212.193.30.219 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 212.193.30.219 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Potentially Malicious Host 🟡 46/100

Host and Network Information

  • Tags: cyber security, ioc, malicious, Nextray, phishing

  • View other sources: Spamhaus VirusTotal

  • Country: Czechia
  • Network:
  • Noticed: 30 times
  • Protocols Attacked: ntp
  • Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
  • Passive DNS Results: a.pykgfw.ru beveiliging-id.icu its-me.icu

Malware Detected on Host

Count: 12 b579bb9f23a181c591bda3c058d4d35f8e1429a21ca00b24813f393ff7e63677 2888fd7336e7c6fcf301d7804eae4bff711a2f90799153a051d808c9bc4f394c 97e10280ead9a72f923c2552ee51c6e0732ab7ead894eb23b420794308fde28f f23677d09bc0a5f584c5314970a68ec25f3020657d5f3b789b257de10c28960f 0d733a15a0b9fb3792b40cc7017e480a050e5ff6504b96c610bf704c837b6cae 195be444b70b09260bea365c3de454778444949df21f3577e1caf9534cb04fb8 30c610f519efc9da9b7838021f6695591b193b2cb6afbf7ebe306acd1b9f3acf 38414bb5850a7076f4b33bf81bac9db0376a4df188355fac39d80193d7c7f557 fa1be914982a111f999fee0ed612d94ba9d0792257ee54c41acba3c2126e35ab efc211134ed98ee965bd30ab73c26551b52cea38318c53a933bf400a70af4f62

Open Ports Detected

22 443 80 8000

CVEs Detected

CVE-2021-23017 CVE-2021-3618 CVE-2023-44487

Map

Links to attack logs

****** awsau-ntp-bruteforce-ip-list-2021-12-04 ntp-bruteforce-ip-list-2021-12-04 awsbah-ntp-bruteforce-ip-list-2021-12-04 ****** ******

Share on: