202.6.238.34 Threat Intelligence and Host Information

Share on:

General

This page was generated as a result of this host being detected actively attacking or scanning another host. See below for information related to the host network, location, number of days noticed, protocols attacked and other information including reverse DNS and whois.

Potentially Malicious Host 🟡 31/100

Host and Network Information

  • Tags: Malicious IP, blacklist, botnet, bruteforce, digital ocean, mirai, mssql, scan, smb, tcp
  • View other sources: Spamhaus VirusTotal

  • Country: Indonesia
  • Network: AS23756 padi internet
  • Noticed: 3 times
  • Protcols Attacked: mssql
  • Countries Attacked: Germany

Malware Detected on Host

Count: 1 be9923b8f365740297bc8511359fec162b2c714f41c5f36244ce19ae5ce09ae0

Open Ports Detected

1701 1723 2000 80

Map

Whois Information

  • inetnum: 202.6.224.0 - 202.6.239.255
  • netname: PADINET-ID
  • descr: Padi Internet, PT
  • descr: Internet Service Provider
  • descr: Mayjen Sungkono no.83
  • descr: Surabaya 60242
  • descr: Indonesia
  • country: ID
  • admin-c: LL355-AP
  • tech-c: LL355-AP
  • status: ALLOCATED PORTABLE
  • mnt-by: MNT-APJII-ID
  • mnt-lower: MAINT-ID-PADINET
  • mnt-irt: IRT-PADINET-ID
  • last-modified: 2013-09-25T04:05:38Z
  • irt: IRT-PADINET-ID
  • address: Jl. Mayjen Sungkono no.83
  • address: Surabaya 60242
  • address: Indonesia
  • e-mail: [email protected]
  • abuse-mailbox: [email protected]
  • admin-c: LL355-AP
  • tech-c: LL355-AP
  • mnt-by: MAINT-ID-PADINET
  • last-modified: 2018-05-31T22:30:19Z
  • person: Louis Larry
  • nic-hdl: LL355-AP
  • e-mail: [email protected]
  • address: Jl. Mayjen Sungkono no.83
  • address: Surabaya 60242
  • address: Indonesia
  • phone: +62.31.5616330
  • fax-no: +62.31.5616304
  • country: ID
  • mnt-by: MAINT-ID-PADINET
  • last-modified: 2008-09-04T07:29:20Z
  • route: 202.6.238.0/24
  • descr: Route object of PT Padi Internet
  • descr: Corporate Internet Service Provider
  • descr: Surabaya
  • country: ID
  • origin: AS23756
  • notify: [email protected]
  • mnt-routes: MAINT-ID-PADINET
  • mnt-by: MAINT-ID-PADINET
  • last-modified: 2009-07-07T04:27:10Z
  • route: 202.6.238.0/24
  • descr: PADInet
  • descr: ISP
  • descr: Surabaya
  • country: ID
  • origin: AS9237
  • mnt-by: MAINT-ID-PADINET
  • last-modified: 2008-09-04T07:54:56Z
  • inetnum: 202.6.224.0 - 202.6.239.255
  • netname: PADINET-ID
  • descr: Padi Internet, PT
  • descr: Internet Service Provider
  • descr: Mayjen Sungkono no.83
  • descr: Surabaya 60242
  • descr: Indonesia
  • country: ID
  • admin-c: LL355-AP
  • admin-c: MZ631-AP
  • admin-c: HAP1-AP
  • tech-c: LL355-AP
  • tech-c: MZ631-AP
  • tech-c: HAP1-AP
  • status: ALLOCATED PORTABLE
  • mnt-by: MNT-APJII-ID
  • mnt-lower: MAINT-ID-PADINET
  • mnt-irt: IRT-PADINET-ID
  • last-modified: 2020-05-14T07:05:34Z
  • irt: IRT-PADINET-ID
  • address: PT. Padi Internet
  • address: Jl. Mayjen Sungkono no.83
  • address: Surabaya 60242
  • address: Indonesia
  • e-mail: [email protected]
  • abuse-mailbox: [email protected]
  • admin-c: LL355-AP
  • admin-c: MZ631-AP
  • admin-c: HAP1-AP
  • tech-c: LL355-AP
  • tech-c: MZ631-AP
  • tech-c: HAP1-AP
  • mnt-by: MAINT-ID-PADINET
  • last-modified: 2020-05-14T07:17:28Z
  • person: Henry Agung Pambudi
  • address: Jl. Mayjen Sungkono 83
  • address: Surabaya 60242 ID
  • country: ID
  • phone: +62-31-5616330
  • e-mail: [email protected]
  • nic-hdl: HAP1-AP
  • mnt-by: MAINT-ID-PADINET
  • last-modified: 2020-05-14T06:51:29Z
  • person: Louis Larry
  • nic-hdl: LL355-AP
  • e-mail: [email protected]
  • address: Jl. Mayjen Sungkono no.83
  • address: Surabaya 60242
  • address: Indonesia
  • phone: +62.31.5616330
  • fax-no: +62.31.5616304
  • country: ID
  • mnt-by: MAINT-ID-PADINET
  • last-modified: 2008-09-04T07:29:20Z
  • person: Mohammad Zamroni
  • nic-hdl: MZ631-AP
  • e-mail: [email protected]
  • address: Jl. Mayjen Sungkono 83
  • address: Surabaya 60242 ID
  • phone: +62-31-5616330
  • fax-no: +62-31-5616304
  • country: ID
  • mnt-by: MAINT-ID-PADINET
  • last-modified: 2009-01-09T04:30:17Z
  • route: 202.6.238.0/24
  • descr: Route object of PT Padi Internet
  • descr: Corporate Internet Service Provider
  • descr: Surabaya
  • country: ID
  • origin: AS23756
  • notify: [email protected]
  • notify: [email protected]
  • mnt-routes: MAINT-ID-PADINET
  • mnt-by: MAINT-ID-PADINET
  • last-modified: 2020-05-14T07:32:50Z

Links to attack logs

dofrank-mssql-bruteforce-ip-list-2023-05-02