190.61.106.248 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 190.61.106.248 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Potentially Malicious Host 🟡 40/100

Host and Network Information

  • Tags: attack, awsindia, bruteforce, cowrie, cyber security, digital ocean, ioc, login, malicious, Nextray, phishing, scanner, Scanner, scanning, smtp, ssh, SSH, tcp, telnet, Telnet, Webattack

  • View other sources: Spamhaus VirusTotal

  • Country: Costa Rica
  • Network: AS52468 ufinet panama s.a.
  • Noticed: 50 times
  • Protocols Attacked: telnet
  • Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, India, Latvia, Lithuania, Norway, Poland, Romania, Singapore, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America

Open Ports Detected

10000 1024 10243 10250 104 10443 10554 111 11112 11288 113 11371 11434 12345 13047 1311 1337 13579 1400 1414 14265 1433 14344 1443 1471 1515 1521 15443 1599 16010 16030 16992 16993 1723 1741 175 1800 18245 19071 1911 1925 1926 1935 195 1962 19930 2000 20256 2082 2083 2086 2087 21379 23424 2345 2375 2376 2404 2480 25001 25105 264 27015 2761 2762 28017 28080 3000 3001 30010 311 3128 31337 31443 32400 3260 3299 3310 3333 3388 3389 34125 3460 35000 3541 3542 3689 37215 3749 37777 3780 3790 4000 4040 41443 4157 4242 427 443 4433 444 4443 4444 44818 4567 4664 4782 4786 47990 4848 49152 49153 5000 50000 5001 5005 50050 5006 50070 5009 51106 51443 5201 5222 52311 5269 52869 5357 5435 554 55442 55443 5555 55553 5560 5601 5672 5800 5801 5900 5901 5938 5985 5986 60001 60010 60030 60129 6080 631 63256 63257 6443 6664 6668 6881 7001 7071 7171 7434 7443 7474 7547 7548 7657 7777 7779 7989 80 8000 8001 8008 8009 8010 8060 8069 8080 8081 8083 8085 8086 8089 8090 8098 81 8112 8123 8139 8140 8181 8188 82 8200 8291 83 8333 8334 84 8443 8554 8728 88 8800 8834 8880 8888 8889 9000 9001 9002 9009 9080 9090 9091 9095 9100 9191 9200 9295 9398 9418 9443 9530 9595 9600 9633 9800 9869 9898 9943 9944 9981 9999

Map

Links to attack logs

awsindia-telnet-bruteforce-ip-list-2022-05-20 ****** dosing-telnet-bruteforce-ip-list-2022-05-09 ****** ******

Share on: