212.193.30.210 Threat Intelligence and Host Information

Share on:

General

This page contains threat intelligence information for the IPv4 address 212.193.30.210 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Potentially Malicious Host 🟡 40/100

Host and Network Information

  • Mitre ATT&CK IDs: T1110 - Brute Force
  • Tags: Bruteforce, Malicious IP, Nextray, RDP, SSH, Scanner, Telnet, Webattack, abuse, attack, blacklist, botnet, bruteforce, cowrie, cyber security, fraud, ioc, ipqs, ipqualityscore, login, malicious, mirai, phishing, scan, scanner, scanning, smtp, ssh, tcp, telnet, web attack
  • View other sources: Spamhaus VirusTotal

  • Country: Czechia
  • Network: AS211252 delis llc
  • Noticed: 27 times
  • Protcols Attacked: ssh
  • Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
  • Passive DNS Results: klngdoms.com www.defl-klngdoms.com defl-klngdoms.com belfusdashboard.com belfisius.com befliusdashboard.com belfiuso.com nyoka.duckdns.org cldgr.duckdns.org

Malware Detected on Host

Count: 11 bf2f76799ab48abaa5b39c035874c2e29b3528a414cdcdc70091fe9cc5b63996 2b17064a5beb209a3c075c6172752572e89c87d74f05578f0f79b6c48d42e91d 36fee94df9ac2810e9524e31ba2c54cacd91092a3cbe65584b1cf5e846d4bfe1 5d6ff2643b74919193a41086ab9daf8db12884870cbf2eaa2dd6f353a70c60ac 2f33920ae1154c17f28e10f59692baedf6b54144fe021afbb45fe4beb5300b56 31e451c0ed9facf723843ed727b18a1b3a81229879821293f240da1ba815348c daef8e3db60866e88b709068a1deae4b9a0931de56ea85e6536d23414b28a5cb 02cedfdd4f81a7e84a825212dd428fb3096db68675a01845d4aa5eaeab39845a 99cf221a695faf75f501bfaab261c764597cef440b367a96de006f2c22227da3 03badf963c3ddd39fc21e95513ae303bc0881ceb263c8fa76fb79ad2a2cfe9b2

Map

Whois Information

  • inetnum: 212.237.249.0 - 212.237.249.255
  • netname: ACL-9582
  • descr: ZITCOM A/S
  • country: DK
  • org: ORG-ZA59-RIPE
  • admin-c: ZIN4-RIPE
  • tech-c: ZIN4-RIPE
  • status: ASSIGNED PA
  • mnt-by: ZITCOM-MNT
  • created: 2018-01-03T12:56:43Z
  • last-modified: 2022-10-27T07:02:59Z
  • geofeed: https://geofeed.s3-dk6.clu2.obj.storagefactory.io/geofeed.csv
  • organisation: ORG-ZA59-RIPE
  • org-name: team.blue Denmark A/S
  • country: DK
  • org-type: LIR
  • address: Højvangen 4
  • address: 8660
  • address: Skanderborg
  • address: DENMARK
  • phone: +4570400000
  • admin-c: MHV24-RIPE
  • admin-c: AS48854-RIPE
  • abuse-c: ZIN4-RIPE
  • mnt-ref: RIPE-NCC-HM-MNT
  • mnt-ref: ZITCOM-MNT
  • mnt-by: RIPE-NCC-HM-MNT
  • mnt-by: ZITCOM-MNT
  • created: 2010-08-27T09:23:04Z
  • last-modified: 2022-01-03T08:46:09Z
  • role: team.blue Denmark Network
  • address: Højvangen 4
  • address: Skanderborg 8660
  • address: Denmark
  • phone: +45 70235566
  • admin-c: MHV24-RIPE
  • admin-c: AS48854-RIPE
  • tech-c: MHV24-RIPE
  • tech-c: AS48854-RIPE
  • nic-hdl: ZIN4-RIPE
  • mnt-by: ZITCOM-MNT
  • created: 2010-08-31T10:44:11Z
  • last-modified: 2022-01-19T10:02:01Z
  • abuse-mailbox: [email protected]
  • route: 212.237.248.0/23
  • descr: ZITCOM A/S
  • origin: AS48854
  • mnt-by: ZITCOM-MNT
  • created: 2017-04-06T12:29:44Z
  • last-modified: 2017-04-06T12:29:44Z