163.53.247.5 Threat Intelligence and Host Information

Share on:

General

This page was generated as a result of this host being detected actively attacking or scanning another host. See below for information related to the host network, location, number of days noticed, protocols attacked and other information including reverse DNS and whois.

Potentially Malicious Host 🟡 42/100

Host and Network Information

  • Mitre ATT&CK IDs: T1110 - Brute Force
  • Tags: Brute-Force, Bruteforce, SSH, aws, brute force, rdp, scanners, ssh, tsec
  • View other sources: Spamhaus VirusTotal
  • Contained within other IP sets: blocklist_net_ua, haley_ssh

  • Country: Macao
  • Network: AS132422 hong kong telecom global data centre
  • Noticed: 16 times
  • Protcols Attacked: ssh
  • Countries Attacked: Australia, Singapore
  • Passive DNS Results: www.24uka.com 24uka.com www.exin888.cn exin888.cn pay.exin888.cn www.ekagou.com ekagou.com pygbg.com uyuct.com

Malware Detected on Host

Count: 2 49c531ab965641d0f6d43075743783e000bdb541df83e10ef8634a9d266a1806 49c531ab965641d0f6d43075743783e000bdb541df83e10ef8634a9d266a1806

Open Ports Detected

195 7657 9080

Map

Whois Information

  • inetnum: 163.53.247.0 - 163.53.247.255
  • netname: MVIPACL-MO
  • descr: MACAO-MO
  • country: MO
  • admin-c: MVIP1-AP
  • tech-c: MVIP1-AP
  • abuse-c: AM3002-AP
  • status: ALLOCATED NON-PORTABLE
  • mnt-by: MAINT-MVIPACL-MO
  • mnt-irt: IRT-MVIPACL-MO
  • last-modified: 2021-01-15T00:33:47Z
  • irt: IRT-MVIPACL-MO
  • address: Macao
  • e-mail: [email protected]
  • abuse-mailbox: [email protected]
  • admin-c: MVIP1-AP
  • tech-c: MVIP1-AP
  • mnt-by: MAINT-MVIPACL-MO
  • last-modified: 2023-04-14T02:05:11Z
  • role: ABUSE MVIPACLMO
  • address: Macao
  • country: ZZ
  • phone: +000000000
  • e-mail: [email protected]
  • admin-c: MVIP1-AP
  • tech-c: MVIP1-AP
  • nic-hdl: AM3002-AP
  • abuse-mailbox: [email protected]
  • mnt-by: APNIC-ABUSE
  • last-modified: 2023-02-01T14:01:33Z
  • role: MACAO VICTORY INTELLECTUAL PROPERTY AGENT CO LTD
  • address: Macao
  • country: MO
  • phone: +853-65405471
  • e-mail: [email protected]
  • admin-c: MVIP1-AP
  • tech-c: MVIP1-AP
  • nic-hdl: MVIP1-AP
  • mnt-by: MAINT-MVIPACL-MO
  • last-modified: 2015-01-09T06:06:02Z

Links to attack logs

bruteforce-ip-list-2022-02-17 dosing-ssh-bruteforce-ip-list-2023-03-29 **