOCEmail: [email protected]
  • RNOCRef: https://rdap.arin.net/registry/entity/NOC11962-ARIN
  • RTechHandle: ADMIN2521-ARIN
  • RTechName: Admin
  • RTechPhone: +1-650-319-8930
  • RTechEmail: [email protected]
  • RTechRef: https://rdap.arin.net/registry/entity/ADMIN2521-ARIN
  • RAbuseHandle: ABUSE2916-ARIN
  • RAbuseName: Abuse
  • RAbusePhone: +1-650-319-8930
  • RAbuseEmail: [email protected]
  • RAbuseRef: https://rdap.arin.net/registry/entity/ABUSE2916-ARIN

Links to attack logs

anonymous-proxy-ip-list-2023-07-09