185.208.220.48 Threat Intelligence and Host Information
General
This page contains threat intelligence information for the IPv4 address 185.208.220.48 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.
Potentially Malicious Host 🟡 40/100
Host and Network Information
-
Tags: attack, awsjap, bruteforce, cyber security, ioc, login, malicious, Nextray, phishing, scanner, SSH, telnet, Telnet, tsec
-
View other sources: Spamhaus VirusTotal
- Country: Spain
- Network: AS205718 alcort ingenieria y asesoria s.l.
- Noticed: 37 times
- Protocols Attacked: telnet
- Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, Japan, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
- Passive DNS Results: 185.208.220.48
Open Ports Detected
10001 10073 10134 10143 10243 10250 10443 10909 10911 11000 11112 11210 11211 11288 11300 11371 11434 12000 13579 14147 14344 16010 16030 16285 16992 16993 17000 18081 18245 18553 18888 19000 19071 19989 20000 20256 20547 20880 21025 21379 22067 23023 23424 25001 25565 27015 27017 28015 28017 28080 30002 30003 30010 3074 3080 3087 3088 3094 3103 3104 3107 3111 3119 3128 3200 3260 3268 3269 3270 3299 3301 3306 3310 3337 3352 3388 3389 3460 3498 3503 3521 3522 3541 3542 3549 3551 3552 3554 3563 3689 3690 3749 3780 3790 3792 3794 4000 4040 4043 4063 4064 4117 4200 4242 4282 4321 4369 4433 4434 4443 4444 4482 4500 4506 4567 4664 4782 4786 4840 4848 4911 5000 5001 5005 5006 5007 5009 5010 5025 5122 5150 5201 5209 5280 5357 5431 5432 5435 5446 5454 5555 5560 5568 5569 5592 5595 5601 5604 5605 5634 5672 5697 5800 5801 5858 5900 5901 5938 5984 5985 5986 6000 6001 6002 6036 6308 6352 6379 6443 6511 6543 6560 6590 6633 6653 6664 6667 6668 6748 6789 6998 7000 7001 7014 7071 7170 7171 7218 7415 7434 7443 7444 7474 7548 7557 7657 7777 7779 7989 8008 8009 8010 8013 8020 8024 8028 8030 8032 8039 8045 8052 8056 8060 8069 8080 8081 8083 8085 8086 8087 8089 8090 8092 8093 8094 8097 8098 8099 81 8107 8112 8123 8139 8140 8159 8181 8188 8200 8249 8252 8291 8333 8334 8383 8401 8402 8414 8420 8425 8426 8433 8443 8513 8545 8575 8622 8649 8663 8728 8767 8787 88 8802 8806 8808 8811 8813 8815 8818 8824 8828 8831 8834 8835 8838 8842 8847 8848 8850 8856 8866 8872 8880 8887 8888 8889 8969 8993 8999 9000 9001 9002 9003 9008 9009 9015 9019 9023 9029 9034 9038 9041 9042 9048 9070 9080 9090 9091 9095 9100 9106 9160 9191 9199 9200 9207 9212 9215 9217 9219 9221 9222 9295 9300 9301 9302 9306 9307 9398 9433 9443 9530 9595 9600 9690 9743 9761 9800 9869 9876 9898 9899 9943 9944 9950 9981 9991 9998 9999
Map
Links to attack logs
dosing-telnet-bruteforce-ip-list-2021-12-22 awsjap-telnet-bruteforce-ip-list-2022-04-20 ****** dolondon-telnet-bruteforce-ip-list-2021-12-18 vultrparis-telnet-bruteforce-ip-list-2021-12-01 ****** ******
Share on: