167.71.12.1 Threat Intelligence and Host Information
General
This page contains threat intelligence information for the IPv4 address 167.71.12.1 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.
Potentially Malicious Host 🟡 35/100
Host and Network Information
-
Tags: cyber security, ioc, malicious, Nextray, phishing, tsec
-
View other sources: Spamhaus VirusTotal
- Country: Netherlands
- Network:
- Noticed: 33 times
- Protocols Attacked: Anonymous Proxy
- Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
- Passive DNS Results: raiseddarkness.com testersuite.co.uk testersuite.nl samvestor.com
Open Ports Detected
10000 10134 102 1023 1024 10243 104 10443 10909 10911 111 11112 11210 11211 113 11434 1200 122 1224 1234 1245 1311 1337 1344 135 1400 1414 1443 1500 1515 1521 1741 1801 1911 1925 1926 1935 2000 2002 2003 2008 2012 211 2121 22 221 2222 2320 2323 2332 2345 2404 25 26 2626 3001 3005 3101 311 3111 3128 3129 3301 3310 3333 3541 3542 4000 4040 4242 4321 443 4433 4434 444 4444 445 4506 4523 4545 4840 4911 5000 5001 5005 5006 5007 5009 5010 502 5025 503 515 5201 5222 541 5432 5435 5601 5800 5801 5900 5901 5918 5938 6000 6001 631 6443 6605 6633 7001 7004 7218 7433 7434 7443 7634 79 80 8000 8007 8008 8009 8010 8012 8029 8112 8126 8139 8140 8200 8334 8408 8545 88 8800 8801 8806 8814 8834 8842 9000 9002 9009 9010 9011 9019 902 9033 9039 9042 9100 9110 9200 9213 9306 9307 9333 9418 9443 9530 9600 9633 9800 9943 9944
Map
Whois Information
- NetRange: 167.71.0.0 - 167.71.255.255
- CIDR: 167.71.0.0/16
- NetName: DIGITALOCEAN-167-71-0-0
- NetHandle: NET-167-71-0-0-1
- Parent: NET167 (NET-167-0-0-0-0)
- NetType: Direct Allocation
- OriginAS: AS14061
- Organization: DigitalOcean, LLC (DO-13)
- RegDate: 2019-04-24
- Updated: 2020-04-03
- Comment: Routing and Peering Policy can be found at https://www.as14061.net
- Comment:
- Ref: https://rdap.arin.net/registry/ip/167.71.0.0
- OrgName: DigitalOcean, LLC
- OrgId: DO-13
- Address: 101 Ave of the Americas
- Address: FL2
- City: New York
- StateProv: NY
- PostalCode: 10013
- Country: US
- RegDate: 2012-05-14
- Updated: 2023-10-23
- Ref: https://rdap.arin.net/registry/entity/DO-13
- OrgNOCHandle: NOC32014-ARIN
- OrgNOCName: Network Operations Center
- OrgNOCPhone: +1-347-875-6044
- OrgNOCEmail: noc@digitalocean.com
- OrgNOCRef: https://rdap.arin.net/registry/entity/NOC32014-ARIN
- OrgTechHandle: NOC32014-ARIN
- OrgTechName: Network Operations Center
- OrgTechPhone: +1-347-875-6044
- OrgTechEmail: noc@digitalocean.com
- OrgTechRef: https://rdap.arin.net/registry/entity/NOC32014-ARIN
- OrgAbuseHandle: ABUSE5232-ARIN
- OrgAbuseName: Abuse, DigitalOcean
- OrgAbusePhone: +1-347-875-6044
- OrgAbuseEmail: abuse@digitalocean.com
- OrgAbuseRef: https://rdap.arin.net/registry/entity/ABUSE5232-ARIN
Links to attack logs
****** awssafrica-ntp-bruteforce-ip-list-2022-06-07 digitaloceanlondon-ssh-bruteforce-ip-list-2024-10-02 ****** digitaloceanlondon-ssh-bruteforce-ip-list-2024-11-08 digitaloceanlondon-ssh-bruteforce-ip-list-2024-10-03 aws-ssh-bruteforce-ip-list-2021-03-21 digitaloceansingapore-ssh-bruteforce-ip-list-2024-10-01 ****** ****** digitaloceansingapore-ssh-bruteforce-ip-list-2024-11-06
Share on: