198.98.52.143 Threat Intelligence and Host Information

Share on:

General

This page contains threat intelligence information for the IPv4 address 198.98.52.143 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Likely Malicious Host 🟠 70/100

Host and Network Information

  • Tags: Nextray, SSH, TOR, Telnet, VPN, attack, cyber security, ioc, la, lafusioncenter, login, louisiana, malicious, phishing, scanner, tsec
  • Known tor exit node
  • View other sources: Spamhaus VirusTotal
  • Contained within other IP sets: dm_tor, et_tor, haley_ssh, maxmind_proxy_fraud, stopforumspam_365d

  • Known TOR node
  • Country: United States
  • Network: AS53667 frantech solutions
  • Noticed: 50 times
  • Protcols Attacked: SSH
  • Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
  • Passive DNS Results: gitea.jwhite.network

Malware Detected on Host

Count: 10 045833c7c7a7f19d211e640c47ce3de279ef5171e25c97406c465acb49a30a25 a7e484d7cdbcb39538cd203c269d39b15d59f1703cf73429ca67128bb66c0a00 4fa3f2617f30ba961c5a8ba15364a6b9c70882bf4f405cc868ef734bfefeed91 fa3822cdb4113c9a330de5d457024d63d1acf56b71d732e43c39b1e2932e5b3d 9dea924fdd1549b0c47146c29acc9c218b0c3de565b7b7f947a2a3d918a80f73 bec6b87763b6440dd84a10c7c9d417dc77fc9fbbd560fd9c5fd46a213041ea98 1ea6e228b98c2b1d1fcd3e10c40119cec7ccdc63d256b29ad81800d5b61ba1d1 b472aec8c63a88f49e0efa6fbbad0c82a1c9d96551c6300b237fd92675385b86 122aaca6d61b6af60813a2d0a5b393867e41f2014e73291a5a96dacc88b5dafe a4a89e99a06c54d540429d0065c8865193c6587a155e67a4cdf867e57de77a02

Map

Whois Information

  • inetnum: 212.107.16.0 - 212.107.17.255
  • netname: HOSTINGER-HOSTING
  • country: NL
  • org: ORG-HIL8-RIPE
  • admin-c: HN1858-RIPE
  • tech-c: HN1858-RIPE
  • status: ASSIGNED PA
  • mnt-by: de-kis2-1-mnt
  • mnt-by: MNT-HOSTINGER
  • mnt-lower: MNT-HOSTINGER
  • mnt-routes: MNT-HOSTINGER
  • mnt-domains: MNT-HOSTINGER
  • created: 2019-03-27T13:18:21Z
  • last-modified: 2022-10-18T05:44:32Z
  • geoloc: 52.692547 6.190908
  • geofeed: https://raw.githubusercontent.com/hostinger/geofeed/main/geofeed.csv
  • organisation: ORG-HIL8-RIPE
  • org-name: Hostinger International Limited
  • org-type: OTHER
  • descr: Hostinger International Ltd.
  • address: 61 Lordou Vyronos Lumiel Building, 4th floor
  • address: 6023
  • address: Larnaca
  • address: CYPRUS
  • phone: +37064503378
  • fax-no: +37064503378
  • abuse-c: HA2755-RIPE
  • mnt-ref: de-kiservices-1-mnt
  • mnt-by: de-kiservices-1-mnt
  • mnt-ref: de-kis2-1-mnt
  • created: 2017-11-30T14:12:01Z
  • last-modified: 2019-01-02T15:52:53Z
  • person: Hostinger NOC
  • address: Hostinger International Ltd.
  • address: 61 Lordou Vyronos
  • address: Lumiel Building, 4th floor
  • address: 6023
  • address: Larnaca
  • address: CYPRUS
  • phone: +37064503378
  • nic-hdl: HN1858-RIPE
  • mnt-by: HN19812-MNT
  • created: 2013-12-02T20:17:12Z
  • last-modified: 2016-09-29T07:03:26Z
  • route: 212.107.16.0/23
  • origin: AS47583
  • mnt-by: MNT-HOSTINGER
  • created: 2019-03-27T13:20:49Z
  • last-modified: 2019-03-27T13:20:49Z