2.59.119.2 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 2.59.119.2 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Possibly Malicious Host 🟢 10/100

Host and Network Information

  • JARM: 29d29d00029d29d00042d43d00041d598ac0c1012db967bb1ad0ff2491b3ae

  • View other sources: Spamhaus VirusTotal

  • Contained within other IP sets: blocklist_net_ua

Malware Detected on Host

Count: 17 e2bf55af798752e37b417eed9b639885390f9775f68cf30c932570e7eb0986a5 73d6fd53676104904fa7005a5d90cd80bad00c6eba81668a19134f13e56a39cf 09e77b25dd64a04057957b85835ee2f8ffde9a5be49fb1fcee9788e4f91c433d 64060de9b6a924560c9f476671b874220fbb58ca525ac67a5ae10a08a201ff5f a979e65a90e5f5b633385f3b8c6074f556de5976f3aba678a96a5a64e08ac90e d107ba9f9e325426d1adff6d7a4c997c80cf43d97c72a920bd8ac84c75fb3051 7015a51d605ff90fd62a94159689f6ece83c73f3427b4eb038731c124417903c d9c980e8fccf316f07c8b0f598567b8d9feaea330f1d190de67eed72a6abcf8f d66e89e3267a93d005444e115711baee2df779bc5c673a7e7cf1a45303e82aca 03a21714d0b16b2c559a81f239b5bc41c3ff43db93ffb368c8730d1f90c1b5ff

Open Ports Detected

110 111 143 161 2077 2082 2083 2086 2087 21 3306 443 465 53 587 80 993 995

Map

Whois Information

  • inetnum: 2.59.119.0 - 2.59.119.127
  • netname: HOSTINGDUNYAM
  • country: TR
  • org: ORG-HA960-RIPE
  • admin-c: EB13930-RIPE
  • tech-c: EB13930-RIPE
  • status: LIR-PARTITIONED PA
  • created: 2022-01-09T08:23:45Z
  • last-modified: 2022-01-09T08:23:45Z
  • mnt-by: ensarb-mnt
  • organisation: ORG-HA960-RIPE
  • org-name: Hosting Dunyam internet Hizmetleri
  • org-type: OTHER
  • address: Sütlüce Mahallesi imrahor Caddesi Haliç Park Plaza no:2/1 Kat:5 Daire:13, 34212 Beyoglu/istanbul
  • abuse-c: ACRO45798-RIPE
  • mnt-ref: ensarb-mnt
  • mnt-by: ensarb-mnt
  • created: 2022-01-09T08:06:47Z
  • last-modified: 2022-01-09T08:27:05Z
  • person: ensar bogaz
  • address: Sütlüce Mahallesi ?mrahor Caddesi Haliç Park Plaza no:2/1 Kat:5 Daire:13, 34212 Beyo?lu/?stanbul,
  • phone: +90 212 909 96 56
  • nic-hdl: EB13930-RIPE
  • mnt-by: ensarb-mnt
  • created: 2022-01-09T08:15:28Z
  • last-modified: 2022-01-09T08:15:28Z
  • route: 2.59.119.0/24
  • origin: AS212219
  • mnt-by: EB12679-RIPE
  • mnt-by: mnt-tr-mehmet1-1
  • mnt-by: mehmetu
  • mnt-by: ensar
  • mnt-by: MU2093-RIPE
  • created: 2020-12-07T13:53:11Z
  • last-modified: 2020-12-07T13:53:11Z

Links to attack logs

anonymous-proxy-ip-list-2023-10-06 anonymous-proxy-ip-list-2023-10-25 anonymous-proxy-ip-list-2023-10-17 anonymous-proxy-ip-list-2023-10-04 anonymous-proxy-ip-list-2023-10-21 anonymous-proxy-ip-list-2023-09-15 anonymous-proxy-ip-list-2023-09-27 forum-spam-ip-list-2021-04-11 doamsterdam-telnet-bruteforce-ip-list-2022-09-08 anonymous-proxy-ip-list-2023-10-22 anonymous-proxy-ip-list-2023-10-23 anonymous-proxy-ip-list-2023-10-24 anonymous-proxy-ip-list-2023-09-21 anonymous-proxy-ip-list-2023-09-26 anonymous-proxy-ip-list-2023-09-18

Share on: