54.246.219.149 Threat Intelligence and Host Information

Share on:

General

This page contains threat intelligence information for the IPv4 address 54.246.219.149 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Possibly Malicious Host 🟢 10/100

Host and Network Information

  • View other sources: Spamhaus VirusTotal

  • Country: Ireland
  • Network: AS16509 amazon.com inc
  • Noticed: 1 times
  • Protcols Attacked: Anonymous Proxy

Malware Detected on Host

Count:

Open Ports Detected

10000 10001 10134 10554 11000 11112 11210 12000 14265 16010 18081 18245 19000 20000 3128 3299 3301 3306 3310 3311 3407 3412 3443 3479 3503 3542 3548 3549 3550 3551 3555 3561 3563 3567 3569 3690 3749 3780 3791 3793 3952 4100 4282 4369 4433 4506 4567 4664 4848 4911 5001 5003 5005 5007 5025 5050 5080 5090 5150 5172 5201 5209 5222 5357 5494 5560 5567 5591 5596 5602 5603 5672 5800 5853 5858 5900 5901 5908 5909 5938 5984 6002 6003 6005 6009 6102 6262 6379 6543 6561 6565 6580 6590 6603 6653 6664 6668 6697 6955 6998 7001 7218 7401 7415 7443 7474 7500 7634 7657 7676 7776 7777 7779 7788 7989 7998 80 8001 8002 8003 8005 8008 8010 8020 8026 8028 8030 8032 8033 8035 8037 8041 8043 8044 8046 8047 8049 8053 8054 8055 8066 8069 8071 8081 8089 8090 8091 8098 8108 8109 8111 8112 8126 8143 8159 8181 8184 8200 8222 8237 8239 8252 8334 8383 8401 8405 8412 8413 8416 8418 8420 8423 8429 8431 8433 8442 8445 8447 8500 8513 8545 8586 8590 8602 8621 8637 8700 8765 8767 8779 8788 8791 8802 8807 8809 8824 8831 8834 8836 8838 8841 8852 8853 8860 8866 8870 8874 8875 8879 8889 8899 9003 9004 9009 9015 9016 9025 9026 9027 9032 9037 9039 9042 9043 9051 9070 9080 9093 9094 9095 9103 9107 9108 9111 9119 9136 9151 9191 9200 9201 9202 9204 9206 9207 9211 9219 9295 9306 9311 9445 9527 9530 9743 9800 9869 9944 9950 9966 9988 9992 9998 9999

CVEs Detected

CVE-2019-12519 CVE-2019-12520 CVE-2019-12521 CVE-2019-12522 CVE-2019-12523 CVE-2019-12524 CVE-2019-12525 CVE-2019-12526 CVE-2019-12527 CVE-2019-12528 CVE-2019-12529 CVE-2019-12854 CVE-2019-13345 CVE-2019-18676 CVE-2019-18677 CVE-2019-18678 CVE-2019-18679 CVE-2019-18860 CVE-2020-11945 CVE-2020-14058 CVE-2020-15049 CVE-2020-15810 CVE-2020-15811 CVE-2020-24606 CVE-2020-25097 CVE-2020-8449 CVE-2020-8450 CVE-2020-8517 CVE-2021-28116 CVE-2021-28651 CVE-2021-28652 CVE-2021-28662 CVE-2021-31806 CVE-2021-31807 CVE-2021-31808 CVE-2021-33620 CVE-2021-46784 CVE-2022-41318

