45.58.133.10 Threat Intelligence and Host Information

Share on:

General

This page contains threat intelligence information for the IPv4 address 45.58.133.10 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Potentially Malicious Host 🟡 32/100

Host and Network Information

  • Mitre ATT&CK IDs: T1400 - Modify System Partition, T1401 - Device Administrator Permissions
  • Tags: Malicious IP, Nextray, as16276 ovh, as46844 stbgp, blacklist, botnet, bruteforce, coin, cyber security, dloader, dnschanger, eternalblue, forshare, great britain, http, ioc, ipv4, kingdom, malicious, miner, mirai, moldova, mssql, neksminer, nmap, pcshare, phishing, port-scan, republic, sas france, sas germany, sas united, scan, smb, suspicious, tcp, united, venik, winrar sfx, wmi injector, xmrig miner

  • View other sources: Spamhaus VirusTotal

  • Country: United States
  • Network: AS46844 sharktech
  • Noticed: 1 times
  • Protcols Attacked: SSH
  • Countries Attacked: Australia, Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
  • Passive DNS Results: wmi.mykings.top xmr.5b6b7b.ru wmi.oo000oo.club

Malware Detected on Host

Count: 2 7a008fee9525be3779bab30d35ebc888fbc2aa7e8c81c5e05532942daa47bc5b 13abfcb768df22d58fde457ca2ea082786a0968902439bc7244215682966fe9e

Map

Whois Information

  • NetRange: 45.58.128.0 - 45.58.191.255
  • CIDR: 45.58.128.0/18
  • NetName: SHARK-7
  • NetHandle: NET-45-58-128-0-1
  • Parent: NET45 (NET-45-0-0-0-0)
  • NetType: Direct Allocation
  • OriginAS: AS46844
  • Organization: Sharktech (SHARK-7)
  • RegDate: 2015-02-06
  • Updated: 2015-02-06
  • Comment: FOR ABUSE RELATED ENQUIRIES PLEASE CONTACT ABUSE AT SHARKTECH.NET
  • Ref: https://rdap.arin.net/registry/ip/45.58.128.0
  • OrgName: Sharktech
  • OrgId: SHARK-7
  • Address: 8560 S. Eastern Ave Suite 210
  • City: Las Vegas
  • StateProv: NV
  • PostalCode: 89120
  • Country: US
  • RegDate: 2012-01-20
  • Updated: 2022-11-30
  • Comment: FOR ABUSE RELATED QUESTIONS PLEASE EMAIL ABUSE AT SHARKTECH.NET
  • Ref: https://rdap.arin.net/registry/entity/SHARK-7
  • OrgTechHandle: NOC2002-ARIN
  • OrgTechName: Network Operations Center
  • OrgTechPhone: +1-844-706-7383
  • OrgTechEmail: [email protected]
  • OrgTechRef: https://rdap.arin.net/registry/entity/NOC2002-ARIN
  • OrgNOCHandle: NOC2002-ARIN
  • OrgNOCName: Network Operations Center
  • OrgNOCPhone: +1-844-706-7383
  • OrgNOCEmail: [email protected]
  • OrgNOCRef: https://rdap.arin.net/registry/entity/NOC2002-ARIN
  • OrgAbuseHandle: ABUSE1080-ARIN
  • OrgAbuseName: ABUSE Department
  • OrgAbusePhone: +1-702-425-9980
  • OrgAbuseEmail: [email protected]
  • OrgAbuseRef: https://rdap.arin.net/registry/entity/ABUSE1080-ARIN
  • NetRange: 45.58.128.0 - 45.58.191.255
  • CIDR: 45.58.128.0/18
  • NetName: ST-AMS
  • NetHandle: NET-45-58-128-0-2
  • Parent: SHARK-7 (NET-45-58-128-0-1)
  • NetType: Reassigned
  • OriginAS: AS46844
  • Customer: Sharktech Inc. (C09051178)
  • RegDate: 2022-11-30
  • Updated: 2022-11-30
  • Comment: FOR ABUSE RELATED QUESTIONS PLEASE EMAIL ABUSE AT SHARKTECH.NET
  • Ref: https://rdap.arin.net/registry/ip/45.58.128.0
  • CustName: Sharktech Inc.
  • Address: Lemelerbergweg 27
  • City: Amsterdam
  • StateProv:
  • PostalCode: 1101 AH
  • Country: NL
  • RegDate: 2022-11-30
  • Updated: 2022-11-30
  • Ref: https://rdap.arin.net/registry/entity/C09051178
  • OrgTechHandle: NOC2002-ARIN
  • OrgTechName: Network Operations Center
  • OrgTechPhone: +1-844-706-7383
  • OrgTechEmail: [email protected]
  • OrgTechRef: https://rdap.arin.net/registry/entity/NOC2002-ARIN
  • OrgNOCHandle: NOC2002-ARIN
  • OrgNOCName: Network Operations Center
  • OrgNOCPhone: +1-844-706-7383
  • OrgNOCEmail: [email protected]
  • OrgNOCRef: https://rdap.arin.net/registry/entity/NOC2002-ARIN
  • OrgAbuseHandle: ABUSE1080-ARIN
  • OrgAbuseName: ABUSE Department
  • OrgAbusePhone: +1-702-425-9980
  • OrgAbuseEmail: [email protected]
  • OrgAbuseRef: https://rdap.arin.net/registry/entity/ABUSE1080-ARIN

Links to attack logs

nmap-scanning-list-2020-11-29 mssql-bruteforce-ip-list-2020-11-29