199.249.230.157 Threat Intelligence and Host Information

Share on:

General

This page was generated as a result of this host being detected actively attacking or scanning another host. See below for information related to the host network, location, number of days noticed, protocols attacked and other information including reverse DNS and whois.

Likely Malicious Host 🟠 70/100

Host and Network Information

  • Tags: Nextray, Raspberry Robin, TOR, VPN, anna paula, associated, currc3adculo, cve202229266, cyber security, description, description ip, from email, headers, indicator, indicator type, ioc, malicious, malspam email, msi file, phishing, tor ip, tuesday, utf8, zip archive
  • Known tor exit node
  • View other sources: Spamhaus VirusTotal
  • Contained within other IP sets: botscout_30d, botscout_7d, dm_tor, et_tor, sblam, stopforumspam, stopforumspam_180d, stopforumspam_30d, stopforumspam_365d, stopforumspam_7d, stopforumspam_90d, tor_exits

  • Known TOR node
  • Country: United States of America
  • Network: AS62744 quintex alliance consulting
  • Noticed: 50 times
  • Protcols Attacked: spam
  • Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, South Africa, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
  • Passive DNS Results: block2.mmms.eu edcrowcloud.myds.me

Malware Detected on Host

Count: 48 15ef0a1d45c7e02a8963f3c1917e957a657938c6f0e1b70ebfebc41f62533395 66f42c964c81f4dfed55fe123da4b0a791d73cce7bf25e7cf3051e7d686f3d64 b11e614cdd02aecb8d6ae65bf67bfac8cbefd68830065217e2cb48922743bb12 cd7eccb828d9bbefb488620a26710d46583907d8eb48ce8840599c7daf8b54cd 99cb069870ab51775c9dd88da1c3b84ab0190bf7b34338ae2eaa8cb0de6bcd01 6a8004aae12643b6d6d993fa960439fc191cd61de23bce87d2f1d7384b88b940 ff8f1de68e86ef17d9fcd554d6ae95f215c5547cca2d4163600a7b6212b7d17f b84f4383bb671370a33ef6daad1bd8c2e14ea8164592c04b0a318bd3e1077d58 604716a0f702e54ffc8390652aba8b04aa85192fe4655e17f125b2156651073d 32d2b7e27a636d422d521cf4c3dad5cb050adfc858f86fcca09a5cb47fa520b5

Map

Whois Information

  • NetRange: 199.249.230.0 - 199.249.230.255
  • CIDR: 199.249.230.0/24
  • NetName: QUINTEX230
  • NetHandle: NET-199-249-230-0-1
  • Parent: NET199 (NET-199-0-0-0-0)
  • NetType: Direct Allocation
  • OriginAS: AS62744
  • Organization: Quintex Alliance Consulting (QAC-4-Z)
  • RegDate: 1994-06-07
  • Updated: 2021-12-14
  • Ref: https://rdap.arin.net/registry/ip/199.249.230.0
  • OrgName: Quintex Alliance Consulting
  • OrgId: QAC-4-Z
  • Address: 6730 Goodland Loop
  • City: San Angelo
  • StateProv: TX
  • PostalCode: 76901
  • Country: US
  • RegDate: 2017-03-22
  • Updated: 2022-01-04
  • Ref: https://rdap.arin.net/registry/entity/QAC-4-Z
  • OrgAbuseHandle: JR125-ARIN
  • OrgAbuseName: Ricketts, John L
  • OrgAbusePhone: +1-325-304-1600
  • OrgAbuseEmail: [email protected]
  • OrgAbuseRef: https://rdap.arin.net/registry/entity/JR125-ARIN
  • OrgTechHandle: JR125-ARIN
  • OrgTechName: Ricketts, John L
  • OrgTechPhone: +1-325-304-1600
  • OrgTechEmail: [email protected]
  • OrgTechRef: https://rdap.arin.net/registry/entity/JR125-ARIN
  • RNOCHandle: JR125-ARIN
  • RNOCName: Ricketts, John L
  • RNOCPhone: +1-325-304-1600
  • RNOCEmail: [email protected]
  • RNOCRef: https://rdap.arin.net/registry/entity/JR125-ARIN
  • RAbuseHandle: JR125-ARIN
  • RAbuseName: Ricketts, John L
  • RAbusePhone: +1-325-304-1600
  • RAbuseEmail: [email protected]
  • RAbuseRef: https://rdap.arin.net/registry/entity/JR125-ARIN
  • RTechHandle: JR125-ARIN
  • RTechName: Ricketts, John L
  • RTechPhone: +1-325-304-1600
  • RTechEmail: [email protected]
  • RTechRef: https://rdap.arin.net/registry/entity/JR125-ARIN

Links to attack logs

forum-spam-ip-list-2023-03-15