185.106.94.171 Threat Intelligence and Host Information

Share on:

General

This page was generated as a result of this host being detected actively attacking or scanning another host. See below for information related to the host network, location, number of days noticed, protocols attacked and other information including reverse DNS and whois.

Potentially Malicious Host 🟡 35/100

Host and Network Information

  • Tags: scanners, ssh, vultr
  • View other sources: Spamhaus VirusTotal

  • Country: Russian Federation
  • Network: AS210644
  • Noticed: 5 times
  • Protcols Attacked: ssh
  • Countries Attacked: Spain

Open Ports Detected

100 10000 10001 102 1022 1024 10243 1025 104 10554 106 1080 1099 11 110 11000 111 1111 11112 1119 11210 11211 113 11300 1153 119 1200 12000 121 1234 1250 13 131 1311 13579 1388 1400 14147 14265 143 1433 1494 15 1521 154 1599 16010 1604 1660 16992 17 1723 1741 175 179 1801 18081 18245 1883 19000 1901 19071 1911 1925 1935 195 1950 1962 1981 199 1990 20 2000 20000 2001 2008 2010 2018 2020 2021 20256 2030 2049 2052 2053 20547 2055 2060 2063 2064 2066 2067 2069 2077 2081 2082 2083 2086 2087 21 2100 21025 2111 2121 21379 2154 2181 22 2200 2201 2202 221 2211 222 2222 2223 2232 225 2259 2320 23424 2345 2352 2375 2404 2443 2455 2480 25 25001 2506 2549 2554 2556 25565 2557 2558 2559 2560 2563 2569 2570 26 2601 264 27015 27017 2709 2761 2762 28015 28017 3000 3001 3002 3005 3050 3052 3053 3054 3055 3056 3058 3059 3060 3061 3067 3068 3072 3077 3078 3084 3085 3086 3089 3091 3095 3097 3098 3100 3102 3105 3110 3112 3113 3114 3115 3116 3118 3121 3128 3129 3211 3221 32400 3260 3268 3269 32764 3299 3301 3306 33060 3307 3310 3388 3389 3402 3403 3404 3406 3407 3412 3443 35000 3521 3522 3523 3524 3541 3542 3549 3550 3551 3557 3558 3559 3560 3562 3566 3567 3568 3569 3570 3689 37 3749 37777 3792 3838 389 3910 3950 3953 4000 4002 4010 4022 4040 4043 4063 4064 4117 41800 4190 4200 4242 4243 427 4282 43 4321 4369 44158 443 4430 4433 444 4444 445 447 448 44818 4482 4500 4505 4506 465 4664 4734 4782 4786 4840 4848 4899 49 4911 49153 4949 4999 50000 5002 5005 50050 5007 50070 5009 5010 502 5025 503 5070 5090 51 51106 5122 51235 515 5201 5209 522 5222 5269 52869 53 5357 5400 541 54138 5432 5443 548 5494 5500 55000 554 5542 55442 555 55554 5567 5590 5591 5592 5594 5595 5596 5597 5607 5672 5673 5800 5801 5822 5853 5858 5900 5901 5910 593 5938 5984 5985 6000 6001 6003 6009 6036 6080 61613 61616 62078 6308 631 6352 636 6363 6379 6443 6464 6510 6512 6543 6560 6565 6580 6581 6588 6590 6605 6622 6633 6650 6653 666 6666 6667 6668 6697 675 685 6887 70 7000 7001 7002 7003 7004 7005 7070 7071 7171 7401 7474 7500 7510 7547 7634 7654 7657 771 777 7776 7777 7779 7788 7887 789 79 7979 80 8000 8001 8003 8004 8005 8006 8009 801 8011 8012 8014 8022 8027 8028 8029 8030 8038 8039 8040 8041 8046 8052 8054 8055 806 8060 8064 8069 8072 808 8080 8081 8084 8086 8087 8090 8091 8092 8093 8094 8096 8097 8098 8099 8100 8101 8107 8112 8118 8126 8139 8140 8143 8182 8184 8190 8200 8243 8248 8249 8252 8291 8333 8334 8402 8403 8404 8405 8406 8408 8409 8411 8412 8413 8415 8424 8426 8428 843 8431 8433 8442 8444 8446 85 8545 8554 8575 8585 86 8602 8637 8649 8663 8700 8728 873 8733 8788 8789 8790 8791 880 8800 8801 8805 8806 8814 8817 8818 8821 8823 8824 8827 8829 8836 8846 8848 8850 8851 8852 8859 8862 8863 8866 8869 8870 8872 8873 8877 8879 888 8880 8881 8885 8887 8888 8935 8988 8990 8999 9000 9001 9007 9008 9009 9011 9014 902 9020 9024 9025 9026 9027 9029 9031 9034 9035 9039 9042 9045 9049 9051 9080 9090 9092 9095 9096 9097 9098 9099 9100 9101 9102 9103 9104 9106 9136 9151 9160 9191 9199 9200 9202 9203 9204 9208 9209 9210 9212 9214 9219 9220 9222 9301 9302 9304 9306 9308 9309 9311 9444 95 9500 9530 9595 96 9600 9606 9690 97 9761 9765 98 9869 9876 9898 9899 99 990 992 993 994 9944 995 9994 9997 9998 9999

CVEs Detected

CVE-2006-20001 CVE-2017-15710 CVE-2017-15715 CVE-2018-11763 CVE-2018-1283 CVE-2018-1301 CVE-2018-1302 CVE-2018-1303 CVE-2018-1312 CVE-2018-1333 CVE-2018-17189 CVE-2018-17199 CVE-2019-0196 CVE-2019-0211 CVE-2019-0217 CVE-2019-0220 CVE-2019-10081 CVE-2019-10082 CVE-2019-10092 CVE-2019-10098 CVE-2019-17567 CVE-2019-9517 CVE-2020-11993 CVE-2020-13938 CVE-2020-1927 CVE-2020-1934 CVE-2020-35452 CVE-2020-9490 CVE-2021-26690 CVE-2021-26691 CVE-2021-33193 CVE-2021-34798 CVE-2021-39275 CVE-2021-40438 CVE-2021-44224 CVE-2021-44790 CVE-2022-22719 CVE-2022-22720 CVE-2022-22721 CVE-2022-23943 CVE-2022-26377 CVE-2022-28330 CVE-2022-28614 CVE-2022-28615 CVE-2022-29404 CVE-2022-30556 CVE-2022-31813 CVE-2022-36760 CVE-2022-37436 CVE-2023-25690 CVE-2023-27522

Map

Whois Information

  • inetnum: 185.106.94.0 - 185.106.94.255
  • netname: Aeza-Network
  • country: AT
  • org: ORG-AGL38-RIPE
  • geofeed: https://aeza.net/static/ipv4_f.csv
  • geoloc: 48.2697765 16.4100816
  • admin-c: AN32749-RIPE
  • tech-c: AN32749-RIPE
  • mnt-routes: aeza-mnt
  • mnt-domains: aeza-mnt
  • status: ASSIGNED PA
  • mnt-by: aeza-mnt
  • created: 2022-04-21T11:59:08Z
  • last-modified: 2023-02-24T15:16:03Z
  • organisation: ORG-AGL38-RIPE
  • org-name: AEZA GROUP LLC
  • org-type: OTHER
  • address: 350001, Krasnodar, st. im. Mayakovskogo, b. 160, office 2.4
  • abuse-c: AA38875-RIPE
  • mnt-ref: aeza-mnt
  • mnt-ref: DN-MNT
  • mnt-ref: VF1-MNT
  • mnt-ref: DATAMAX-M
  • mnt-by: aeza-mnt
  • created: 2021-11-23T13:59:30Z
  • last-modified: 2023-01-06T12:18:43Z
  • role: Aeza Network
  • address: 350001, Krasnodar, st. im. Mayakovskogo, b. 160, office 2.4
  • nic-hdl: AN32749-RIPE
  • mnt-by: aeza-group-mnt
  • created: 2021-11-24T09:55:02Z
  • last-modified: 2021-11-24T09:55:02Z
  • route: 185.106.94.0/24
  • origin: AS210644
  • mnt-by: aeza-mnt
  • mnt-by: AEZA-NETWORK-MNT
  • created: 2022-04-26T10:55:08Z
  • last-modified: 2022-04-26T10:55:08Z

Links to attack logs

vultrmadrid-ssh-bruteforce-ip-list-2023-04-18 vultrmadrid-ssh-bruteforce-ip-list-2023-04-20 bruteforce-ip-list-2023-04-18