204.11.59.195 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 204.11.59.195 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Known Malicious Host 🔴 72/100

Host and Network Information

  • Mitre ATT&CK IDs: T1021.001 - Remote Desktop Protocol, T1110 - Brute Force, T1184 - SSH Hijacking, T1192 - Spearphishing Link, T1194 - Spearphishing via Service, T1442 - Fake Developer Accounts, T1454 - Malicious SMS Message, T1566 - Phishing, T1583.001 - Domains, T1583.006 - Web Services, T1585.001 - Social Media Accounts, T1586 - Compromise Accounts, T1591.002 - Business Relationships

  • Tags: anydesk, as15169 as16509, as19871 as22612, as9002, business email compromise, c2, caas, fraud, hosting, identifying, parked domains, scams, ssh hijacking, typosquatting

  • View other sources: Spamhaus VirusTotal

  • Contained within other IP sets: hphosts_emd, hphosts_fsa, hphosts_psh

Malware Detected on Host

Count: 15 bc592b9aa8a837c7f0dc678a8baae27ddf9aa4b87290b5488afa27fda48edbe8 e96838749b420c7c8af3594501b3fd5c6423a9adc86d4ded5666c49e498c0269 f5146a460951b3a488244f012f2397d18b56131b37dca35f8f183062a9c1c216 3e306fbb77f8eaea36a281688e68fa3d3baebf9198a5ec2c4402e06149fe3da9 6dcb0095330e6faf4a59ea2d1a3b984425b72076402b566a969ccf5c15c82062 ff17c9a55e73acffe9b91d1b74a045763fc37f60d65fec772dd050c2e9d53613 b612ef4c8447b84f1dad290b69344ac88364d7e5bfa5d88fb21d1e272d476386 7f29a8d8e3d823bb42bfbe29e71c62f4d49dab10cc80a3a853223fdaf7b7ee39 18921283b9df87bfd574d3b19108c1b987dc19729196d6d54235ec8c102b4e1f ee811cdfd43ecaeeeaa64d3ce8c80c91740d968333e17fec9cca54341338c471

Open Ports Detected

110 2077 2082 2083 2086 2087 2095 21 22 2222 26 3306 443 465 53 587 80 993 995

CVEs Detected

CVE-2007-2768 CVE-2008-3844 CVE-2016-20012 CVE-2017-15906 CVE-2018-15473 CVE-2018-15919 CVE-2018-20685 CVE-2019-11358 CVE-2019-6109 CVE-2019-6110 CVE-2019-6111 CVE-2020-11022 CVE-2020-11023 CVE-2020-14145 CVE-2020-15778 CVE-2021-36368 CVE-2021-41617 CVE-2023-38408 CVE-2023-48795 CVE-2023-51385 CVE-2023-51767 CVE-2025-26465

Map

Whois Information

Links to attack logs

****** ****** ******

Share on: