31.14.115.193 Threat Intelligence and Host Information

Share on:

General

This page contains threat intelligence information for the IPv4 address 31.14.115.193 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Possibly Malicious Host 🟢 25/100

Host and Network Information

  • Mitre ATT&CK IDs: T1110 - Brute Force
  • Tags: brute force, Bruteforce, Brute-Force, ssh, SSH

  • View other sources: Spamhaus VirusTotal

  • Country: Iran
  • Network: AS25184 afranet
  • Noticed: 1 times
  • Protcols Attacked: ssh
  • Countries Attacked: Australia

Open Ports Detected

10001 102 10243 10250 1028 10443 10554 1099 11000 111 11112 11211 113 11300 11371 1200 12000 1234 12345 1311 1337 135 14265 1433 1471 1515 1521 1599 1604 16992 16993 1723 175 179 1800 1801 18081 18245 1911 1926 1935 1962 199 1990 2000 20000 2001 2008 2018 20256 2030 2049 2052 20547 2067 2086 2087 2096 21025 2121 2122 21379 2154 22 221 2222 23424 2375 2376 2404 25001 25105 2548 2572 26 264 27015 27017 28017 3000 3001 3059 3063 3075 3085 3108 311 3118 3128 32400 3260 3269 32764 3299 3306 33060 3388 3389 3402 3542 3551 3689 37 37215 37777 389 4000 4040 4063 4117 41800 4242 427 43 4321 4369 44158 444 4443 4444 44818 4500 4506 4567 4643 465 4664 4782 47990 4840 4848 49 4911 49153 4949 50000 5001 5003 50050 5006 5007 50070 51106 51235 5201 5209 5222 52869 53 5357 5432 55000 554 55443 5555 5560 5567 5604 5672 5800 5801 5858 58749 5900 5901 5908 5910 593 5938 5984 5985 6000 60001 6001 60010 6002 6004 6036 6080 61616 62078 631 6379 6580 6603 6653 666 6666 6667 6668 6697 70 7001 7003 7010 7081 7415 7474 7548 7657 777 7777 789 80 8000 8001 8008 8009 8010 8015 8043 8060 8064 8083 8086 8087 8090 8091 8094 8098 8099 81 8100 8111 8112 8126 8139 8140 8180 8182 82 8200 8291 83 8383 84 8410 8415 8430 8431 8443 8446 86 8649 87 8728 873 8766 88 880 8800 8801 8823 8839 8840 8880 8899 8999 90 9000 9002 9009 9012 902 9020 9046 9051 9080 9084 9089 9090 9094 91 9110 9111 9160 9191 9217 9222 9295 9305 9306 9310 95 9530 9595 9600 9704 9761 9800 9869 990 993 9944 995 9981 9998 9999

Map

Whois Information

  • inetnum: 31.14.112.0 - 31.14.127.255
  • netname: IR-AFRANET-20110418
  • org: ORG-AA32-RIPE
  • country: IR
  • admin-c: AFR81189-RIPE
  • tech-c: AFR81189-RIPE
  • status: ALLOCATED PA
  • mnt-by: RIPE-NCC-HM-MNT
  • mnt-by: AFRA-MNT-NESH-1
  • mnt-routes: AFRA-MNT-NESH-1
  • mnt-domains: AFRA-MNT-NESH-1
  • created: 2014-09-17T16:00:16Z
  • last-modified: 2019-04-15T05:49:32Z
  • organisation: ORG-AA32-RIPE
  • org-name: Afranet
  • country: IR
  • org-type: LIR
  • address: 7th Floor, No. 12, Sahand Street, Beheshti Avenue
  • address: 15598-36111
  • address: Tehran
  • address: IRAN, ISLAMIC REPUBLIC OF
  • phone: +982181180000
  • fax-no: +982188737133
  • mnt-ref: RIPE-NCC-HM-MNT
  • mnt-ref: AFRA-MNT-NESH-1
  • mnt-by: RIPE-NCC-HM-MNT
  • mnt-by: AFRA-MNT-NESH-1
  • admin-c: MRA99-RIPE
  • abuse-c: AFAR1000-RIPE
  • created: 2004-04-17T11:28:03Z
  • last-modified: 2020-12-16T13:43:18Z
  • person: Afranet Co
  • address: No 12 ,Sahand St,Beheshti Ave,Tehran, Iran
  • mnt-by: AFRA-MNT-NESH-1
  • phone: +98-21-81180
  • nic-hdl: AFR81189-RIPE
  • created: 2009-10-17T10:58:44Z
  • last-modified: 2018-02-12T10:21:00Z
  • route: 31.14.112.0/20
  • descr: Afranet Co
  • origin: AS25184
  • mnt-by: AFRA-MNT-NESH-1
  • created: 2014-09-20T04:41:36Z
  • last-modified: 2014-09-20T04:41:36Z

Links to attack logs

digitaloceantoronto-ssh-bruteforce-ip-list-2023-11-25