199.249.230.157 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 199.249.230.157 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Likely Malicious Host 🟠 70/100

Host and Network Information

  • Tags: cve202229266, cyber security, description, description ip, indicator, indicator type, ioc, malicious, Nextray, phishing, tor

  • Known tor exit node

  • View other sources: Spamhaus VirusTotal

  • Contained within other IP sets: blocklist_net_ua, botscout_1d, dm_tor, et_tor, sblam, stopforumspam_180d, stopforumspam_1d, stopforumspam_30d, stopforumspam_365d, stopforumspam_7d, stopforumspam_90d, stopforumspam, tor_exits

  • Known TOR node
  • Country: United States
  • Network:
  • Noticed: 50 times
  • Protocols Attacked: spam
  • Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
  • Passive DNS Results: tor68.quintex.com block2.mmms.eu edcrowcloud.myds.me

Malware Detected on Host

Count: 48 15ef0a1d45c7e02a8963f3c1917e957a657938c6f0e1b70ebfebc41f62533395 66f42c964c81f4dfed55fe123da4b0a791d73cce7bf25e7cf3051e7d686f3d64 b11e614cdd02aecb8d6ae65bf67bfac8cbefd68830065217e2cb48922743bb12 cd7eccb828d9bbefb488620a26710d46583907d8eb48ce8840599c7daf8b54cd 99cb069870ab51775c9dd88da1c3b84ab0190bf7b34338ae2eaa8cb0de6bcd01 6a8004aae12643b6d6d993fa960439fc191cd61de23bce87d2f1d7384b88b940 ff8f1de68e86ef17d9fcd554d6ae95f215c5547cca2d4163600a7b6212b7d17f b84f4383bb671370a33ef6daad1bd8c2e14ea8164592c04b0a318bd3e1077d58 604716a0f702e54ffc8390652aba8b04aa85192fe4655e17f125b2156651073d 32d2b7e27a636d422d521cf4c3dad5cb050adfc858f86fcca09a5cb47fa520b5

Map

Whois Information

Links to attack logs

****** forum-spam-ip-list-2023-03-15 ****** ******

Share on: