45.79.5.134 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 45.79.5.134 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Potentially Malicious Host 🟡 35/100

Host and Network Information

  • Tags: blacklist, botnet, cyber security, ioc, malicious, Malicious IP, mirai, Nextray, phishing, scan, SIP, tcp, udp

  • View other sources: Spamhaus VirusTotal

  • Country: United States
  • Network:
  • Noticed: 35 times
  • Protocols Attacked: sip
  • Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
  • Passive DNS Results: digitaloutreachmarket.com digitaloutreachshopper.com digitaloutreachmarketplace.com watchgadgetlab.com trendydivafashions.com trendywomenwear.com timepiecetechgear.com clearsightlenses.com visiontechgear.com smartglassgear.com sneakerchicdesigns.com mensfashionzone.com gentsfashionwardrobe.com li1104-134.members.linode.com fastbebidas.com skyuniverses.net

Open Ports Detected

10000 10001 10004 10005 10018 10034 10084 10089 10090 10180 10181 10209 10225 10243 10250 10283 10443 10909 10934 11000 11112 11180 11300 11371 11434 11688 12000 12105 12114 12116 12122 12124 12136 12143 12150 12158 12159 12173 12177 12183 12188 12194 12200 12221 12223 12227 12251 12255 12266 12303 12309 12310 12312 12324 12327 12333 12341 12342 12347 12355 12363 12364 12381 12402 12416 12417 12422 12424 12436 12439 12440 12468 12470 12490 12498 12508 12522 12540 12541 12546 12547 12552 12553 12560 12564 12577 12578 12581 12583 12586 13443 13579 13780 14130 14147 14401 14407 14875 14896 14897 14905 15040 15044 15504 15555 15831 16021 16022 16025 16029 16036 16046 16050 16051 16059 16080 16093 16097 16992 16993 17010 18015 18031 18032 18046 18056 18074 18079 18081 18084 18105 18245 19000 19014 19071 19090 19998 20030 20070 20080 20082 20100 20121 20185 20443 20892 21025 21200 21246 21267 21294 21306 21308 21313 21329 21379 21443 22082 22556 22705 23023 23424 24084 25001 25105 25565 27015 28017 30000 30002 30003 30025 30701 30892 31001 32303 35000 35250 35531 38080 41800 44100 44158 44307 44308 44345 44399 44818 47000 47990 49080 49153 49682 49767 50005 50014 50050 50100 50112 51000 51106 51235 52200 52311 55000 55442 55554 57785 58532

Map

Whois Information

Links to attack logs

****** dofrank-sip-bruteforce-ip-list-2023-01-02 vultrwarsaw-sip-bruteforce-ip-list-2023-01-03 ****** ******

Share on: