46.101.230.11 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 46.101.230.11 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Likely Malicious Host 🟠 65/100

Host and Network Information

  • Mitre ATT&CK IDs: T1078 - Valid Accounts, T1083 - File and Directory Discovery, T1098.004 - SSH Authorized Keys, T1105 - Ingress Tool Transfer, T1110.004 - Credential Stuffing, T1110 - Brute Force

  • Tags: 0xBFKX, brute force, bruteforce, Bruteforce, Brute-Force, cowrie, cyber security, fail2ban, ioc, malicious, Nextray, phishing, port 22, rdp, scanners, ssh, SSH, tcp/22, vultr

  • JARM: 27d27d27d00027d00042d43d00041df04c41293ba84f6efe3a613b22f983e6

  • View other sources: Spamhaus VirusTotal

  • Country: Germany
  • Network:
  • Noticed: 50 times
  • Protocols Attacked: ssh
  • Countries Attacked: Australia, Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
  • Passive DNS Results: www.do16.dev.deploy.devops.rebrain.srwx.net do16.dev.deploy.devops.rebrain.srwx.net 46-101-230-11.ipv4.staticdns1.io

Open Ports Detected

100 10000 10001 10002 10003 10011 10017 10020 10022 10023 10027 10028 10030 10033 10034 10035 10036 10044 10046 10047 1012 1013 10134 102 1022 1023 1024 10243 1027 1028 104 10443 10444 10445 106 10909 10911 10935 110 11002 111 1111 11111 11112 11210 11211 113 11300 11434 1200 1207 121 122 1234 1235 1311 1337 1343 1344 135 1400 1414 143 1433 1443 1515 1521 1604 1723 1741 1800 1801 1820 1830 1911 1925 1926 1935 2000 2002 2003 2008 2010 2031 21 2101 2108 2121 22 2200 2201 2202 2209 221 2221 2222 2226 23 2320 2323 2332 234 2345 24 2404 2423 2433 2444 25 26 2626 2628 2806 3001 3005 3010 3013 3047 3103 3104 3105 3107 3108 311 3110 3112 3114 3117 3118 3120 3126 3128 3130 3137 3139 314 3140 3141 3143 3146 3301 3310 3333 3341 3342 3401 3403 3410 3443 3503 3522 3530 3541 3841 3922 4000 4002 4021 4022 4023 4040 4100 4118 4147 4242 4243 4244 427 4321 4344 4401 443 4433 4434 4436 4437 4438 444 4443 4444 4447 445 4505 4506 4523 4531 4602 4646 4734 4808 4840 4911 4933 5000 5001 5005 5006 5007 5009 5010 502 5025 503 5100 513 5135 515 5201 5222 5228 5234 5238 5241 5243 5245 5321 5400 541 5431 5432 5435 5439 5500 5601 5602 5605 5800 5801 5804 5822 5900 5901 5904 5910 5912 5914 5919 5920 5938 6000 6001 6002 6003 6004 6007 6009 6011 6020 6021 6022 631 636 6400 6405 6433 6440 6443 6500 6503 6510 6512 6544 66 6600 6603 6605 6633 6700 700 7000 7001 7002 7004 7005 7006 7010 7014 7015 7018 7022 7100 7218 7302 7401 7415 7434 7441 7443 7535 7547 7634 7801 79 80 800 8000 8001 8006 8008 8009 801 8010 8011 8013 8015 8019 8021 8027 8030 8031 8032 8033 8037 8038 8042 8044 8046 8047 805 8080 8102 8103 811 8110 8111 8112 8117 8123 8126 8127 8132 8133 8137 8139 8140 8142 8143 8144 8145 8147 8200 8230 8243 831 832 8322 8333 8334 8402 8403 8405 8406 8407 8408 8410 8412 8414 8415 8422 8427 8430 8433 8501 8513 8514 8515 8519 8520 8524 8525 8526 8531 8544 8545 8622 8637 8640 8701 8702 8707 8708 8723 8724 8732 8733 8745 88 8800 8802 8805 8807 8808 8810 8812 8822 8827 8831 8834 8844 8845 888 8901 8908 8910 8911 8912 9000 9002 9004 9005 9008 9009 9019 902 9021 9026 9027 9029 9030 9031 9032 9033 9035 9037 9038 9040 9042 9047 9100 9103 9104 9105 9107 9109 9114 9116 9120 9125 9128 9134 9144 9145 9147 9200 9201 9206 9207 9213 9216 9217 9219 9223 9226 9230 9236 9241 9303 9304 9307 9311 9315 9333 9418 943 9433 9441 9443 9444 9446 9501 9527 9529 9530 9532 9600 9611 9633 9710 9711 9734 9800 9804 9900 9901 9909 9918 9929 9930 9939 9943 9944 9999

