5.101.1.20 Threat Intelligence and Host Information
General
This page contains threat intelligence information for the IPv4 address 5.101.1.20 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.
Likely Malicious Host 🟠 55/100
Host and Network Information
-
Mitre ATT&CK IDs: T1078 - Valid Accounts, T1083 - File and Directory Discovery, T1098.004 - SSH Authorized Keys, T1105 - Ingress Tool Transfer, T1110.004 - Credential Stuffing, T1110 - Brute Force
-
Tags: Bruteforce, Brute-Force, cowrie, cyber security, ioc, malicious, Nextray, phishing, ssh, SSH
-
View other sources: Spamhaus VirusTotal
-
Contained within other IP sets: haley_ssh
- Country: Russia
- Network: AS34665 petersburg internet network ltd.
- Noticed: 50 times
- Protocols Attacked: ssh
- Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
- Passive DNS Results: download-tradingview.com litrazalilibe.xyz download-etoro.net download-etoro.org www.download-etoro.com download-etoro.com download-tradingview.net download-tradingview.org www.download-tradingview.org www.afterburners-msi.net www.overclocking-afterburner.org www.msiafterburner-download.net www.puncakesoftware.com www.msiafterburner-download.org www.jetbrainsidea.com www.intelijidea.com www.intelijidea.net www.afterburner-overclock.org www.afterburner-overclock.net software-google.com www.software-google.com afterburners-msi.net afterburners-msi.org www.afterburners-msi.com afterburners-msi.com download-cryptohopper.net download-cryptohopper.org www.download-cryptohopper.com download-cryptohopper.com downloads-msi.net downloads-msi.org software-obs.org download-msi.net downloads-msi.com software-obs.com download-msi.com software-obs.net www.software-obs.net obs-studio.org software-afterburner.net www.software-afterburner.net obs-software.org www.obs-software.org obs-software.net www.obs-software.net software-afterburner.org www.software-afterburner.org software-afterburner.com www.software-afterburner.com software-msi.net software-msi.org www.software-msi.org software-msi.com www.software-msi.com kombustor-msi.net www.kombustor-msi.org kombustor-msi.org kombustor-msi.com www.kombustor-msi.com www.obs-sproject.net obs-sproject.net www.obs-sproject.org obs-sproject.org www.obs-sproject.com obs-sproject.com intelijidea.com intelijidea.org www.intelijidea.org intelijidea.net jetbrainsidea.com afterburner-msidevelopment.com www.santacapitals.com santacapitals.com www.tatum-nft.com tatum-nft.com adobe-aftereffects.net www.adobe-aftereffects.net adobe-aftereffects.org www.adobe-aftereffects.org santatrading.com puncakesoftware.com www.afterburner-software.com afterburner-software.com msiafterburner-download.net msiafterburner-download.org msiafterburner-download.com www.msiafterburner-download.com afterburner-overclock.net afterburner-overclock.org overclocking-afterburner.org afterburner-overclock.com www.processlasso-download.org processlasso-download.org www.processlasso-download.net processlasso-download.net processlasso-download.com www.processlasso-download.com www.msiafterburner-overclocking.com msiafterburner-overclocking.com www.screamingfrog-download.com screamingfrog-download.com security-eye-software.org www.security-eye-software.org www.online-firsthorizon.org online-firsthorizon.org www.screamingfrog-download.org screamingfrog-download.org www.security-eye-download.com www.download-afterburnermsi.net download-afterburnermsi.net www.online-firsthorizon.com online-firsthorizon.com www.screamingfrog-download.net screamingfrog-download.net www.afterburnermsi-overclocking.org afterburnermsi-overclocking.org afterburnermsi-overclocking.net www.afterburnermsi-overclocking.net msiafterburner-overclocking.net www.msiafterburner-overclocking.net afterburner-gpuoverclocking.net www.afterburner-gpuoverclocking.net www.download-afterburner-msi.net afterburner-gpuoverclocking.org www.afterburner-gpuoverclocking.org overclocking-msi.org www.overclocking-msi.org overclocking-msi.net www.overclocking-msi.net www.overclocking-msi.com overclocking-msi.com overclocking-afterburner.com www.overclocking-afterburner.com www.overclocking-afterburner.net overclocking-afterburner.net afterburner-gpuoverclocking.com www.afterburner-gpuoverclocking.com download-afterburner-msi.net security-eye-download.com www.online-firsthorizon.net online-firsthorizon.net download-afterburner-msi.org www.download-afterburner-msi.org msiafterburner.org www.msiafterburner.org www.download-afterburner.org download-afterburner.org www.download-afterburnermsi.com download-afterburnermsi.com www.download-afterburner.net download-afterburner.net download-afterburner.com www.download-afterburner.com afterburnermsi-overclocking.com www.afterburnermsi-overclocking.com afterburnermsi-download.org www.afterburnermsi-download.org afterburnermsi-download.net www.afterburnermsi-download.net www.afterburner-msioverclocking.at afterburner-msioverclocking.at afterburnermsi-download.com www.afterburnermsi-download.com afterburner-msioverclocking.org www.afterburner-msioverclocking.org afterburner-msioverclocking.net www.afterburner-msioverclocking.net www.download-afterburner-msi.com www.download-msi.org download-msi.org download-afterburner-msi.com
Map
Whois Information
- inetnum: 5.101.1.0 - 5.101.1.255
- netname: PIN-DATACENTER-NET
- descr: s80.spb-dc’s objects
- country: RU
- admin-c: PIN44050-RIPE
- mnt-domains: MNT-PINSUPPORT
- tech-c: PIN44050-RIPE
- status: SUB-ALLOCATED PA
- mnt-routes: MNT-PINSUPPORT
- mnt-by: MNT-PINSUPPORT
- created: 2016-01-25T19:11:53Z
- last-modified: 2016-01-25T19:11:53Z
- role: PINDC Support and NOC Teams
- org: ORG-PINl1-RIPE
- address: 58 Malaya Balkanskaya
- address: Saint-Petersburg
- address: 192029
- address: RUSSIAN FEDERATION
- phone: +78126772525
- abuse-mailbox: abuse@pindc.ru
- nic-hdl: PIN44050-RIPE
- mnt-by: MNT-PIN
- mnt-by: MNT-PINSUPPORT
- created: 2013-06-08T06:08:16Z
- last-modified: 2020-12-16T10:58:34Z
- route: 5.101.1.0/24
- descr: PIN DC
- origin: AS34665
- mnt-by: MNT-PIN
- mnt-by: MNT-PINSUPPORT
- created: 2019-11-07T13:35:29Z
- last-modified: 2019-11-07T13:35:29Z
Links to attack logs
dolondon-ssh-bruteforce-ip-list-2022-08-30 bruteforce-ip-list-2022-06-25 bruteforce-ip-list-2022-05-19 ****** dosing-ssh-bruteforce-ip-list-2022-09-01 dolondon-ssh-bruteforce-ip-list-2022-07-16 dosing-ssh-bruteforce-ip-list-2022-09-21 dofrank-ssh-bruteforce-ip-list-2022-06-26 dofrank-ssh-bruteforce-ip-list-2022-09-11 vultrwarsaw-ssh-bruteforce-ip-list-2022-07-12 vultrparis-ssh-bruteforce-ip-list-2022-08-17 vultrparis-ssh-bruteforce-ip-list-2022-09-14 dofrank-ssh-bruteforce-ip-list-2022-06-18 bruteforce-ip-list-2022-08-29 dotoronto-ssh-bruteforce-ip-list-2022-09-03 vultrmadrid-ssh-bruteforce-ip-list-2022-08-17 dofrank-ssh-bruteforce-ip-list-2022-09-28 dotoronto-ssh-bruteforce-ip-list-2022-07-16 dofrank-ssh-bruteforce-ip-list-2022-08-22 vultrwarsaw-ssh-bruteforce-ip-list-2022-08-31 vultrmadrid-ssh-bruteforce-ip-list-2022-09-14 bruteforce-ip-list-2022-07-27 vultrmadrid-ssh-bruteforce-ip-list-2022-08-29 ****** vultrwarsaw-ssh-bruteforce-ip-list-2022-06-25 dolondon-ssh-bruteforce-ip-list-2022-06-21 ******
Share on: