45.91.101.18 Threat Intelligence and Host Information

Share on:

General

This page was generated as a result of this host being detected actively attacking or scanning another host. See below for information related to the host network, location, number of days noticed, protocols attacked and other information including reverse DNS and whois.

Known Malicious Host 🔴 80/100

Host and Network Information

  • Mitre ATT&CK IDs: T1078 - Valid Accounts, T1083 - File and Directory Discovery, T1098.004 - SSH Authorized Keys, T1105 - Ingress Tool Transfer, T1110 - Brute Force, T1110.004 - Credential Stuffing
  • Tags: Nextray, TOR, VPN, awsbah, bruteforce, cowrie, cyber security, ioc, la, lafusioncenter, louisiana, malicious, phishing, probing, redis, scanning, ssh, webscan, webscanner bruteforce web app attack
  • View other sources: Spamhaus VirusTotal
  • Contained within other IP sets: sblam, stopforumspam_180d, stopforumspam_365d, tor_exits, tor_exits_1d, tor_exits_30d, tor_exits_7d

  • Country: Germany
  • Network: AS48314 michael sebastian schinzel trading as ip-projects gmbh & co. kg
  • Noticed: 50 times
  • Protcols Attacked: redis
  • Countries Attacked: Bahrain, Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
  • Passive DNS Results: backup.arvidortwig.de

Malware Detected on Host

Count: 27 f046b65739764aa74d38bfaf666094d45ad087b3bc6430c5a19c599b1735a54e 949c6737d24f301ca7ea79dfd0936614bb3158ca66be70a842e7e0a7510d8616 7cf34eadb163afa46e8936bc8a37c38d51a646079d39897397ab6bd3fd527f9a 25837be752586ccedb7da8ab32d563a7baa799d91ca69067f0b8acc14dfc0923 c257a3fb6cfed8c4d106bdfe865969d15a2f8fac9f1fa69498dde215e02207d2 f2d2ac74db5bbbb4afb1818bf345019c15a5688b574e53c5f93aa41b1df353c4 7ddef1c1c6c94febf3565291d7f4604f550144fd90a33b8c7445626ac29256d3 a7e484d7cdbcb39538cd203c269d39b15d59f1703cf73429ca67128bb66c0a00 4c84095d79415b4eb846b08183204a3e8a6b1b551657d42d2476ca9345276622 3170af6cd2acf26572482407adc0c9827a5b1383505e83033b15f261a68290be

Open Ports Detected

3389

Map

Whois Information

  • inetnum: 45.91.101.0 - 45.91.101.255
  • netname: IPP-NET-243
  • descr: IP-Projects GmbH & Co. KG
  • country: de
  • language: de
  • admin-c: MS45042-RIPE
  • tech-c: MS45042-RIPE
  • status: ASSIGNED PA
  • mnt-by: mnt-de-verwaltung16-ipp-1
  • mnt-routes: de-ip-projects-1-mnt
  • mnt-routes: mnt-de-verwaltung18-ipp-1
  • created: 2019-12-23T07:18:17Z
  • last-modified: 2021-10-24T05:56:02Z
  • person: Michael Schinzel
  • address: IP-Projects GmbH & Co. KG
  • address: Am Vogelherd 14
  • address: D-97295 Waldbrunn
  • phone: +49 (0)9306 - 76499-0
  • fax-no: +49 (0)9306 - 76499-15
  • nic-hdl: MS45042-RIPE
  • mnt-by: de-ip-projects-1-mnt
  • created: 2018-01-05T11:12:28Z
  • last-modified: 2018-01-05T11:12:28Z
  • route: 45.91.101.0/24
  • descr: IP-Routing by www.ip-projects.de
  • origin: AS48314
  • mnt-by: de-ip-projects-1-mnt
  • created: 2021-08-05T15:22:31Z
  • last-modified: 2021-10-24T05:56:24Z

Links to attack logs

awsbah-redis-bruteforce-ip-list-2021-09-16 **