195.122.253.20 Threat Intelligence and Host Information

Share on:

General

This page was generated as a result of this host being detected actively attacking or scanning another host. See below for information related to the host network, location, number of days noticed, protocols attacked and other information including reverse DNS and whois.

Potentially Malicious Host 🟡 35/100

Host and Network Information

  • Tags: 465, Bruteforce, Nextray, SMTP, attack, credential stuff, cyber security, ioc, malicious, password spray, phishing, scanners, ssh, vultr
  • View other sources: Spamhaus VirusTotal

  • Country: Russian Federation
  • Network: AS8580 mts pjsc
  • Noticed: 13 times
  • Protcols Attacked: ssh
  • Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Spain, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
  • Passive DNS Results: jlweda.keenetic.link

Open Ports Detected

7547

Map

Whois Information

  • inetnum: 195.122.253.0 - 195.122.253.127
  • netname: SANDY-NAT-4
  • descr: Static NAT addresses Bras1 Bras2
  • country: RU
  • admin-c: SND-RIPE
  • tech-c: SND-RIPE
  • status: ASSIGNED PA
  • mnt-by: AS8580-MNT
  • created: 2008-12-12T14:28:49Z
  • last-modified: 2008-12-12T14:28:49Z
  • role: SANDY ISP Network Operation Center
  • address: Mobile TeleSystems OJSC Macro-region “Povolje”
  • address: 168a, Gagarina prospect
  • address: Nizhny Novgorod, 603009, Russia
  • phone: +7 831 2728930
  • fax-no: +7 831 2728998
  • tech-c: SYZ1-RIPE
  • nic-hdl: SND-RIPE
  • mnt-by: AS8580-MNT
  • created: 2002-03-12T13:25:47Z
  • last-modified: 2016-07-25T06:06:24Z
  • abuse-mailbox: [email protected]
  • route: 195.122.224.0/19
  • descr: Closed Join Stock Company “KOMSTAR-Regiony”
  • descr: Communication Service Centre of the Volga Region Branch in Nizhny Novgorod
  • descr: 46 Ulyanov St.
  • descr: N.Novgorod 603600
  • descr: Russia
  • origin: AS8580
  • mnt-by: AS8580-MNT
  • created: 1970-01-01T00:00:00Z
  • last-modified: 2019-07-08T14:20:40Z

Links to attack logs

vultrmadrid-ssh-bruteforce-ip-list-2023-02-21