5.254.62.54 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 5.254.62.54 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Potentially Malicious Host 🟡 40/100

Host and Network Information

  • Tags: - 239.255.255.250.pdf, Nextray, cyber security, ioc, malicious, phishing

  • JARM: 15d3fd16d29d29d00042d43d0000009ec686233a4398bea334ba5e62e34a01

  • View other sources: Spamhaus VirusTotal

Malware Detected on Host

Count: 927 9dd88393b8f00eff7818b7ae16e5673c8d37e27cdd710f8f82d236e001843570 eb1508fe8260e9c6ffddb5183f9041f0af1ea0ecad4e2a9ae22ccd8d9d6896ea c5b0f5cace7dac866dae6d827d67acfd7a318868f455ac3cfb24a62501e407ec e3e1cee22149dec1c01005daae85a5ad360caae830fc9fbef1ee32b77ae0ddba a0e7943fe742394a4a1b6f3964079d06c7ca54cd45e2b77a787c69f0ce98bcc3 a1f2b7de108f5017de781eeca9c4fbc0c6bafd69e292f2f4b2ea1daa5fafafec b19a377dd6ef40f9cde110878810da8c4946b58b5bbed86323721d734fb78e9c ef8873b9184ca994bc300346b203897a540cfdeefc70b0ee5e6e3444c0a3678e 5b9c4030d163170bb9619cbb83b6ce3f8476477b939f33cbb646f9b82ea837d8 445b0d44cbdcc2bde81f5a60c41c0e557ed8806d601ea245011f77ff3fa4aee4

Open Ports Detected

110 143 2082 2083 2086 2087 2095 2096 21 22 3306 443 465 53 587 80 993 995

CVEs Detected

CVE-2016-20012 CVE-2017-15906 CVE-2018-15473 CVE-2018-15919 CVE-2018-20685 CVE-2019-6109 CVE-2019-6110 CVE-2019-6111 CVE-2020-14145 CVE-2020-15778 CVE-2021-36368 CVE-2021-41617 CVE-2023-38408

Map

Whois Information

  • inetnum: 5.254.62.52 - 5.254.62.55
  • netname: NaoServers
  • org: ORG-NS578-RIPE
  • country: US
  • geoloc: 34.058392 -118.235656
  • admin-c: NSS90-RIPE
  • tech-c: NSS90-RIPE
  • abuse-c: ACRO44427-RIPE
  • status: ASSIGNED PA
  • mnt-by: VOXILITY-MNT
  • created: 2021-11-12T06:14:36Z
  • last-modified: 2021-11-12T06:14:36Z
  • organisation: ORG-NS578-RIPE
  • org-name: Nao Servers
  • org-type: OTHER
  • address: 333 Fremont Street
  • abuse-c: ACRO44427-RIPE
  • mnt-ref: VOXILITY-MNT
  • mnt-by: VOXILITY-MNT
  • created: 2021-11-12T06:13:02Z
  • last-modified: 2021-11-12T06:13:02Z
  • person: Nao Server Support
  • address: 333 Fremont Street
  • phone: +17402920198
  • nic-hdl: NSS90-RIPE
  • mnt-by: VOXILITY-MNT
  • created: 2021-11-12T06:11:35Z
  • last-modified: 2021-11-12T06:11:35Z
  • route: 5.254.62.0/24
  • origin: AS3223
  • mnt-by: VOXILITY-MNT
  • created: 2017-09-13T07:28:04Z
  • last-modified: 2017-09-13T07:28:04Z
  • descr: Voxility.net
Share on: