197.85.7.165 Threat Intelligence - South Africa | IP Address Lookup

Share on:

General

IP Address
197.85.7.165
IPv4 Address
Location
πŸ‡ΏπŸ‡¦ South Africa
ZA
Network
AS3741
Dimension Data
Threat Score
40/100
Medium Risk
Aggressive-Detectionattacker-ipautomatedbrute-forcebruteforceBruteforceBrute-ForceConnection-Reset
Attack Intelligence
MITRE ATT&CK Techniques
T1110 - Brute Force
Noticed
11 times
Protocols Attacked
combined ssh
Countries Attacked
Finland, France, Germany, Poland, United States of America
Passive DNS
maragra.mobi
Open Ports Detected
1005022
Geographic Location
Country
South Africa
City
Unknown
Region
Unknown
Coordinates
-29.0000, 24.0000
Network Information
ASN
AS3741
Organization
Dimension Data
Network
AS3741 Dimension Data
WHOIS Information
inetnum
197.85.0.0 - 197.85.255.255
netname
IGNITE-NET-197-85-0-0
descr
IGNITE
org
ORG-DD1-AFRINIC
admin-c
AS24-AFRINIC
tech-c
AS24-AFRINIC
status
ASSIGNED PA
mnt-by
IS-OPTINET-MNT
mnt-lower
IS-OPTINET-MNT
mnt-domains
IS-OPTINET-MNT
parent
197.80.0.0 - 197.87.255.255
organisation
ORG-DD1-AFRINIC
org-name
Dimension Data
org-type
LIR
country
ZA
address
The Campus,
phone
tel:+27-72-614-3611
mnt-ref
AFRINIC-HM-MNT
person
Arthur Seesink
nic-hdl
AS24-AFRINIC
fax-no
tel:+27-11-447-5567
Attack Logs
DateTarget LocationProtocolLink
2026-09-21 Digitaloceanlondon Combined Multiple View Log
2026-09-21 London, UK SSH View Log
Additional Intelligence
Threat Feeds / IP Sets
  • haley_ssh
Disclaimer
This page contains threat intelligence information for the IPv4 address 197.85.7.165 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only, and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.