185.106.94.88 Threat Intelligence and Host Information

Share on:

General

This page contains threat intelligence information for the IPv4 address 185.106.94.88 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Possibly Malicious Host 🟢 15/100

Host and Network Information

  • View other sources: Spamhaus VirusTotal

  • Country: Russia
  • Network:
  • Noticed: times
  • Protcols Attacked: ssh
  • Passive DNS Results: homeasle.homes

Open Ports Detected

10001 1029 111 11211 113 1200 12000 1290 13 15 1599 16010 16992 175 18081 1833 19071 1911 195 1950 1951 2000 2008 2020 2022 20256 2049 2063 2067 2080 2081 21025 2121 2181 22 2200 221 2222 2345 2351 2382 25 2549 25565 2562 2568 26 2601 2626 2650 2761 3001 3052 3062 3086 3096 3097 3098 3101 3102 3105 3110 3111 3114 31337 3221 3260 32764 3299 3301 3307 3310 3352 3402 3407 3409 3412 3479 3503 3522 3524 3548 3570 3689 3953 3954 4000 4118 41800 427 4282 43 444 4444 44818 4505 4506 4523 4808 49 5000 50000 5004 5005 5070 515 5190 5280 53 541 54138 55443 55553 55554 5600 5900 5901 5907 5909 6000 6036 61613 6262 636 6511 6550 6580 6581 6590 6600 6601 6667 6668 675 70 7005 7090 7171 7444 7548 7654 7676 771 777 789 80 8003 8009 8011 8023 8038 8044 8066 8091 8096 8097 8108 8118 8123 8159 8184 82 8222 8243 8249 8251 8282 8291 8333 8409 8410 8414 8416 8424 8442 8590 8649 8666 8782 8808 8813 8816 8825 8827 8833 8835 8841 8846 8848 8852 8864 8866 8867 8873 8876 89 8935 8988 8991 9030 9033 9050 9051 9084 9092 91 9106 9191 9206 9219 9221 9300 9304 9307 9418 95 9530 9595 97 9743 98 992 993 994 995 9981

CVEs Detected

CVE-2006-20001 CVE-2019-17567 CVE-2020-11984 CVE-2020-11993 CVE-2020-13938 CVE-2020-13950 CVE-2020-1927 CVE-2020-1934 CVE-2020-35452 CVE-2020-9490 CVE-2021-26690 CVE-2021-26691 CVE-2021-33193 CVE-2021-34798 CVE-2021-36160 CVE-2021-39275 CVE-2021-40438 CVE-2021-44224 CVE-2021-44790 CVE-2022-22719 CVE-2022-22720 CVE-2022-22721 CVE-2022-23943 CVE-2022-26377 CVE-2022-28330 CVE-2022-28614 CVE-2022-28615 CVE-2022-29404 CVE-2022-30556 CVE-2022-31813 CVE-2022-36760 CVE-2022-37436 CVE-2023-25690 CVE-2023-27522

Map

Whois Information

  • inetnum: 185.106.94.0 - 185.106.94.255
  • netname: Aeza-Network
  • country: AT
  • org: ORG-AGL38-RIPE
  • geofeed: https://aeza.net/static/ipv4_f.csv
  • geoloc: 48.2697765 16.4100816
  • admin-c: AN32749-RIPE
  • tech-c: AN32749-RIPE
  • mnt-routes: aeza-mnt
  • mnt-domains: aeza-mnt
  • status: ASSIGNED PA
  • mnt-by: aeza-mnt
  • created: 2022-04-21T11:59:08Z
  • last-modified: 2023-02-24T15:16:03Z
  • organisation: ORG-AGL38-RIPE
  • org-name: AEZA GROUP LLC
  • org-type: OTHER
  • address: 350001, Krasnodar, st. im. Mayakovskogo, b. 160, office 2.4
  • abuse-c: AA38875-RIPE
  • mnt-ref: aeza-mnt
  • mnt-ref: DN-MNT
  • mnt-ref: VF1-MNT
  • mnt-ref: DATAMAX-M
  • mnt-by: aeza-mnt
  • created: 2021-11-23T13:59:30Z
  • last-modified: 2023-01-06T12:18:43Z
  • role: Aeza Network
  • address: 350001, Krasnodar, st. im. Mayakovskogo, b. 160, office 2.4
  • nic-hdl: AN32749-RIPE
  • mnt-by: aeza-group-mnt
  • created: 2021-11-24T09:55:02Z
  • last-modified: 2021-11-24T09:55:02Z
  • route: 185.106.94.0/24
  • origin: AS210644
  • mnt-by: aeza-mnt
  • mnt-by: AEZA-NETWORK-MNT
  • created: 2022-04-26T10:55:08Z
  • last-modified: 2022-04-26T10:55:08Z

Links to attack logs

vultrmadrid-ssh-bruteforce-ip-list-2023-05-18