212.113.119.45 Threat Intelligence and Host Information

Share on:

General

This page contains threat intelligence information for the IPv4 address 212.113.119.45 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Possibly Malicious Host 🟢 17/100

Host and Network Information

  • Tags: Brute-Force, Bruteforce, SSH
  • View other sources: Spamhaus VirusTotal

  • Country: United States
  • Network: AS1239 sprint
  • Noticed: 1 times
  • Protcols Attacked: SSH
  • Passive DNS Results: mak.volia.tk user.work.volia.tk hid.volia.tk 212.113.119.45.sslip.io

Open Ports Detected

10001 10134 102 10243 104 1080 1099 11000 111 11210 11371 1167 1200 12345 13 1311 13579 15 1515 17 1723 175 180 1833 1901 20000 2008 2020 2067 2081 2082 2096 21025 22 225 23424 2382 25001 25105 2554 2601 2602 28015 28017 3050 3052 3061 3081 3084 3085 3091 3094 3096 3113 32400 3268 3270 3301 3306 3307 3333 3352 3388 3409 3460 3479 3498 35000 3551 3561 37 37777 3780 3951 4000 4063 4064 4157 4282 4321 44158 443 4444 448 4500 4505 4550 4567 4643 4782 4786 49 4949 5000 5005 50050 5006 502 5025 5122 5150 5201 53 5357 55442 5599 5605 5606 5672 593 5938 5984 6001 60129 6080 6161 62078 6262 6264 631 636 6379 6560 6565 6600 666 6668 6697 685 7170 7171 7415 7443 7444 7474 7500 7547 7634 7777 7778 79 80 8000 8004 8012 8028 8029 8031 8037 8038 8041 8042 8069 8083 8084 8090 8099 8104 8123 8139 8140 8180 8237 8243 8291 8405 8407 8428 8429 8554 86 873 8733 88 8800 8804 8830 8833 888 8889 8891 8935 9000 9009 9023 9029 9031 9042 9088 9093 9096 9099 9105 9108 9160 9200 9206 9207 9210 9213 9222 9310 9899 990 9944 9955 9998 9999

Map

Whois Information

  • inetnum: 115.48.0.0 - 115.63.255.255
  • netname: UNICOM-HA
  • descr: China Unicom Henan province network
  • descr: China Unicom
  • country: CN
  • admin-c: CH1302-AP
  • tech-c: WW444-AP
  • mnt-by: APNIC-HM
  • mnt-lower: MAINT-CNCGROUP-HA
  • mnt-routes: MAINT-CNCGROUP-RR
  • mnt-irt: IRT-CU-CN
  • status: ALLOCATED PORTABLE
  • last-modified: 2016-05-04T00:13:27Z
  • irt: IRT-CU-CN
  • address: No.21,Financial Street
  • address: Beijing,100033
  • address: P.R.China
  • e-mail: [email protected]
  • abuse-mailbox: [email protected]
  • admin-c: CH1302-AP
  • tech-c: CH1302-AP
  • mnt-by: MAINT-CNCGROUP
  • last-modified: 2017-10-23T05:59:13Z
  • person: ChinaUnicom Hostmaster
  • nic-hdl: CH1302-AP
  • e-mail: [email protected]
  • address: No.21,Jin-Rong Street
  • address: Beijing,100033
  • address: P.R.China
  • phone: +86-10-66259764
  • fax-no: +86-10-66259764
  • country: CN
  • mnt-by: MAINT-CNCGROUP
  • last-modified: 2017-08-17T06:13:16Z
  • person: Wei Wang
  • nic-hdl: WW444-AP
  • e-mail: [email protected]
  • phone: +86-371-65952358
  • fax-no: +86-371-65968952
  • country: CN
  • mnt-by: MAINT-CNCGROUP-HA
  • last-modified: 2010-03-05T08:20:01Z
  • route: 115.48.0.0/12
  • descr: CNC Group CHINA169 Henan Province Network
  • country: CN
  • origin: AS4837
  • mnt-by: MAINT-CNCGROUP-RR
  • last-modified: 2008-09-04T07:55:26Z

Links to attack logs

bruteforce-ip-list-2023-05-07