45.143.220.79 Threat Intelligence and Host Information

Share on:

General

This page contains threat intelligence information for the IPv4 address 45.143.220.79 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Potentially Malicious Host 🟡 32/100

Host and Network Information

  • Mitre ATT&CK IDs: T1110 - Brute Force
  • Tags: Bruteforce, Nextray, SSH, Telnet, bruteforce, cowrie, cyber security, ioc, malicious, phishing, ssh, telnet, tsec
  • View other sources: Spamhaus VirusTotal

  • Country: Belize
  • Network: AS213371 squitter networks
  • Noticed: 1 times
  • Protcols Attacked: SSH
  • Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America

Malware Detected on Host

Count: 7 bd6aada208d783f9b3124f74638ba48608fcdc91102d5ada49440f44ab23210d 08e74017fdbcc63ea26df4781392f7da85e95fff2b3717a9b4b6550ea3fdb1ff d931499e38b471a1c5f67d55c20f377183f4e1c98bfa1f93351aa6124ce95b3f 3d7786e82cb22b447291f3c855827a350f0806cd188c880ee948cc53f369ce50 1d6e3b62bce5ee0b654379a93098160d51e5998c57827dd9bdd16ebfcaf32c7e 6ea0a47079b97269d602a8746bc4760fa869708c648f287e6460f0bffa94403f bddb826b7d99669ae7e194dd269f048f2fd64d376d9d6f7c801c70e32cdc8c4e

Open Ports Detected

80 8443

CVEs Detected

CVE-2014-0160

Map

Whois Information

  • inetnum: 45.143.220.0 - 45.143.220.255
  • netname: ABC-NL-DSRV
  • country: NL
  • geoloc: 52.370216 4.895168
  • geofeed: https://gist.githubusercontent.com/myweblimited/d5e6acaa3e15c7d2abb768ad4e7a0b1f/raw/2612a56c6ef4368f85021c449e3219c96ca64ae5/mywebgeofeed.csv
  • admin-c: SN8949-RIPE
  • tech-c: SN8949-RIPE
  • org: ORG-SQTR1-RIPE
  • status: ASSIGNED PA
  • mnt-by: SQUITTER-MNT
  • created: 2019-10-13T10:27:10Z
  • last-modified: 2023-05-29T15:58:17Z
  • organisation: ORG-SQTR1-RIPE
  • org-name: ABC Consultancy
  • country: IN
  • org-type: OTHER
  • address: Netherlands
  • geoloc: 52.3702 4.8952
  • abuse-c: SN8949-RIPE
  • mnt-ref: SQUITTER-MNT
  • mnt-ref: PREFIXBROKER-MNT
  • mnt-by: SQUITTER-MNT
  • created: 2020-04-13T10:54:36Z
  • last-modified: 2022-12-01T17:26:41Z
  • role: ABC Consultancy
  • address: Netherlands
  • abuse-mailbox: [email protected]
  • nic-hdl: SN8949-RIPE
  • mnt-by: SQUITTER-MNT
  • created: 2020-04-13T10:51:05Z
  • last-modified: 2020-12-09T11:35:47Z
  • route: 45.143.220.0/24
  • origin: AS213371
  • mnt-by: SQUITTER-MNT
  • created: 2020-12-09T12:59:34Z
  • last-modified: 2020-12-09T12:59:46Z

Links to attack logs

bruteforce-ip-list-2020-07-04