185.220.102.248 Threat Intelligence and Host Information

Share on:

General

This page was generated as a result of this host being detected actively attacking or scanning another host. See below for information related to the host network, location, number of days noticed, protocols attacked and other information including reverse DNS and whois.

Likely Malicious Host 🟠 70/100

Host and Network Information

  • Mitre ATT&CK IDs: T1110 - Brute Force
  • Tags: AwfulShred, BidSwipe, Brute-Force, Bruteforce, CaddyWiper, Data Wipers, Nextray, OSINT, SDelete, SSH, T1027.002, T1573, Telnet, UK, Ukraine, ZeroWipe, apt, attack, awfulshred, aws, badrequest, bidswipe, bruteforce, caddywiper, cyber security, digital ocean, geopolitical conflict, initiator ip, ioc, kfsensor, login, malicious, phishing, probing, rdp, scanner, scanners, scanning, sdelete, ssh, ukraine, vultr, webscan, webscanner, webscanner bruteforce web app attack, zerowipe
  • Known tor exit node
  • View other sources: Spamhaus VirusTotal
  • Contained within other IP sets: blocklist_net_ua, botscout_30d, botscout_7d, cruzit_web_attacks, dm_tor, et_tor, greensnow, haley_ssh, sblam, stopforumspam, stopforumspam_180d, stopforumspam_1d, stopforumspam_30d, stopforumspam_365d, stopforumspam_7d, stopforumspam_90d, tor_exits, tor_exits_1d, tor_exits_30d, tor_exits_7d

  • Known TOR node
  • Country: Germany
  • Network: AS60729 zwiebelfreunde e.v.
  • Noticed: 50 times
  • Protcols Attacked: ssh
  • Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Singapore, Spain, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America

Malware Detected on Host

Count: 33 32d2b7e27a636d422d521cf4c3dad5cb050adfc858f86fcca09a5cb47fa520b5 d21b5efb6fb6a8886a49910ee6d251bac78fffaaa10d0a590ca8a54c4f2d2c4a 7b0dad1c77e7e11c5e9fc857bfac196a309d6935b18bdbf4835a359ebd32f186 2e1cb6a2cb1b284dbdd0b8d47d53f946ca0b27a196c45600cc656889c2e57623 f3000d56afe77e0d95335f7ea86562b3c0e598c1c66ecd4d62e5ccc8af6569d3 7548589cca05a011b563d58e795233faf2310975659bbc8b4d1db7ae6d805280 6a4fbdf1ce4ed0b37a31f1de5d55e02eccc671867c748ec9e39df3cf98c0e276 a4a63515b6bd2562e94430e10629c0c9e69309b2281dc857628cd537909c0352 e746ba510b706bc06b084ce84d6cd7e417137efde85bf12e421fdf21fd677943 e7711425a3037a9b4a805b185c9096b2db65a523f07c8f908ab89d1da37370b7

Open Ports Detected

123 443 80 8080

Map

Whois Information

  • inetnum: 185.220.102.240 - 185.220.102.255
  • netname: DIGITALCOURAGE-EXITS
  • country: DE
  • admin-c: KM6429-RIPE
  • tech-c: KM6429-RIPE
  • org: ORG-DE86-RIPE
  • status: SUB-ALLOCATED PA
  • mnt-by: de-zwf-1-mnt
  • mnt-by: ZWIEBELFREUNDE
  • created: 2020-08-16T15:25:46Z
  • last-modified: 2020-08-16T15:26:13Z
  • organisation: ORG-DE86-RIPE
  • org-name: Digitalcourage e.V.
  • org-type: OTHER
  • address: Marktstrasse 18
  • abuse-c: ACRO33566-RIPE
  • mnt-ref: ZWIEBELFREUNDE
  • mnt-by: de-zwf-1-mnt
  • mnt-by: ZWIEBELFREUNDE
  • created: 2020-06-15T07:35:08Z
  • last-modified: 2020-06-15T07:38:47Z
  • person: Karl Mueller
  • address: Marktstr. 18, D-33602 Bielefeld, Germany
  • phone: +49-521-1639 1639
  • nic-hdl: KM6429-RIPE
  • mnt-by: Digitalcourage
  • created: 2016-04-06T18:18:29Z
  • last-modified: 2017-10-30T23:11:41Z
  • route: 185.220.102.0/24
  • origin: AS60729
  • mnt-by: de-zwf-1-mnt
  • created: 2017-09-17T04:04:03Z
  • last-modified: 2018-05-15T08:28:07Z

Links to attack logs

bruteforce-ip-list-2023-01-22 vultrwarsaw-ssh-bruteforce-ip-list-2022-12-15 bruteforce-ip-list-2023-01-24 bruteforce-ip-list-2021-03-29 vultrparis-ssh-bruteforce-ip-list-2022-07-16 bruteforce-ip-list-2023-01-27 vultrmadrid-ssh-bruteforce-ip-list-2023-02-27 vultrwarsaw-ssh-bruteforce-ip-list-2022-12-03 vultrmadrid-ssh-bruteforce-ip-list-2022-12-04 vultrparis-ssh-bruteforce-ip-list-2023-02-07 vultrwarsaw-ssh-bruteforce-ip-list-2023-03-25 vultrparis-ssh-bruteforce-ip-list-2023-02-27 bruteforce-ip-list-2020-11-18 bruteforce-ip-list-2021-05-11 bruteforce-ip-list-2022-12-07 bruteforce-ip-list-2021-03-09 dotoronto-ssh-bruteforce-ip-list-2023-02-21 aws-ssh-bruteforce-ip-list-2021-06-08 aws-ssh-bruteforce-ip-list-2021-06-23 bruteforce-ip-list-2023-01-05 bruteforce-ip-list-2021-03-12 vultrparis-ssh-bruteforce-ip-list-2023-01-15 dofrank-ssh-bruteforce-ip-list-2023-01-08 vultrparis-ssh-bruteforce-ip-list-2023-02-13 vultrmadrid-ssh-bruteforce-ip-list-2022-12-23 bruteforce-ip-list-2020-09-03 dotoronto-ssh-bruteforce-ip-list-2023-01-23 vultrparis-ssh-bruteforce-ip-list-2023-03-21 dosing-ssh-bruteforce-ip-list-2023-03-06 vultrmadrid-ssh-bruteforce-ip-list-2023-04-03 bruteforce-ip-list-2021-03-13 vultrmadrid-ssh-bruteforce-ip-list-2022-12-01 dotoronto-ssh-bruteforce-ip-list-2022-12-02 vultrmadrid-ssh-bruteforce-ip-list-2022-12-07 dosing-ssh-bruteforce-ip-list-2022-12-21 vultrmadrid-ssh-bruteforce-ip-list-2023-02-15 aws-ssh-bruteforce-ip-list-2021-02-05 dosing-ssh-bruteforce-ip-list-2023-03-31 aws-ssh-bruteforce-ip-list-2021-04-26 vultrparis-ssh-bruteforce-ip-list-2022-11-28 bruteforce-ip-list-2020-08-28 aws-ssh-bruteforce-ip-list-2021-06-10 dolondon-ssh-bruteforce-ip-list-2022-11-28