168.63.127.55 Threat Intelligence and Host Information

Share on:

General

This page was generated as a result of this host being detected actively attacking or scanning another host. See below for information related to the host network, location, number of days noticed, protocols attacked and other information including reverse DNS and whois.

Host and Network Information

  • Mitre ATT&CK IDs: T1078 - Valid Accounts, T1083 - File and Directory Discovery, T1098.004 - SSH Authorized Keys, T1105 - Ingress Tool Transfer, T1110 - Brute Force, T1110.004 - Credential Stuffing
  • Tags: Bruteforce, aws, cowrie, digital ocean, scanners, ssh, vultr
  • View other sources: Spamhaus VirusTotal

  • Country: Netherlands
  • Network: AS8075 microsoft corporation
  • Noticed: 17 times
  • Protcols Attacked: ssh
  • Countries Attacked: Germany, Poland, Singapore, United Kingdom

Open Ports Detected

443 80

CVEs Detected

CVE-2006-20001 CVE-2022-22719 CVE-2022-22720 CVE-2022-22721 CVE-2022-23943 CVE-2022-26377 CVE-2022-28330 CVE-2022-28614 CVE-2022-28615 CVE-2022-29404 CVE-2022-30556 CVE-2022-31813 CVE-2022-36760 CVE-2022-37436

Map

Whois Information

  • NetRange: 168.61.0.0 - 168.63.255.255
  • CIDR: 168.62.0.0/15, 168.61.0.0/16
  • NetName: MICROSOFT
  • NetHandle: NET-168-61-0-0-1
  • Parent: NET168 (NET-168-0-0-0-0)
  • NetType: Direct Allocation
  • OriginAS:
  • Organization: Microsoft Corp (MSFT-Z)
  • RegDate: 2011-06-22
  • Updated: 2021-12-14
  • Ref: https://rdap.arin.net/registry/ip/168.61.0.0
  • OrgName: Microsoft Corp
  • OrgId: MSFT-Z
  • Address: One Microsoft Way
  • City: Redmond
  • StateProv: WA
  • PostalCode: 98052
  • Country: US
  • RegDate: 2011-06-22
  • Updated: 2021-10-14
  • Comment: To report suspected security issues specific to
  • Comment: traffic emanating from Microsoft online services,
  • Comment: including the distribution of malicious content
  • Comment: or other illicit or illegal material through a
  • Comment: Microsoft online service, please submit reports
  • Comment: to:
  • Comment: * https://cert.microsoft.com.
  • Comment:
  • Comment: For SPAM and other abuse issues, such as Microsoft
  • Comment: Accounts, please contact:
  • Comment: * [email protected].
  • Comment:
  • Comment: To report security vulnerabilities in Microsoft
  • Comment: products and services, please contact:
  • Comment: * [email protected].
  • Comment:
  • Comment: For legal and law enforcement-related requests,
  • Comment: please contact:
  • Comment: * [email protected]
  • Comment:
  • Comment: For routing, peering or DNS issues, please
  • Comment: contact:
  • Comment: * [email protected]
  • Ref: https://rdap.arin.net/registry/entity/MSFT-Z
  • OrgAbuseHandle: MAC74-ARIN
  • OrgAbuseName: Microsoft Abuse Contact
  • OrgAbusePhone: +1-425-882-8080
  • OrgAbuseEmail: [email protected]
  • OrgAbuseRef: https://rdap.arin.net/registry/entity/MAC74-ARIN
  • OrgTechHandle: IPHOS5-ARIN
  • OrgTechName: IPHostmaster, IPHostmaster
  • OrgTechPhone: +1-425-538-6637
  • OrgTechEmail: [email protected]
  • OrgTechRef: https://rdap.arin.net/registry/entity/IPHOS5-ARIN
  • OrgTechHandle: MRPD-ARIN
  • OrgTechName: Microsoft Routing, Peering, and DNS
  • OrgTechPhone: +1-425-882-8080
  • OrgTechEmail: [email protected]
  • OrgTechRef: https://rdap.arin.net/registry/entity/MRPD-ARIN

Links to attack logs

dolondon-ssh-bruteforce-ip-list-2022-07-21 bruteforce-ip-list-2022-07-20 dosing-ssh-bruteforce-ip-list-2022-07-19 dofrank-ssh-bruteforce-ip-list-2022-07-20 dosing-ssh-bruteforce-ip-list-2022-07-20 vultrwarsaw-ssh-bruteforce-ip-list-2022-08-09