CVEs Detected

CVE-2009-2940 CVE-2009-3720 CVE-2020-29396 CVE-2021-32052 CVE-2023-27043 CVE-2023-30861 CVE-2023-36632 CVE-2024-6232 CVE-2024-7592 CVE-2024-9287

Map

Whois Information

  • inetnum: 46.101.128.0 - 46.101.255.255
  • abuse-c: AD10778-RIPE
  • netname: DIGITALOCEAN
  • country: DE
  • admin-c: PT7353-RIPE
  • tech-c: PT7353-RIPE
  • status: ASSIGNED PA
  • mnt-by: digitalocean
  • created: 2020-04-01T22:29:11Z
  • last-modified: 2020-04-01T22:29:11Z
  • person: DigitalOcean Network Operations
  • address: 105 Edgeview Drive, Suite 425
  • address: Broomfield, Colorado 80021
  • address: United States of America
  • phone: +16468274366
  • nic-hdl: PT7353-RIPE
  • mnt-by: digitalocean
  • created: 2015-03-11T16:37:07Z
  • last-modified: 2025-04-11T19:39:01Z
  • org: ORG-DOI2-RIPE

Links to attack logs

dofrank-ssh-bruteforce-ip-list-2023-06-22 digitaloceanlondon-ssh-bruteforce-ip-list-2023-10-07 dofrank-ssh-bruteforce-ip-list-2023-07-10 digitaloceanfrankfurt-ssh-bruteforce-ip-list-2023-10-31 ****** vultrwarsaw-ssh-bruteforce-ip-list-2023-09-26 digitaloceanfrankfurt-ssh-bruteforce-ip-list-2023-11-04 dosing-ssh-bruteforce-ip-list-2023-07-06 bruteforce-ip-list-2023-07-15 digitaloceantoronto-ssh-bruteforce-ip-list-2023-12-10 digitaloceantoronto-ssh-bruteforce-ip-list-2023-08-08 vultrparis-ssh-bruteforce-ip-list-2023-08-27 digitaloceanlondon-ssh-bruteforce-ip-list-2023-12-06 vultrwarsaw-ssh-bruteforce-ip-list-2023-10-22 digitaloceantoronto-ssh-bruteforce-ip-list-2023-11-26 vultrmadrid-ssh-bruteforce-ip-list-2023-07-04 digitaloceanfrankfurt-ssh-bruteforce-ip-list-2023-11-23 digitaloceanfrankfurt-ssh-bruteforce-ip-list-2023-11-12 digitaloceansingapore-ssh-bruteforce-ip-list-2023-12-12 digitaloceansingapore-ssh-bruteforce-ip-list-2023-12-21 digitaloceanlondon-ssh-bruteforce-ip-list-2023-10-17 digitaloceantoronto-ssh-bruteforce-ip-list-2023-09-15 ****** dofrank-ssh-bruteforce-ip-list-2023-07-04 bruteforce-ip-list-2023-07-13 ****** digitaloceanfrankfurt-ssh-bruteforce-ip-list-2024-01-05

Share on: