199.19.226.253 Threat Intelligence and Host Information

Share on:

General

This page contains threat intelligence information for the IPv4 address 199.19.226.253 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Potentially Malicious Host 🟡 40/100

Host and Network Information

  • Tags: C&C, Nextray, RDP, SSH, Telnet, abuse, alienvault ip, apache, attack, aws, bernal, botnet, botnet c2, bruteforce, carapicuiba, cowrie, cyber security, dstip, exploits, fail2ban, feodo tracker, fraud, generic, ho chi, host at, host de, host in, host tw, ioc, ip blocklist, ipqs, ipqualityscore, la, lafusioncenter, login, louisiana, malicious, malicious host, phishing, probing, scanner, scanners, scanning, ssh, web attack, webscan, webscanner bruteforce web app attack
  • View other sources: Spamhaus VirusTotal
  • Contained within other IP sets: haley_ssh

  • Country: United States
  • Network: AS53667 frantech solutions
  • Noticed: 50 times
  • Protcols Attacked: SSH
  • Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, Japan, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America

Malware Detected on Host

Count: 8 a4e0cc314a8937a630268f8f10e1bf1880d7ea371f5bc474878abf5bf689aded 976dbe7d3a51b35bfe59871ff178701109231d4ebe69f007341cf0001638ac08 6dd7390a2f1159a86973893f1e3da5e98ee929ed0f17564e6d82f2fd334d7123 57b9be23bb617671b1a421b3045e2135ba65c908314eac0096c4622b36f88cfe 57b9be23bb617671b1a421b3045e2135ba65c908314eac0096c4622b36f88cfe 4b5e1c88d6d13b0159f2c084f55c8cd0619d2a7656cf267c2d1646723dc0d7ae 4b5e1c88d6d13b0159f2c084f55c8cd0619d2a7656cf267c2d1646723dc0d7ae 781531101878ffc8637addb464cd5a4eb61fd238885c7e238a2af4dbca4d8aed

Map

Whois Information

  • NetRange: 199.19.224.0 - 199.19.227.255
  • CIDR: 199.19.224.0/22
  • NetName: PONYNET-01
  • NetHandle: NET-199-19-224-0-1
  • Parent: NET199 (NET-199-0-0-0-0)
  • NetType: Direct Allocation
  • OriginAS: AS18779, AS53667
  • Organization: FranTech Solutions (SYNDI-5)
  • RegDate: 2010-08-03
  • Updated: 2012-03-25
  • Ref: https://rdap.arin.net/registry/ip/199.19.224.0
  • OrgName: FranTech Solutions
  • OrgId: SYNDI-5
  • Address: 1621 Central Ave
  • City: Cheyenne
  • StateProv: WY
  • PostalCode: 82001
  • Country: US
  • RegDate: 2010-07-21
  • Updated: 2017-01-28
  • Ref: https://rdap.arin.net/registry/entity/SYNDI-5
  • OrgAbuseHandle: FDI19-ARIN
  • OrgAbuseName: Dias, Francisco
  • OrgAbusePhone: +1-778-977-8246
  • OrgAbuseEmail: [email protected]
  • OrgAbuseRef: https://rdap.arin.net/registry/entity/FDI19-ARIN
  • OrgTechHandle: FDI19-ARIN
  • OrgTechName: Dias, Francisco
  • OrgTechPhone: +1-778-977-8246
  • OrgTechEmail: [email protected]
  • OrgTechRef: https://rdap.arin.net/registry/entity/FDI19-ARIN
  • Li Jia
  • address: NO.969 West Wen Yi Road, Yu Hang District, Hangzhou
  • country: CN
  • phone: +86-0571-85022088
  • e-mail: [email protected]
  • nic-hdl: ZM1015-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2014-07-30T02:02:01Z
  • person: Guoxin Gao
  • address: 5F, Builing D, the West Lake International Plaza of S&T
  • address: No.391 Wen’er Road, Hangzhou City
  • address: Zhejiang, China, 310099
  • country: CN
  • phone: +86-0571-85022600
  • fax-no: +86-0571-85022600
  • e-mail: [email protected]
  • nic-hdl: ZM875-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2014-07-30T01:56:01Z
  • person: security trouble
  • e-mail: [email protected]
  • address: Hangzhou, Zhejiang, China
  • phone: +86-0571-85022600
  • country: CN
  • mnt-by: MAINT-CNNIC-AP
  • nic-hdl: ZM876-AP
  • last-modified: 2021-04-13T23:22:33Z
  • person: Guowei Pan
  • address: 5F, Builing D, the West Lake International Plaza of S&T
  • address: No.391 Wen’er Road, Hangzhou City
  • address: Zhejiang, China, 310099
  • country: CN
  • phone: +86-0571-85022088-30763
  • fax-no: +86-0571-85022600
  • e-mail: [email protected]
  • nic-hdl: ZM877-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2013-07-09T01:34:02Z
  • route: 115.28.0.0/15
  • descr: Hangzhou Alibaba Advertising Co.,Ltd.
  • country: CN
  • origin: AS37963
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2019-08-07T23:28:03Z
  • route: 115.28.0.0/15
  • descr: Alibaba (US) Technology Co., Ltd.
  • country: CN
  • origin: AS45102
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2019-08-07T23:28:02Z

Links to attack logs

bruteforce-ip-list-2021-06-16 aws-ssh-bruteforce-ip-list-2021-06-21 awsjap-ssh-bruteforce-ip-list-2021-07-04 aws-ssh-bruteforce-ip-list-2021-06-18 bruteforce-ip-list-2021-06-07 bruteforce-ip-list-2021-06-15 awsjap-ssh-bruteforce-ip-list-2021-06-25 bruteforce-ip-list-2021-06-26 aws-ssh-bruteforce-ip-list-2021-06-15 awsjap-ssh-bruteforce-ip-list-2021-06-18 aws-ssh-bruteforce-ip-list-2021-06-20