192.101.68.63 Threat Intelligence and Host Information

Share on:

General

This page was generated as a result of this host being detected actively attacking or scanning another host. See below for information related to the host network, location, number of days noticed, protocols attacked and other information including reverse DNS and whois.

Potentially Malicious Host 🟡 33/100

Host and Network Information

  • Tags: Malicious IP, Nextray, SIP, awsau, awssafrica, blacklist, botnet, bruteforce, cyber security, ioc, malicious, mirai, phishing, scan, sip, tcp, udp
  • View other sources: Spamhaus VirusTotal

  • Country: United States of America
  • Network: AS40676 psychz networks
  • Noticed: 4 times
  • Protcols Attacked: sip
  • Countries Attacked: Australia, Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, South Africa, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
  • Passive DNS Results: www.rawdani.com rawdani.com www.mail.flexiblepos.gmteknologi.com www.mail.aponishop.my.id nontonmotogp.com tokokusp.googo.my.id app.gmteknologi.com www.mail.aure-studios.com www.mail.beautiffskin.com promo.gmteknologi.com www.promo.gmteknologi.com www.scanner.luthfiansyah.com scanner.luthfiansyah.com www.adhofficial.com www.mail.astroinovasi.co.id www.vpn.gmteknologi.com vpn.gmteknologi.com www.berkahpersadainternusa.com berkahpersadainternusa.com dentist.luthfiansyah.com www.dentist.luthfiansyah.com flexiblepos.gmteknologi.com www.flexiblepos.gmteknologi.com blog.gmteknologi.com www.blog.gmteknologi.com www.parfume.luthfiansyah.com parfume.luthfiansyah.com www.lp.luthfiansyah.com lp.luthfiansyah.com www.porto.luthfiansyah.com porto.luthfiansyah.com googo.my.id www.googo.my.id citrasamuderaraya.com www.citrasamuderaraya.com www.berkahpersadamaritim.com berkahpersadamaritim.com www.sby.luthfiansyah.com sby.luthfiansyah.com www.gadget.luthfiansyah.com gadget.luthfiansyah.com www.luthfiansyah.com luthfiansyah.com ptnobelindonesia.com www.ptnobelindonesia.com seller.gmsport.id gmsport.id www.gmsport.id www.bigfamily.my.id bigfamily.my.id stocky.gmteknologi.com www.lintascitra.co.id lintascitra.co.id www.beautiffskincare.com beautiffskincare.com www.beautiffskin.com beautiffskin.com tokohoe.com www.tokohoe.com hosting.gmteknologi.com www.hosting.gmteknologi.com adhofficial.com pinjamanaman.my.id www.pinjamanaman.my.id amertajati.co.id www.amertajati.co.id www.skincare.luthfiansyah.com skincare.luthfiansyah.com perfume.luthfiansyah.com www.perfume.luthfiansyah.com www.parfum.luthfiansyah.com parfum.luthfiansyah.com ilfindonesia.com www.ilfindonesia.com ibeauty.my.id www.ibeauty.my.id beauty.luthfiansyah.com www.beauty.luthfiansyah.com www.gudangproyek.com gudangproyek.com www.mail.ujiinvo.gmserver.my.id www.mailer.gmteknologi.com mailer.gmteknologi.com aure-studios.com www.aure-studios.com jw.googo.my.id fredy.googo.my.id www.astroinovasi.co.id astroinovasi.co.id aponishop.my.id www.aponishop.my.id deny.googo.my.id www.gmserver.my.id gmserver.my.id www.mail.gmserver.my.id gmteknologi.com www.gmteknologi.com

Open Ports Detected

110 143 21 25 443 465 53 587 7080 80 8090 993 995

Map

Whois Information

  • NetRange: 192.101.64.0 - 192.101.71.255
  • CIDR: 192.101.64.0/21
  • NetName: DECRY18IP
  • NetHandle: NET-192-101-64-0-1
  • Parent: NET192 (NET-192-0-0-0-0)
  • NetType: Direct Allocation
  • OriginAS: AS12679
  • Organization: DECRYPT (DL-317)
  • RegDate: 2018-10-31
  • Updated: 2022-01-28
  • Comment: —–BEGIN CERTIFICATE—–MIIDPDCCAiQCCQCmubqeK9TjRTANBgkqhkiG9w0BAQsFADBgMQswCQYDVQQGEwJVUzELMAkGA1UECAwCVkExETAPBgNVBAcMCFJpY2htb25kMRAwDgYDVQQKDAdERUNSWVBUMR8wHQYJKoZIhvcNAQkBFhBtYW5hZ2VAbWFuYWdlLnV5MB4XDTIyMDEyODIyNTkzNFoXDTIzMDEyODIyNTkzNFowYDELMAkGA1UEBhMCVVMxCzAJBgNVBAgMAlZBMREwDwYDVQQHDAhSaWNobW9uZDEQMA4GA1UECgwHREVDUllQVDEfMB0GCSqGSIb3DQEJARYQbWFuYWdlQG1hbmFnZS51eTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALK/saiDksUOVzVqkQGyBE9gemcD+vLF6APL08z0EYk3b63vwId4TAHXhP0WorUACEboIIG339EbeXxHHlwKKkeZ35P+07uCm2RakPjRLktgjxrirhxPcEu3joXoUYqoQbSdMbKf3Wujvp9ANF2Hk74VL/vABATOXqabG1mBLfySBYYhHUj3j9kKcTGgH3RdwYkokHR4/lasROEcytOVCvZMilwGMHMepWGHd1+wjZY6gMcmSbQ5IHGmHkhy0QVZtggI6hlSGGDYwzlT62C5hKeQ77qRrAA/lYp9vmVtndEDHkeDUWVMVpjH6aYmt5n1FZiGvpE7sGx/V85h9L3EroUCAwEAATANBgkqhkiG9w0BAQsFAAOCAQEAertyNrnwrbpaxGcWsAOuEzKrzlrI5qPqdaJYDIfcCJB+c08F0TyJQAXF29bUy/smleSzKnyhJ2A+xthXuOdXW1xV0h6sbYNirSNQc4uy3UJDuMi7ugMyTX919T9l7YAzrCyKHhMD5fEaXNyM9wVodJ7RdbW5+roXhZv3bwmVJJXRLWZm2cZ6aszp3kLFKTRhtHg3RIteO4aAMylwKuM4N6MLjDe4RdGK+gYQhPpGcl8fJdOd4u1/17hA58Fg4rFgBExxrxpk/EHe3k4H9UCVwV/UlV66OJvzMzuacylHMVEMt8G+VI2OlYnZUYic7tUkxSBZR256pg63JAi61oLIAQ==—–END CERTIFICATE—–
  • Ref: https://rdap.arin.net/registry/ip/192.101.64.0
  • OrgName: DECRYPT
  • OrgId: DL-317
  • City: Glen Allen
  • StateProv: VA
  • PostalCode: 23059
  • Country: US
  • RegDate: 2015-12-03
  • Updated: 2022-11-01
  • Ref: https://rdap.arin.net/registry/entity/DL-317
  • OrgNOCHandle: MOTOV-ARIN
  • OrgNOCName: Motova, Denis
  • OrgNOCPhone: +1-804-212-2251
  • OrgNOCEmail: [email protected]
  • OrgNOCRef: https://rdap.arin.net/registry/entity/MOTOV-ARIN
  • OrgAbuseHandle: ABUSE8568-ARIN
  • OrgAbuseName: Abuse
  • OrgAbusePhone: +1-804-550-6725
  • OrgAbuseEmail: [email protected]
  • OrgAbuseRef: https://rdap.arin.net/registry/entity/ABUSE8568-ARIN
  • OrgTechHandle: MOTOV-ARIN
  • OrgTechName: Motova, Denis
  • OrgTechPhone: +1-804-212-2251
  • OrgTechEmail: [email protected]
  • OrgTechRef: https://rdap.arin.net/registry/entity/MOTOV-ARIN

Links to attack logs

awsau-sip-bruteforce-ip-list-2022-04-01 awssafrica-sip-bruteforce-ip-list-2022-04-01