185.13.120.112 Threat Intelligence and Host Information

Share on:

General

This page was generated as a result of this host being detected actively attacking or scanning another host. See below for information related to the host network, location, number of days noticed, protocols attacked and other information including reverse DNS and whois.

Potentially Malicious Host 🟡 31/100

Host and Network Information

  • Tags: Nextray, cyber security, ioc, malicious, phishing
  • View other sources: Spamhaus VirusTotal

  • Country: Russian Federation
  • Network: AS12688 joint stock company transtelecom
  • Noticed: 2 times
  • Protcols Attacked: telnet
  • Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America

Malware Detected on Host

Count: 2 444f075626031eca66bb76201a2bb2c91655a929e52a7e67af00c6ef48195a9b 444f075626031eca66bb76201a2bb2c91655a929e52a7e67af00c6ef48195a9b

Map

Whois Information

  • inetnum: 185.13.120.0 - 185.13.121.255
  • netname: RU-BTTK
  • country: RU
  • org: ORG-CJSC4-RIPE
  • admin-c: BTTC-RIPE
  • tech-c: BTTC-RIPE
  • status: ASSIGNED PA
  • mnt-by: BTTC-MNT
  • created: 2012-12-26T23:32:02Z
  • last-modified: 2021-04-16T03:53:57Z
  • organisation: ORG-CJSC4-RIPE
  • org-name: Closed Joint Stock Company SibTransTelecom
  • org-type: OTHER
  • address: 1, Televizornaya str.
  • address: 660028
  • address: Krasnoyarsk
  • address: RUSSIAN FEDERATION
  • phone: +73912160498
  • fax-no: +73912160489
  • mnt-ref: RU-SIBTTK-MNT
  • mnt-by: RU-SIBTTK-MNT
  • abuse-c: AR16923-RIPE
  • admin-c: KAV1000-RIPE
  • admin-c: STTK-RIPE
  • admin-c: SDB777-RIPE
  • admin-c: EAV9-RIPE
  • admin-c: APL8-RIPE
  • created: 2004-04-17T11:58:30Z
  • last-modified: 2020-10-26T14:57:26Z
  • role: GIS KTTK Sibir
  • address: JSC Company TransTeleCom
  • address: Branch SIBIR-TTK
  • address: Russia
  • address: 664025 Irkutsk
  • address: 38 Gagarina blvd
  • abuse-mailbox: [email protected]
  • admin-c: MVP125-RIPE
  • admin-c: TAI447-RIPE
  • tech-c: MVP125-RIPE
  • tech-c: TAI447-RIPE
  • nic-hdl: BTTC-RIPE
  • mnt-by: BTTC-MNT
  • created: 2011-03-23T07:33:25Z
  • last-modified: 2019-03-05T03:50:51Z
  • route: 185.13.120.0/22
  • descr: Customers with Baikal-TransTeleCom Global Access
  • origin: AS12688
  • mnt-by: BTTC-MNT
  • created: 2012-12-26T07:05:31Z
  • last-modified: 2012-12-26T07:05:31Z
  • route: 185.13.120.0/22
  • descr: TTK-Retail route object
  • origin: AS15774
  • mnt-by: BTTC-MNT
  • created: 2018-02-15T10:31:33Z
  • last-modified: 2018-02-15T10:31:33Z

Links to attack logs

doamsterdam-telnet-bruteforce-ip-list-2022-12-09