45.66.230.105 Threat Intelligence and Host Information

Share on:

General

This page contains threat intelligence information for the IPv4 address 45.66.230.105 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Possibly Malicious Host 🟢 30/100

Host and Network Information

  • Tags: Botnet, Malicious IP, Port Scan, Skype, aws, blacklist, botnet, combinations, compromise ipv4, digital ocean, http, iocs, ipv4 port, linux, mirai, mirai botnet, port 22, port 80, scan, scanners, sha1, sha256, ssh, tcp, tcp/22, tcp/80, tsec
  • View other sources: Spamhaus VirusTotal

  • Country: Bulgaria
  • Network: AS397423 tier.net technologies llc
  • Noticed: 1 times
  • Protcols Attacked: ssh
  • Countries Attacked: Canada, Singapore, Spain, United States of America

Malware Detected on Host

Count: 5 c74261bf8664d753249c1b6f613798dbd00d3f83bf6564fe7a1da2013bdb8968 92f7e66f63941c5aec8fdd987d1e72a178da99e347941f92d434d61437bf5526 819643f09ca5473173d73ce12d15e3bf36c0fa8f803134b99dd65af79329c5d7 df60a16224430bd3c9113c870d0448b6f30bedf4b0fc6026945b82023f4eab98 90a1b0edb95f9eb75402ac65073554a1c79011d7b3bfc3e9ee4cc7a532b4aff3

Open Ports Detected

21 3306 3389

Map

Whois Information

  • inetnum: 45.66.230.0 - 45.66.230.255
  • netname: SERVERION_BV-NET
  • org: ORG-DCB8-RIPE
  • country: NL
  • admin-c: SB27731-RIPE
  • tech-c: SB27731-RIPE
  • mnt-domains: mnt-nl-descapital-1
  • mnt-lower: mnt-nl-descapital-1
  • mnt-routes: mnt-nl-descapital-1
  • status: ASSIGNED PA
  • mnt-by: MNT-NETERRA
  • created: 2022-12-13T14:35:09Z
  • last-modified: 2022-12-13T14:35:09Z
  • organisation: ORG-DCB8-RIPE
  • org-name: Des Capital B.V.
  • country: NL
  • org-type: LIR
  • address: Krammer 8
  • address: 3232HE
  • address: Brielle
  • address: NETHERLANDS
  • phone: +31851308338
  • phone: +13023803902
  • admin-c: AA35882-RIPE
  • tech-c: TA7409-RIPE
  • abuse-c: AR60082-RIPE
  • mnt-ref: mnt-nl-descapital-1
  • mnt-ref: RELCOMGROUP-EXT-MNT
  • mnt-ref: FREENET-MNT
  • mnt-ref: MNT-NETERRA
  • mnt-ref: MNT-MAYAK
  • mnt-ref: bg-mcreative-1-mnt
  • mnt-ref: mnt-bg-mconsulting15-1
  • mnt-ref: bg-mconsulting-1-mnt
  • mnt-ref: MNT-MCONSULTING
  • mnt-ref: mnt-bg-ccomp-1
  • mnt-by: RIPE-NCC-HM-MNT
  • mnt-by: mnt-nl-descapital-1
  • created: 2020-03-17T15:00:52Z
  • last-modified: 2022-09-26T13:22:34Z
  • mnt-ref: AZERONLINE-MNT
  • mnt-ref: interlir-mnt
  • role: Serverion B.V.
  • address: Krammer 8
  • address: 3232 HE Brielle
  • address: Netherlands
  • phone: +31851308333
  • org: ORG-DCB8-RIPE
  • abuse-mailbox: [email protected]
  • nic-hdl: SB27731-RIPE
  • mnt-by: mnt-com-serverion
  • created: 2020-03-17T15:49:34Z
  • last-modified: 2020-03-17T15:52:30Z

Links to attack logs

dosing-ssh-bruteforce-ip-list-2023-06-09 dotoronto-ssh-bruteforce-ip-list-2023-06-10