5.56.132.116 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 5.56.132.116 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

🟡 Low Risk — 40/100

Geographic Location

Host and Network Information

  • View other sources: Spamhaus VirusTotal Shodan AbuseIPDB
  • Country: Iran
  • Noticed: 10 times
  • Protocols Attacked: ssh
  • Countries Attacked: Australia, Finland, France, Germany, Poland, United States of America
  • Open Ports: 21, 25, 465
  • Tor Node: No

Tags

  • 01.10.2025
  • 2025
  • brute force
  • Bruteforce
  • Brute-Force
  • cisco
  • cowrie
  • HoneyNet Connect
  • honeytrap
  • LAMP
  • malicious
  • scan
  • sftp
  • sip
  • sipvicious
  • ssh
  • SSH

MITRE ATT&CK TTPs

  • T1110 - Brute Force
  • T1595 - Active Scanning

Passive DNS

  • optimistic-elgamal.5-56-132-116.plesk.page

Attack Log References

Whois Information

inetnum: 5.56.132.0 - 5.56.132.255 org: ORG-MDPM1-RIPE netname: MobinhostInfrastructure country: IR mnt-routes: dpmobin-mnt mnt-lower: dpmobin-mnt geoloc: 35.73999704 51.37166518 mnt-domains: dpmobin-mnt admin-c: SDM491-RIPE tech-c: SDM491-RIPE status: SUB-ALLOCATED PA mnt-by: dpmobin-mnt mnt-by: ir-dadepardazimobinhost-1-mnt mnt-by: mnt-ir-dpmobin-1 mnt-by: SubstructionLTD created: 2025-02-10T20:17:43Z last-modified: 2025-02-10T20:35:29Z organisation: ORG-MDPM1-RIPE org-name: MobinInfrastructure Sub geoloc: 35.73999704 51.37166518 descr: Sub 5.79.87 org-type: OTHER address: Gisha St , Chamran Highway ,Tehran abuse-c: MA22148-RIPE mnt-ref: SubstructionLTD phone: +982172308 mnt-by: SubstructionLTD mnt-by: MobinInfrastructure mnt-by: dpmobin-mnt created: 2018-11-05T06:45:37Z last-modified: 2025-02-10T19:49:40Z person: Seyed Davoud Montazeri address: 1447794164 address: Tehran address: IRAN, ISLAMIC REPUBLIC OF phone: +982172308 nic-hdl: SDM491-RIPE mnt-by: mnt-ir-dpmobin-1 mnt-by: MobinInfrastructure mnt-by: ir-dadepardazimobinhost-1-mnt mnt-by: ir-dadepardazimobinhost-1 mnt-by: dpmobin-mnt mnt-by: DPMobin created: 2019-07-11T11:13:51Z last-modified: 2023-03-18T10:40:01Z route: 5.56.132.0/24 origin: AS204544 mnt-by: Substruction mnt-by: SubstructionLTD mnt-by: dpmobin-mnt created: 2023-03-18T10:51:26Z last-modified: 2025-02-10T20:59:02Z route: 5.56.132.0/24 descr: Mobin Infrastructure origin: as208555 mnt-by: Substruction mnt-by: SubstructionLTD mnt-by: dpmobin-mnt created: 2020-04-04T10:41:43Z last-modified: 2025-02-10T20:59:09Z route: 5.56.132.0/24 origin: AS51026 org: ORG-DPMC2-RIPE mnt-by: dpmobin-mnt mnt-by: SubstructionLTD mnt-by: Substruction created: 2024-05-21T08:42:28Z last-modified: 2025-02-10T20:59:46Z organisation: ORG-DPMC2-RIPE org-name: Dade Pardazi Mobinhost Co LTD country: IR org-type: LIR address: Mobinhost , No 81 , Jalal Al-e-Ahmad St, Koye Nasr ,Tehran address: 1446665874 address: Tehran address: IRAN, ISLAMIC REPUBLIC OF phone: +982172308 admin-c: SDM491-RIPE tech-c: SDM491-RIPE abuse-c: AR53866-RIPE mnt-ref: dpmobin-mnt mnt-by: RIPE-NCC-HM-MNT mnt-by: dpmobin-mnt created: 2019-07-11T11:13:52Z last-modified: 2020-12-16T13:24:37Z