179.43.152.50 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 179.43.152.50 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Potentially Malicious Host 🟡 40/100

Host and Network Information

  • Tags: cyber security, ioc, kfsensor, malicious, Nextray, phishing, rdp, ssh

  • View other sources: Spamhaus VirusTotal

  • Country: Switzerland
  • Network:
  • Noticed: 50 times
  • Protocols Attacked: SSH
  • Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
  • Passive DNS Results: mcewenmadeit.direct.quickconnect.to c-cerastes.direct.quickconnect.to platonas.synology.me areneas.direct.quickconnect.to jsxr3s4mp9ptbtfwd7w6.direct.quickconnect.to djokovic.myqnapcloud.com windowslivesoffice.ddns.net putakama.hopto.org truetest.sandcats.io

Malware Detected on Host

Count: 7 655d7e42e49b1b1bbe13c557c082ee54ef29878efc762556bcd00b9091edda10 5eb8628f79617a3971473ef5f8080dfdce05f3d0002f7ef62588a66deecb1532 b964a261c5217b2e44ea672bb8e692bb4fe36ae1ea5fba4c6a1d4d80cf8d02bb a62fdcd146a20084a621047e5e5a93101d6f524c467543a355ed5a4b193485a2 25ff1b6221f4c7b2f8cb1ca7ad51d0f421e64b78361ea21a2d1eaa5f6f1f1ea0 4942f13c62483771aa4517a562223fc39eb5db055a7bd1545679d3dc7cc786bf b0ea8ffc342135bb63e500d07c9631c3bf406cfbe75cc87c43f3763f59f6b0b0

Open Ports Detected

22 80

Map

Links to attack logs

****** nmap-scanning-list-2023-05-14 ****** ******

Share on: