51.79.85.22 Threat Intelligence and Host Information

Share on:

General

This page contains threat intelligence information for the IPv4 address 51.79.85.22 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Possibly Malicious Host 🟢 25/100

Host and Network Information

  • Tags: blacklist, bot, botnet, bruteforce, cyber security, ddos, digital ocean, ioc, malicious, Malicious IP, mirai, Nextray, phishing, scan, tcp, telnet, tsec

  • View other sources: Spamhaus VirusTotal

  • Country: Canada
  • Network: AS16276 ovh sas
  • Noticed: 1 times
  • Protcols Attacked: telnet
  • Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom, United Kingdom of Great Britain and Northern Ireland, United States of America
  • Passive DNS Results: cat-gen.cf greatstore.pro vps-3e59ad1c.vps.ovh.ca efsanecicek.com www.efsaneesnaf.com efsaneesnaf.com www.matbaayurdu.com wunderbarmarkt.de www.wunderbarmarkt.de stickeryurdu.com www.stickeryurdu.com ucundanbiraz.com www.ucundanbiraz.com matbaayurdu.com www.internetyurdu.com internetyurdu.com www.hatungiyim.com hatunavm.com hatungiyim.com www.hatunavm.com www.dogumgunudavetiyesi.com dogumgunudavetiyesi.com www.ekonomikesnaf.com ekonomikesnaf.com bayangiyimsepeti.com www.bayangiyimsepeti.com cvyurdu.com www.cvyurdu.com adanaelektriktamircisi.com www.adanaelektriktamircisi.com www.rscturmoil.com rscturmoil.com

Malware Detected on Host

Count: 1 5672c5bc14c5cb24173c5b0e3f79d018d08cd7a5d3745036d5e1d6b5e90875d3

Open Ports Detected

22 3306 443 80 8000

Map

Whois Information

  • inetnum: 51.79.0.0 - 51.79.255.255
  • netname: NON-RIPE-NCC-MANAGED-ADDRESS-BLOCK
  • descr: IPv4 address block not managed by the RIPE NCC
  • admin-c: IANA1-RIPE
  • tech-c: IANA1-RIPE
  • status: ALLOCATED UNSPECIFIED
  • mnt-by: RIPE-NCC-HM-MNT
  • created: 2019-01-10T16:01:31Z
  • last-modified: 2019-01-10T16:01:31Z
  • role: Internet Assigned Numbers Authority
  • address: see http://www.iana.org.
  • admin-c: IANA1-RIPE
  • tech-c: IANA1-RIPE
  • nic-hdl: IANA1-RIPE
  • mnt-by: RIPE-NCC-MNT
  • created: 1970-01-01T00:00:00Z
  • last-modified: 2001-09-22T09:31:27Z

Links to attack logs

** ** ** dolondon-telnet-bruteforce-ip-list-2023-03-17