216.39.249.201 Threat Intelligence and Host Information

Share on:

General

This page contains threat intelligence information for the IPv4 address 216.39.249.201 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Possibly Malicious Host 🟢 5/100

Host and Network Information

  • View other sources: Spamhaus VirusTotal

  • Country: Singapore
  • Network: AS395092 shock hosting llc
  • Noticed: 1 times
  • Protcols Attacked: Anonymous Proxy

Open Ports Detected

1000 10000 10134 102 10243 1025 1026 104 10554 1099 11000 111 113 11371 1200 121 1234 13 1311 1355 13579 1400 1471 15 154 16010 1604 1650 16992 16993 1723 1741 1801 1820 1833 1883 19 1901 19071 1925 1926 2000 20000 2002 2008 2021 2053 20547 2056 2067 2069 2082 2083 2086 2087 2100 211 2122 21379 2150 2181 2200 221 2225 225 2266 2323 2332 2345 2376 2443 2455 25105 2554 26 2762 28017 2985 3000 30002 30003 3050 3058 3063 3067 3069 3073 3083 3090 3105 3107 311 3111 3112 3113 3118 3119 3120 3121 3129 3200 3260 3268 32764 3299 3301 3310 3337 3352 3389 3400 3401 3404 3407 3409 3412 3498 35000 3503 3521 3522 3524 3550 3551 3554 3555 3561 3562 3569 37 37215 3791 3838 4001 4022 4042 4063 4064 4100 4118 41800 4200 427 4282 4321 4369 44158 443 4433 444 44818 465 4664 4747 4782 4786 4840 4899 49 4911 50000 5001 5004 50050 50070 5010 502 503 53 5321 5431 5432 5435 55442 5555 55553 55554 5595 5599 5601 5606 5800 5822 5858 587 5901 5910 593 5984 5986 6002 6008 6161 6262 6264 631 6379 646 6561 6600 6605 6633 6650 666 6662 6666 6667 6668 6697 6998 7004 7014 7218 7401 7415 7443 7548 7776 7777 7779 79 80 800 8009 801 8010 8013 8015 8016 8024 8025 8031 8034 8036 8041 8042 8043 8050 8055 8080 8081 8083 8088 8090 8092 8094 8098 8100 8102 8103 8104 8110 8112 8118 8126 82 8222 8237 8282 8383 8401 8413 8414 8415 8420 8425 8429 8442 8445 85 8500 8545 8575 8585 8623 8686 8688 8728 8733 8779 8789 880 8803 8805 8808 8811 8813 8817 8818 8820 8821 8843 8848 8850 8851 8852 8853 8855 8860 8861 8862 8878 8885 89 8969 8988 8999 9000 9003 9004 9006 9007 9009 9016 9020 9021 9023 9027 9028 9030 9051 9090 9091 9096 9100 9106 9107 9109 9160 9191 9200 9208 9211 9299 9301 9302 9303 9305 9418 9527 9530 9595 9743 9800 9898 992 995 9991 9998 9999

Map

Whois Information

  • NetRange: 216.39.248.0 - 216.39.251.255
  • CIDR: 216.39.248.0/22
  • NetName: SHOCKVPN
  • NetHandle: NET-216-39-248-0-1
  • Parent: NET216 (NET-216-0-0-0-0)
  • NetType: Direct Allocation
  • OriginAS:
  • Organization: Shock VPN LLC (SVL-50)
  • RegDate: 2021-10-04
  • Updated: 2021-10-04
  • Ref: https://rdap.arin.net/registry/ip/216.39.248.0
  • OrgName: Shock VPN LLC
  • OrgId: SVL-50
  • Address: 30 N Gould Street, Suite 22170
  • City: Sheridan
  • StateProv: WY
  • PostalCode: 82801
  • Country: US
  • RegDate: 2021-06-29
  • Updated: 2021-10-12
  • Ref: https://rdap.arin.net/registry/entity/SVL-50
  • OrgNOCHandle: NOC33325-ARIN
  • OrgNOCName: Network Operations Center
  • OrgNOCPhone: +1-307-655-6727
  • OrgNOCEmail: [email protected]
  • OrgNOCRef: https://rdap.arin.net/registry/entity/NOC33325-ARIN
  • OrgTechHandle: SUPPO2327-ARIN
  • OrgTechName: Support Department
  • OrgTechPhone: +1-307-655-6727
  • OrgTechEmail: [email protected]
  • OrgTechRef: https://rdap.arin.net/registry/entity/SUPPO2327-ARIN
  • OrgAbuseHandle: ABUSE8190-ARIN
  • OrgAbuseName: Abuse Department
  • OrgAbusePhone: +1-307-655-6727
  • OrgAbuseEmail: [email protected]
  • OrgAbuseRef: https://rdap.arin.net/registry/entity/ABUSE8190-ARIN
  • NetRange: 216.39.248.0 - 216.39.251.255
  • CIDR: 216.39.248.0/22
  • NetName: GTHOST
  • NetHandle: NET-216-39-248-0-2
  • Parent: SHOCKVPN (NET-216-39-248-0-1)
  • NetType: Reallocated
  • OriginAS:
  • Organization: GTHost (GC-852)
  • RegDate: 2022-11-08
  • Updated: 2022-11-08
  • Ref: https://rdap.arin.net/registry/ip/216.39.248.0
  • OrgName: GTHost
  • OrgId: GC-852
  • Address: 427 S La Salle St, Suite 405
  • City: Chicago
  • StateProv: IL
  • PostalCode: 60605
  • Country: US
  • RegDate: 2017-12-22
  • Updated: 2022-08-17
  • Ref: https://rdap.arin.net/registry/entity/GC-852
  • OrgNOCHandle: KOLES7-ARIN
  • OrgNOCName: Kolesnyk, Taras
  • OrgNOCPhone: +1-905-549-9959
  • OrgNOCEmail: [email protected]
  • OrgNOCRef: https://rdap.arin.net/registry/entity/KOLES7-ARIN
  • OrgTechHandle: ADMIN6532-ARIN
  • OrgTechName: Admin
  • OrgTechPhone: +1-855-550-1010
  • OrgTechEmail: [email protected]
  • OrgTechRef: https://rdap.arin.net/registry/entity/ADMIN6532-ARIN
  • OrgNOCHandle: ADMIN6532-ARIN
  • OrgNOCName: Admin
  • OrgNOCPhone: +1-855-550-1010
  • OrgNOCEmail: [email protected]
  • OrgNOCRef: https://rdap.arin.net/registry/entity/ADMIN6532-ARIN
  • OrgTechHandle: KOLES7-ARIN
  • OrgTechName: Kolesnyk, Taras
  • OrgTechPhone: +1-905-549-9959
  • OrgTechEmail: [email protected]
  • OrgTechRef: https://rdap.arin.net/registry/entity/KOLES7-ARIN
  • OrgAbuseHandle: ADMIN6532-ARIN
  • OrgAbuseName: Admin
  • OrgAbusePhone: +1-855-550-1010
  • OrgAbuseEmail: [email protected]
  • OrgAbuseRef: https://rdap.arin.net/registry/entity/ADMIN6532-ARIN

Links to attack logs

anonymous-proxy-ip-list-2023-06-22