Map

Whois Information

  • NetRange: 54.224.0.0 - 54.255.255.255
  • CIDR: 54.224.0.0/11
  • NetName: AMAZON-2011L
  • NetHandle: NET-54-224-0-0-1
  • Parent: NET54 (NET-54-0-0-0-0)
  • NetType: Direct Allocation
  • OriginAS: AS16509
  • Organization: Amazon Technologies Inc. (AT-88-Z)
  • RegDate: 2012-03-01
  • Updated: 2021-02-10
  • Comment: —–BEGIN CERTIFICATE—–MIICljCCAX4CCQDvS1je1Bd4uzANBgkqhkiG9w0BAQsFADANMQswCQYDVQQGEwJVUzAeFw0yMDA4MjYxODQ1NThaFw0yMTA4MjYxODQ1NThaMA0xCzAJBgNVBAYTAlVTMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA5geQJL7KoQhQLaTteXnFj0xsze15HgB9cpHPoL6khWVUthOg6AYCBHCcVJWeuEHuYGJcnrtW1tyLWpgfrxaw5E4ZtunSHElzO6BIp2u0215mbSGPQUt3TMR64nvXvEAY4qBP/p2+j0ud2eI47eA3s2ykFztEJPb7eZh8lVCGj5n2msRxeFiYwoB7/u3TDnW0/BwNLnJgyGkAWYUlk68hR10LHoBqGPezn7mPuiLHNa6JQP0WTYBz/80kS3m/4oZ7NS20PMieXqFjfYEgW6fPg7uJKhH3aYVVveZpBS5cRzm360HyT5hj1rUJh34nVCLMlvP+400w1wxr9buLnQzVlwIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQCZD7ERFb2LpeLdQgyji/ZqZ7lDXR8wq4m+ihMiqpPcwTVs1dfBfKDvZ4K6Ddyzkfd1NQYPWiV47nvqgJxwdISa7vN011RxBEGkYdJ8cNaRXW7aCGfQ8ZSQL6mbXsm4sbvDQNHiWJcdUB0KTzR/wpbXf9+24TbPGaOsZvfnKtd1lZhY5xFiOVCOdI59c/XyDH9aqOKNE0pOeATX55I3bU5PKeK5CM8oAtD2sFAQ956Uvj7/vFDs8QP3upzf53R+erSU10L1fTQBWHjNUCcf9wviS+U4hsaCcBZMlw6d5Q84GYX1tS+YwtA0Fv/NQcOWr9RJT+JVnpbyAxEyjI37XOqH—–END CERTIFICATE—–
  • Ref: https://rdap.arin.net/registry/ip/54.224.0.0
  • OrgName: Amazon Technologies Inc.
  • OrgId: AT-88-Z
  • Address: 410 Terry Ave N.
  • City: Seattle
  • StateProv: WA
  • PostalCode: 98109
  • Country: US
  • RegDate: 2011-12-08
  • Updated: 2022-09-30
  • Comment: All abuse reports MUST include:
  • Comment: * src IP
  • Comment: * dest IP (your IP)
  • Comment: * dest port
  • Comment: * Accurate date/timestamp and timezone of activity
  • Comment: * Intensity/frequency (short log extracts)
  • Comment: * Your contact details (phone and email) Without these we will be unable to identify the correct owner of the IP address at that point in time.
  • Ref: https://rdap.arin.net/registry/entity/AT-88-Z
  • OrgTechHandle: ANO24-ARIN
  • OrgTechName: Amazon EC2 Network Operations
  • OrgTechPhone: +1-206-555-0000
  • OrgTechEmail: [email protected]
  • OrgTechRef: https://rdap.arin.net/registry/entity/ANO24-ARIN
  • OrgRoutingHandle: ARMP-ARIN
  • OrgRoutingName: AWS RPKI Management POC
  • OrgRoutingPhone: +1-206-555-0000
  • OrgRoutingEmail: [email protected]
  • OrgRoutingRef: https://rdap.arin.net/registry/entity/ARMP-ARIN
  • OrgRoutingHandle: IPROU3-ARIN
  • OrgRoutingName: IP Routing
  • OrgRoutingPhone: +1-206-555-0000
  • OrgRoutingEmail: [email protected]
  • OrgRoutingRef: https://rdap.arin.net/registry/entity/IPROU3-ARIN
  • OrgAbuseHandle: AEA8-ARIN
  • OrgAbuseName: Amazon EC2 Abuse
  • OrgAbusePhone: +1-206-555-0000
  • OrgAbuseEmail: [email protected]
  • OrgAbuseRef: https://rdap.arin.net/registry/entity/AEA8-ARIN
  • OrgNOCHandle: AANO1-ARIN
  • OrgNOCName: Amazon AWS Network Operations
  • OrgNOCPhone: +1-206-555-0000
  • OrgNOCEmail: [email protected]
  • OrgNOCRef: https://rdap.arin.net/registry/entity/AANO1-ARIN

Links to attack logs

anonymous-proxy-ip-list-2023-06-22